Skip to content

Instantly share code, notes, and snippets.

@Endle
Created July 26, 2014 05:47
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save Endle/c09d39ebe8a992438c75 to your computer and use it in GitHub Desktop.
Save Endle/c09d39ebe8a992438c75 to your computer and use it in GitHub Desktop.
Gist by paste.py @ 2014-07-26 13:47:20.388872
0009:trace:mshtml:HTMLDOMNode_Release (0x1f0b18) ref=1
0009:trace:mshtml:HTMLDOMNode_AddRef (0x120f9a18) ref=3
0009:trace:mshtml:HTMLDOMNode_AddRef (0x120f9a18) ref=4
0009:trace:mshtml:HTMLDOMNode_Release (0x120f9a18) ref=3
0009:trace:mshtml:HTMLAnchorElement_handle_event CLICK
0009:trace:mshtml:get_target_window L""
0009:trace:mshtml:HTMLWindow2_AddRef (0x1eed70) ref=3
0009:trace:mshtml:nsURI_AddRef (0x1f1838) ref=5
0009:Call msvcrt.memcmp(10448388,6b28876c,00000021) ret=6b06a143
0009:Ret msvcrt.memcmp() retval=00000000 ret=6b06a143
0009:trace:mshtml:nsIOService_NewURI ("C:\\users\\lizhenbo\\My Documents\\Documents\\Science 2013-11-01.pdf" "UTF-8" 0x1f1838 0x32edb8)
0009:trace:mshtml:nsURI_QueryInterface (0x1f1838)->(IID_nsWineURI 0x32eb7c)
0009:trace:mshtml:nsURI_AddRef (0x1f1838) ref=6
0009:Call KERNEL32.MultiByteToWideChar(00000000,00000000,0032ec58 "C:\\users\\lizhenbo\\My Documents\\Documents\\Science 2013-11-01.pdf",ffffffff,0032db34,00000824) ret=7c13c095
0009:Ret KERNEL32.MultiByteToWideChar() retval=00000040 ret=7c13c095
0009:trace:urlmon:Uri_HasProperty (0x1f0f20 L"file:///C:/users/Public/Foxit%20Software/Foxit%20Reader/StartPage/start/en_us/index.html")->(5 0x32da64)
0009:trace:urlmon:Uri_AddRef (0x1f0f20) ref=5
0009:Call urlmon.CoInternetCombineUrlEx(001f0f20,0032db34 L"C:\\users\\lizhenbo\\My Documents\\Documents\\Science 2013-11-01.pdf",06000000,0032db2c,00000000) ret=7c131341
0009:trace:urlmon:CoInternetCombineUrlEx (0x1f0f20 L"C:\\users\\lizhenbo\\My Documents\\Documents\\Science 2013-11-01.pdf" 6000000 0x32db2c 0) stub
0009:trace:urlmon:Uri_QueryInterface (0x1f0f20)->(IID_IUriObj 0x32c950)
0009:trace:urlmon:parse_schema (L"file:///C:/users/Public/Foxit%20Software/Foxit%20Reader/StartPage/start/en_us/index.html" 00000000 0x32c8a4 64 0x32c8a0)
0009:trace:urlmon:CreateUri (L"C:\\users\\lizhenbo\\My Documents\\Documents\\Science 2013-11-01.pdf" 5 0 0x32d9f8)
0009:Call ntdll.RtlAllocateHeap(00110000,00000008,00000084) ret=7e192797
0009:Ret ntdll.RtlAllocateHeap() retval=120f9a90 ret=7e192797
0009:trace:urlmon:Uri_Construct ((nil) 0x32c91c)
0009:Call oleaut32.SysAllocStringLen(00000000,0000003f) ret=7e193a62
0009:Ret oleaut32.SysAllocStringLen() retval=001de664 ret=7e193a62
0009:trace:urlmon:parse_uri (0x32c854 4b45): BEGINNING TO PARSE URI L"C:\\users\\lizhenbo\\My Documents\\Documents\\Science 2013-11-01.pdf".
0009:trace:urlmon:parse_scheme (0x32c808 0x32c854 4b45): URI is an implicit file path.
0009:trace:urlmon:parse_scheme (0x32c808 0x32c854 4b45): Found scheme=L"file" scheme_len=4
0009:Call shlwapi.StrCmpNIW(7e1d4c48 L"http",7e1d681e L"file",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4c48 L"http",00000004,7e1d681e L"file",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000003 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000001 ret=7e1943e1
0009:Call shlwapi.StrCmpNIW(7e1d4cb4 L"news",7e1d681e L"file",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4cb4 L"news",00000004,7e1d681e L"file",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000003 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000001 ret=7e1943e1
0009:Call shlwapi.StrCmpNIW(7e1d4cd8 L"nntp",7e1d681e L"file",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4cd8 L"nntp",00000004,7e1d681e L"file",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000003 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000001 ret=7e1943e1
0009:Call shlwapi.StrCmpNIW(7e1d4d20 L"wais",7e1d681e L"file",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4d20 L"wais",00000004,7e1d681e L"file",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000003 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000001 ret=7e1943e1
0009:Call shlwapi.StrCmpNIW(7e1d4d44 L"file",7e1d681e L"file",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4d44 L"file",00000004,7e1d681e L"file",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000002 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000000 ret=7e1943e1
0009:trace:urlmon:parse_scheme (0x32c808 0x32c854 4b45): Assigned 9 as the URL_SCHEME.
0009:trace:urlmon:parse_hierpart (0x32c808 0x32c854 4b45): Treating URI as an hierarchical URI.
0009:trace:urlmon:parse_userinfo (0x32c808 0x32c854 4b45): URI contained no userinfo.
0009:trace:urlmon:parse_ipv4address (0x32c808 0x32c854 4b45): URI didn't contain anything looking like an IPv4 address.
0009:trace:urlmon:parse_path_hierarchical (0x32c808 0x32c854 4b45): Parsed path L"C:\\users\\lizhenbo\\My Documents\\Documents\\Science 2013-11-01.pdf" len=63
0009:trace:urlmon:parse_query (0x32c808 0x32c854 4b45): URI didn't contain a query string.
0009:trace:urlmon:parse_fragment (0x32c808 0x32c854 4b45): URI didn't contain a fragment.
0009:trace:urlmon:parse_uri (0x32c854 4b45): FINISHED PARSING URI.
0009:trace:urlmon:canonicalize_uri (0x32c854 0x120f9a90 4b45): beginning to canonicalize URI L"C:\\users\\lizhenbo\\My Documents\\Documents\\Science 2013-11-01.pdf".
0009:trace:urlmon:compute_canonicalized_length (0x32c854 4b45): Beginning to compute canonicalized length for URI L"C:\\users\\lizhenbo\\My Documents\\Documents\\Science 2013-11-01.pdf"
0009:trace:urlmon:compute_canonicalized_length (0x32c854 4b45): Finished computing canonicalized URI length. length=75
0009:Call ntdll.RtlAllocateHeap(00110000,00000000,00000098) ret=7e192766
0009:Ret ntdll.RtlAllocateHeap() retval=11e813a0 ret=7e192766
0009:trace:urlmon:canonicalize_scheme (0x32c854 0x120f9a90 4b45): Canonicalized scheme=L"file", len=4.
0009:trace:urlmon:remove_dot_segments (0x11e813ae 68): Path after dot segments removed L"/C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf" len=68
0009:trace:urlmon:canonicalize_path_hierarchical Canonicalized path L"/C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf" len=68
0009:trace:urlmon:canonicalize_uri (0x32c854 0x120f9a90 4b45): finished canonicalizing the URI. uri=L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf"
0009:trace:urlmon:Uri_QueryInterface (0x120f9a90)->(IID_IUriObj 0x32c950)
0009:Call oleaut32.SysAllocString(001de664 L"C:\\users\\lizhenbo\\My Documents\\Documents\\Science 2013-11-01.pdf") ret=7e1a41fe
0009:Ret oleaut32.SysAllocString() retval=001f0bfc ret=7e1a41fe
0009:trace:urlmon:parse_uri (0x32c850 4): BEGINNING TO PARSE URI L"C:\\users\\lizhenbo\\My Documents\\Documents\\Science 2013-11-01.pdf".
0009:trace:urlmon:parse_scheme (0x32c7f8 0x32c850 4): URI is an implicit file path.
0009:trace:urlmon:parse_scheme (0x32c7f8 0x32c850 4): Found scheme=L"file" scheme_len=4
0009:Call shlwapi.StrCmpNIW(7e1d4c48 L"http",7e1d681e L"file",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4c48 L"http",00000004,7e1d681e L"file",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000003 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000001 ret=7e1943e1
0009:Call shlwapi.StrCmpNIW(7e1d4cb4 L"news",7e1d681e L"file",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4cb4 L"news",00000004,7e1d681e L"file",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000003 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000001 ret=7e1943e1
0009:Call shlwapi.StrCmpNIW(7e1d4cd8 L"nntp",7e1d681e L"file",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4cd8 L"nntp",00000004,7e1d681e L"file",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000003 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000001 ret=7e1943e1
0009:Call shlwapi.StrCmpNIW(7e1d4d20 L"wais",7e1d681e L"file",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4d20 L"wais",00000004,7e1d681e L"file",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000003 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000001 ret=7e1943e1
0009:Call shlwapi.StrCmpNIW(7e1d4d44 L"file",7e1d681e L"file",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4d44 L"file",00000004,7e1d681e L"file",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000002 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000000 ret=7e1943e1
0009:trace:urlmon:parse_scheme (0x32c7f8 0x32c850 4): Assigned 9 as the URL_SCHEME.
0009:trace:urlmon:parse_hierpart (0x32c7f8 0x32c850 4): Treating URI as an hierarchical URI.
0009:trace:urlmon:parse_userinfo (0x32c7f8 0x32c850 4): URI contained no userinfo.
0009:trace:urlmon:parse_ipv4address (0x32c7f8 0x32c850 4): URI didn't contain anything looking like an IPv4 address.
0009:trace:urlmon:parse_path_hierarchical (0x32c7f8 0x32c850 4): Parsed path L"C:\\users\\lizhenbo\\My Documents\\Documents\\Science 2013-11-01.pdf" len=63
0009:trace:urlmon:parse_query (0x32c7f8 0x32c850 4): URI didn't contain a query string.
0009:trace:urlmon:parse_fragment (0x32c7f8 0x32c850 4): URI didn't contain a fragment.
0009:trace:urlmon:parse_uri (0x32c850 4): FINISHED PARSING URI.
0009:Call ntdll.RtlAllocateHeap(00110000,00000008,00000084) ret=7e192797
0009:Ret ntdll.RtlAllocateHeap() retval=12105000 ret=7e192797
0009:trace:urlmon:Uri_Construct ((nil) 0x32c918)
0009:trace:urlmon:canonicalize_uri (0x32c850 0x12105000 80): beginning to canonicalize URI L"C:\\users\\lizhenbo\\My Documents\\Documents\\Science 2013-11-01.pdf".
0009:trace:urlmon:compute_canonicalized_length (0x32c850 80): Beginning to compute canonicalized length for URI L"C:\\users\\lizhenbo\\My Documents\\Documents\\Science 2013-11-01.pdf"
0009:trace:urlmon:compute_canonicalized_length (0x32c850 80): Finished computing canonicalized URI length. length=75
0009:Call ntdll.RtlAllocateHeap(00110000,00000000,00000098) ret=7e192766
0009:Ret ntdll.RtlAllocateHeap() retval=12105090 ret=7e192766
0009:trace:urlmon:canonicalize_scheme (0x32c850 0x12105000 80): Canonicalized scheme=L"file", len=4.
0009:trace:urlmon:remove_dot_segments (0x1210509e 68): Path after dot segments removed L"/C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf" len=68
0009:trace:urlmon:canonicalize_path_hierarchical Canonicalized path L"/C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf" len=68
0009:trace:urlmon:canonicalize_uri (0x32c850 0x12105000 80): finished canonicalizing the URI. uri=L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf"
0009:trace:urlmon:Uri_Release (0x120f9a90) ref=0
0009:Call oleaut32.SysFreeString(001de664 L"C:\\users\\lizhenbo\\My Documents\\Documents\\Science 2013-11-01.pdf") ret=7e19cb97
0009:Ret oleaut32.SysFreeString() retval=00000000 ret=7e19cb97
0009:Call ntdll.RtlFreeHeap(00110000,00000000,11e813a0) ret=7e192800
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e192800
0009:Call ntdll.RtlFreeHeap(00110000,00000000,120f9a90) ret=7e192800
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e192800
0009:Ret urlmon.CoInternetCombineUrlEx() retval=00000000 ret=7c131341
0009:trace:urlmon:Uri_Release (0x1f0f20) ref=4
0009:Call ntdll.RtlAllocateHeap(00110000,00000008,00000030) ret=7c130b75
0009:Ret ntdll.RtlAllocateHeap() retval=11ea9770 ret=7c130b75
0009:trace:mshtml:nsWebBrowserChrome_AddRef (0x1ec740) ref=33
0009:trace:urlmon:Uri_AddRef (0x12105000) ref=2
0009:trace:urlmon:Uri_GetScheme (0x12105000)->(0x11ea979c)
0009:trace:urlmon:Uri_GetPropertyDWORD (0x12105000 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf")->(17 0x11ea979c 0)
0009:trace:mshtml:create_nsuri retval=0x11ea9770
0009:trace:urlmon:Uri_Release (0x12105000) ref=1
0009:trace:mshtml:nsURI_Release (0x1f1838) ref=5
0009:trace:mshtml:nsURI_Release (0x1f1838) ref=4
0009:trace:mshtml:nsURI_GetSpec (0x11ea9770)->(0x32edbc)
0009:trace:urlmon:Uri_GetPropertyBSTR (0x12105000 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf")->(2 0x32ed24 0)
0009:Call oleaut32.SysAllocString(12105090 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf") ret=7e19d6d9
0009:Ret oleaut32.SysAllocString() retval=001cd64c ret=7e19d6d9
0009:Call KERNEL32.WideCharToMultiByte(0000fde9,00000000,001cd64c L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",ffffffff,00000000,00000000,00000000,00000000) ret=7c130ed2
0009:Ret KERNEL32.WideCharToMultiByte() retval=0000004c ret=7c130ed2
0009:Call ntdll.RtlAllocateHeap(00110000,00000000,0000004c) ret=7c130b44
0009:Ret ntdll.RtlAllocateHeap() retval=00204c78 ret=7c130b44
0009:Call KERNEL32.WideCharToMultiByte(0000fde9,00000000,001cd64c L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",ffffffff,00204c78,0000004c,00000000,00000000) ret=7c130f2d
0009:Ret KERNEL32.WideCharToMultiByte() retval=0000004c ret=7c130f2d
0009:Call oleaut32.SysFreeString(001cd64c L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf") ret=7c136fcc
0009:Ret oleaut32.SysFreeString() retval=00000000 ret=7c136fcc
0009:trace:mshtml:get_uri_string ret "file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf"
0009:Call msvcrt.malloc(00000087) ret=61e42607
0009:Call ntdll.RtlAllocateHeap(10400000,00000000,00000087) ret=7d00dd6b
0009:Ret ntdll.RtlAllocateHeap() retval=11af2890 ret=7d00dd6b
0009:Ret msvcrt.malloc() retval=11af2890 ret=61e42607
0009:Call msvcrt.memcpy(11af2898,00204c78,0000004b) ret=6a438b28
0009:Ret msvcrt.memcpy() retval=11af2898 ret=6a438b28
0009:Call ntdll.RtlFreeHeap(00110000,00000000,00204c78) ret=7c130ba6
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7c130ba6
0009:Call msvcrt.malloc(000000a0) ret=61e42607
0009:Call ntdll.RtlAllocateHeap(10400000,00000000,000000a0) ret=7d00dd6b
0009:Ret ntdll.RtlAllocateHeap() retval=11af2920 ret=7d00dd6b
0009:Ret msvcrt.malloc() retval=11af2920 ret=61e42607
0009:Call msvcrt.free(11af2890) ret=61e425f3
0009:Call ntdll.RtlFreeHeap(10400000,00000000,11af2890) ret=7d00df76
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7d00df76
0009:Ret msvcrt.free() retval=00000001 ret=61e425f3
0009:trace:mshtml:nsURI_Release (0x11ea9770) ref=0
0009:trace:mshtml:nsWebBrowserChrome_Release (0x1ec740) ref=32
0009:trace:urlmon:Uri_Release (0x12105000) ref=0
0009:Call oleaut32.SysFreeString(001f0bfc L"C:\\users\\lizhenbo\\My Documents\\Documents\\Science 2013-11-01.pdf") ret=7e19cb97
0009:Ret oleaut32.SysFreeString() retval=00000000 ret=7e19cb97
0009:Call ntdll.RtlFreeHeap(00110000,00000000,12105090) ret=7e192800
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e192800
0009:Call ntdll.RtlFreeHeap(00110000,00000000,12105000) ret=7e192800
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e192800
0009:Call ntdll.RtlFreeHeap(00110000,00000000,00000000) ret=7c130ba6
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7c130ba6
0009:Call ntdll.RtlFreeHeap(00110000,00000000,11ea9770) ret=7c130ba6
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7c130ba6
0009:Call urlmon.CoInternetCombineUrlEx(001dd7a0,11af2928 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",06000000,0032ee1c,00000000) ret=7c1250e4
0009:trace:urlmon:CoInternetCombineUrlEx (0x1dd7a0 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf" 6000000 0x32ee1c 0) stub
0009:trace:urlmon:Uri_QueryInterface (0x1dd7a0)->(IID_IUriObj 0x32dc90)
0009:trace:urlmon:parse_schema (L"file://C:\\users\\Public\\Foxit Software\\Foxit Reader\\StartPage\\start\\en_us\\index.html" 00000000 0x32dbe4 64 0x32dbe0)
0009:trace:urlmon:CreateUri (L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf" 5 0 0x32ed38)
0009:Call ntdll.RtlAllocateHeap(00110000,00000008,00000084) ret=7e192797
0009:Ret ntdll.RtlAllocateHeap() retval=120f9a90 ret=7e192797
0009:trace:urlmon:Uri_Construct ((nil) 0x32dc5c)
0009:Call oleaut32.SysAllocStringLen(00000000,0000004b) ret=7e193a62
0009:Ret oleaut32.SysAllocStringLen() retval=001cd64c ret=7e193a62
0009:trace:urlmon:parse_uri (0x32db94 4b45): BEGINNING TO PARSE URI L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf".
0009:trace:urlmon:parse_scheme (0x32db48 0x32db94 4b45): Found scheme=L"file" scheme_len=4
0009:Call shlwapi.StrCmpNIW(7e1d4c48 L"http",001cd64c L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4c48 L"http",00000004,001cd64c L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000003 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000001 ret=7e1943e1
0009:Call shlwapi.StrCmpNIW(7e1d4cb4 L"news",001cd64c L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4cb4 L"news",00000004,001cd64c L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000003 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000001 ret=7e1943e1
0009:Call shlwapi.StrCmpNIW(7e1d4cd8 L"nntp",001cd64c L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4cd8 L"nntp",00000004,001cd64c L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000003 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000001 ret=7e1943e1
0009:Call shlwapi.StrCmpNIW(7e1d4d20 L"wais",001cd64c L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4d20 L"wais",00000004,001cd64c L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000003 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000001 ret=7e1943e1
0009:Call shlwapi.StrCmpNIW(7e1d4d44 L"file",001cd64c L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4d44 L"file",00000004,001cd64c L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000002 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000000 ret=7e1943e1
0009:trace:urlmon:parse_scheme (0x32db48 0x32db94 4b45): Assigned 9 as the URL_SCHEME.
0009:trace:urlmon:parse_hierpart (0x32db48 0x32db94 4b45): Treating URI as an hierarchical URI.
0009:trace:urlmon:parse_userinfo (0x32db48 0x32db94 4b45): URI contained no userinfo.
0009:trace:urlmon:parse_ipv4address (0x32db48 0x32db94 4b45): URI didn't contain anything looking like an IPv4 address.
0009:trace:urlmon:parse_reg_name (0x32db48 0x32db94 4b45 0): Parsed reg-name. host=L"" len=0
0009:trace:urlmon:parse_path_hierarchical (0x32db48 0x32db94 4b45): Parsed path L"/C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf" len=68
0009:trace:urlmon:parse_query (0x32db48 0x32db94 4b45): URI didn't contain a query string.
0009:trace:urlmon:parse_fragment (0x32db48 0x32db94 4b45): URI didn't contain a fragment.
0009:trace:urlmon:parse_uri (0x32db94 4b45): FINISHED PARSING URI.
0009:trace:urlmon:canonicalize_uri (0x32db94 0x120f9a90 4b45): beginning to canonicalize URI L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf".
0009:trace:urlmon:compute_canonicalized_length (0x32db94 4b45): Beginning to compute canonicalized length for URI L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf"
0009:trace:urlmon:compute_canonicalized_length (0x32db94 4b45): Finished computing canonicalized URI length. length=75
0009:Call ntdll.RtlAllocateHeap(00110000,00000000,00000098) ret=7e192766
0009:Ret ntdll.RtlAllocateHeap() retval=11e813a0 ret=7e192766
0009:trace:urlmon:canonicalize_scheme (0x32db94 0x120f9a90 4b45): Canonicalized scheme=L"file", len=4.
0009:trace:urlmon:remove_dot_segments (0x11e813ae 68): Path after dot segments removed L"/C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf" len=68
0009:trace:urlmon:canonicalize_path_hierarchical Canonicalized path L"/C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf" len=68
0009:trace:urlmon:canonicalize_uri (0x32db94 0x120f9a90 4b45): finished canonicalizing the URI. uri=L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf"
0009:trace:urlmon:Uri_QueryInterface (0x120f9a90)->(IID_IUriObj 0x32dc90)
0009:Call oleaut32.SysAllocString(001cd64c L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf") ret=7e1a41fe
0009:Call ntdll.RtlAllocateHeap(00110000,00000000,000000a0) ret=7e268c9f
0009:Ret ntdll.RtlAllocateHeap() retval=12105000 ret=7e268c9f
0009:Ret oleaut32.SysAllocString() retval=12105004 ret=7e1a41fe
0009:trace:urlmon:parse_uri (0x32db90 4): BEGINNING TO PARSE URI L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf".
0009:trace:urlmon:parse_scheme (0x32db38 0x32db90 4): Found scheme=L"file" scheme_len=4
0009:Call shlwapi.StrCmpNIW(7e1d4c48 L"http",12105004 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4c48 L"http",00000004,12105004 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000003 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000001 ret=7e1943e1
0009:Call shlwapi.StrCmpNIW(7e1d4cb4 L"news",12105004 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4cb4 L"news",00000004,12105004 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000003 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000001 ret=7e1943e1
0009:Call shlwapi.StrCmpNIW(7e1d4cd8 L"nntp",12105004 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4cd8 L"nntp",00000004,12105004 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000003 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000001 ret=7e1943e1
0009:Call shlwapi.StrCmpNIW(7e1d4d20 L"wais",12105004 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4d20 L"wais",00000004,12105004 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000003 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000001 ret=7e1943e1
0009:Call shlwapi.StrCmpNIW(7e1d4d44 L"file",12105004 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e1943e1
0009:Call KERNEL32.GetThreadLocale() ret=7e734f45
0009:Ret KERNEL32.GetThreadLocale() retval=00000409 ret=7e734f45
0009:Call KERNEL32.CompareStringW(00000409,00000001,7e1d4d44 L"file",00000004,12105004 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000004) ret=7e734f70
0009:Ret KERNEL32.CompareStringW() retval=00000002 ret=7e734f70
0009:Ret shlwapi.StrCmpNIW() retval=00000000 ret=7e1943e1
0009:trace:urlmon:parse_scheme (0x32db38 0x32db90 4): Assigned 9 as the URL_SCHEME.
0009:trace:urlmon:parse_hierpart (0x32db38 0x32db90 4): Treating URI as an hierarchical URI.
0009:trace:urlmon:parse_userinfo (0x32db38 0x32db90 4): URI contained no userinfo.
0009:trace:urlmon:parse_ipv4address (0x32db38 0x32db90 4): URI didn't contain anything looking like an IPv4 address.
0009:trace:urlmon:parse_reg_name (0x32db38 0x32db90 4 0): Parsed reg-name. host=L"" len=0
0009:trace:urlmon:parse_path_hierarchical (0x32db38 0x32db90 4): Parsed path L"/C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf" len=68
0009:trace:urlmon:parse_query (0x32db38 0x32db90 4): URI didn't contain a query string.
0009:trace:urlmon:parse_fragment (0x32db38 0x32db90 4): URI didn't contain a fragment.
0009:trace:urlmon:parse_uri (0x32db90 4): FINISHED PARSING URI.
0009:Call ntdll.RtlAllocateHeap(00110000,00000008,00000084) ret=7e192797
0009:Ret ntdll.RtlAllocateHeap() retval=121050a8 ret=7e192797
0009:trace:urlmon:Uri_Construct ((nil) 0x32dc58)
0009:trace:urlmon:canonicalize_uri (0x32db90 0x121050a8 80): beginning to canonicalize URI L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf".
0009:trace:urlmon:compute_canonicalized_length (0x32db90 80): Beginning to compute canonicalized length for URI L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf"
0009:trace:urlmon:compute_canonicalized_length (0x32db90 80): Finished computing canonicalized URI length. length=75
0009:Call ntdll.RtlAllocateHeap(00110000,00000000,00000098) ret=7e192766
0009:Ret ntdll.RtlAllocateHeap() retval=12105138 ret=7e192766
0009:trace:urlmon:canonicalize_scheme (0x32db90 0x121050a8 80): Canonicalized scheme=L"file", len=4.
0009:trace:urlmon:remove_dot_segments (0x12105146 68): Path after dot segments removed L"/C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf" len=68
0009:trace:urlmon:canonicalize_path_hierarchical Canonicalized path L"/C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf" len=68
0009:trace:urlmon:canonicalize_uri (0x32db90 0x121050a8 80): finished canonicalizing the URI. uri=L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf"
0009:trace:urlmon:Uri_Release (0x120f9a90) ref=0
0009:Call oleaut32.SysFreeString(001cd64c L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf") ret=7e19cb97
0009:Ret oleaut32.SysFreeString() retval=00000000 ret=7e19cb97
0009:Call ntdll.RtlFreeHeap(00110000,00000000,11e813a0) ret=7e192800
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e192800
0009:Call ntdll.RtlFreeHeap(00110000,00000000,120f9a90) ret=7e192800
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7e192800
0009:Ret urlmon.CoInternetCombineUrlEx() retval=00000000 ret=7c1250e4
0009:trace:urlmon:Uri_GetDisplayUri (0x121050a8)->(0x32eda4)
0009:trace:urlmon:Uri_GetPropertyBSTR (0x121050a8 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf")->(2 0x32eda4 0)
0009:Call oleaut32.SysAllocString(12105138 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf") ret=7e19d6d9
0009:Ret oleaut32.SysAllocString() retval=001cd64c ret=7e19d6d9
0009:trace:urlmon:Uri_AddRef (0x121050a8) ref=2
0009:trace:urlmon:Uri_Release (0x121050a8) ref=1
0009:trace:mshtml:navigate_uri L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf"
0009:Call oleaut32.SysAllocString(001cd64c L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf") ret=7c5b5d50
0009:Call ntdll.RtlAllocateHeap(00110000,00000000,000000a0) ret=7e268c9f
0009:Ret ntdll.RtlAllocateHeap() retval=120f9a90 ret=7e268c9f
0009:Ret oleaut32.SysAllocString() retval=120f9a94 ret=7c5b5d50
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032eb50) ret=006168cf
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006168cf
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e9dc) ret=006168cf
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006168cf
0009:Call KERNEL32.lstrlenA(01b0ade8 "\tLLLLLK") ret=006df082
0009:Ret KERNEL32.lstrlenA() retval=00000007 ret=006df082
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000004) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07611490 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000000c) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07610b88 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,000000a8) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07618df8 ret=007aa8ca
0009:Call shlwapi.PathFindExtensionW(07618e08 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf") ret=01432c13
0009:Ret shlwapi.PathFindExtensionW() retval=07618e96 ret=01432c13
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000016) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07604bc0 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,000000a4) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07618ea8 ret=007aa8ca
0009:Call shlwapi.PathIsRelativeW(07618eb4 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf") ret=004afe90
0009:Ret shlwapi.PathIsRelativeW() retval=00000001 ret=004afe90
0009:Call KERNEL32.GetFullPathNameW(07618eb4 L"file:///C:/users/lizhenbo/My%20Documents/Documents/Science%202013-11-01.pdf",00000104,0032e614,0032e60c) ret=004afec5
0009:Ret KERNEL32.GetFullPathNameW() retval=00000076 ret=004afec5
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,000000fa) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07618f58 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,000000fa) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619060 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,000000fa) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619168 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619168) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000016) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07611b30 ret=007aa8ca
0009:Call KERNEL32.GetLastError() ret=007b3c71
0009:Ret KERNEL32.GetLastError() retval=00000000 ret=007b3c71
0009:Call KERNEL32.GetLastError() ret=007b3c71
0009:Ret KERNEL32.GetLastError() retval=00000000 ret=007b3c71
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000016) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076128c0 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07611b30) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000016) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07611b30 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07611b30) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000016) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07611b30 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07611b30) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,076128c0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619060) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,000000fa) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619060 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619060) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000016) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076128c0 ret=007aa8ca
0009:Call KERNEL32.GetLastError() ret=007b3c71
0009:Ret KERNEL32.GetLastError() retval=00000000 ret=007b3c71
0009:Call KERNEL32.GetLastError() ret=007b3c71
0009:Ret KERNEL32.GetLastError() retval=00000000 ret=007b3c71
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000016) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07611b30 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,076128c0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000001a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076128c0 ret=007aa8ca
0009:Call shlwapi.PathFindExtensionW(07618f64 L"C:\\Program Files\\Foxit Software\\Foxit Reader\\file:\\C:\\users\\lizhenbo\\My%20Documents\\Documents\\Science%202013-11-01.pdf") ret=00634e65
0009:Ret shlwapi.PathFindExtensionW() retval=07619048 ret=00634e65
0009:Call KERNEL32.lstrcmpiW(07619048 L".pdf",076128d0 L".pdf") ret=0061a7cf
0009:Ret KERNEL32.lstrcmpiW() retval=00000000 ret=0061a7cf
0009:Call user32.GetSystemMetrics(0000002a) ret=0061a7e2
0009:Ret user32.GetSystemMetrics() retval=00000000 ret=0061a7e2
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,076128c0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000268) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619060 ret=007aa8ca
0009:Call user32.SetRectEmpty(076190b8) ret=0063dc89
0009:Ret user32.SetRectEmpty() retval=00000001 ret=0063dc89
0009:Call KERNEL32.InterlockedIncrement(00144dfc) ret=00637200
0009:Ret KERNEL32.InterlockedIncrement() retval=00000001 ret=00637200
0009:Call KERNEL32.LoadLibraryW(018da9b8 L"User32.dll") ret=00566721
0009:Ret KERNEL32.LoadLibraryW() retval=7ec60000 ret=00566721
0009:Call KERNEL32.GetProcAddress(7ec60000,018da9a8 "GetGuiResources") ret=00566737
0009:Ret KERNEL32.GetProcAddress() retval=7ec6b938 ret=00566737
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000007c) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07611c18 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,000007b8) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076192d0 ret=007aa8ca
0009:Call user32.SetRectEmpty(07619360) ret=0061e422
0009:Ret user32.SetRectEmpty() retval=00000001 ret=0061e422
0009:Call user32.SetRectEmpty(07619488) ret=00be5610
0009:Ret user32.SetRectEmpty() retval=00000001 ret=00be5610
0009:Call user32.SetRectEmpty(076194dc) ret=00be8926
0009:Ret user32.SetRectEmpty() retval=00000001 ret=00be8926
0009:Call user32.SetRectEmpty(076195f8) ret=00b9f426
0009:Ret user32.SetRectEmpty() retval=00000001 ret=00b9f426
0009:Call user32.SetRectEmpty(07619608) ret=00b9f433
0009:Ret user32.SetRectEmpty() retval=00000001 ret=00b9f433
0009:Call user32.SetRectEmpty(07619618) ret=00b9f440
0009:Ret user32.SetRectEmpty() retval=00000001 ret=00b9f440
0009:Call user32.SetRectEmpty(07619520) ret=00b9f447
0009:Ret user32.SetRectEmpty() retval=00000001 ret=00b9f447
0009:Call user32.SetRectEmpty(07619724) ret=00bd2dd9
0009:Ret user32.SetRectEmpty() retval=00000001 ret=00bd2dd9
0009:Call KERNEL32.MultiByteToWideChar(00000003,00000000,018b6180 "",ffffffff,00000000,00000000) ret=00472090
0009:Ret KERNEL32.MultiByteToWideChar() retval=00000001 ret=00472090
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000024) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076128c0 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000002e) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076132b8 ret=007aa8ca
0009:Call ntdll.RtlReAllocateHeap(028d0000,00000000,076128c0,00000040) ret=007a955a
0009:Ret ntdll.RtlReAllocateHeap() retval=076132f0 ret=007a955a
0009:Call ntdll.RtlReAllocateHeap(028d0000,00000000,076132f0,00000056) ret=007a955a
0009:Ret ntdll.RtlReAllocateHeap() retval=07619a90 ret=007a955a
0009:Call ntdll.RtlReAllocateHeap(028d0000,00000000,07619a90,00000078) ret=007a955a
0009:Ret ntdll.RtlReAllocateHeap() retval=07619a90 ret=007a955a
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,076132b8) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619a90) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call KERNEL32.LoadLibraryW(018da9b8 L"User32.dll") ret=0055f6d3
0009:Ret KERNEL32.LoadLibraryW() retval=7ec60000 ret=0055f6d3
0009:Call KERNEL32.GetProcAddress(7ec60000,018da9a8 "GetGuiResources") ret=0055f6e9
0009:Ret KERNEL32.GetProcAddress() retval=7ec6b938 ret=0055f6e9
0009:Call KERNEL32.FindResourceW(00400000,00000009,00000006) ret=0040159e
0009:Ret KERNEL32.FindResourceW() retval=022ed938 ret=0040159e
0009:Call KERNEL32.LoadResource(00400000,022ed938) ret=00401523
0009:Ret KERNEL32.LoadResource() retval=026414ac ret=00401523
0009:Call KERNEL32.LockResource(026414ac) ret=00401533
0009:Ret KERNEL32.LockResource() retval=026414ac ret=00401533
0009:Call KERNEL32.SizeofResource(00400000,022ed938) ret=00401541
0009:Ret KERNEL32.SizeofResource() retval=00000134 ret=00401541
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000009e) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619a90 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000012) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076128c0 ret=007aa8ca
0009:Call user32.LoadIconW(00400000,00000081) ret=0061c813
0009:Ret user32.LoadIconW() retval=00030188 ret=0061c813
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e40c) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018e3f7c L"AfxFrameOrView100su",0032e478) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=0000c0ab ret=0060727b
0009:Call KERNEL32.DeactivateActCtx(00000000,001cda20) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.GetLastError() ret=007b3c71
0009:Ret KERNEL32.GetLastError() retval=00000000 ret=007b3c71
0009:Call KERNEL32.GetLastError() ret=007b3c71
0009:Ret KERNEL32.GetLastError() retval=00000000 ret=007b3c71
0009:Call KERNEL32.GetLastError() ret=007b3c71
0009:Ret KERNEL32.GetLastError() retval=00000000 ret=007b3c71
0009:Call KERNEL32.GetLastError() ret=007b3c71
0009:Ret KERNEL32.GetLastError() retval=00000000 ret=007b3c71
0009:Call KERNEL32.GetLastError() ret=007b3c71
0009:Ret KERNEL32.GetLastError() retval=00000000 ret=007b3c71
0009:Call KERNEL32.GetLastError() ret=007b3c71
0009:Ret KERNEL32.GetLastError() retval=00000000 ret=007b3c71
0009:Call KERNEL32.GetLastError() ret=007b3c71
0009:Ret KERNEL32.GetLastError() retval=00000000 ret=007b3c71
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e3bc) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,00144c5c L"Afx:00400000:b:00010040:00000006:00030188",0032e3fc) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=00000000 ret=0060727b
0009:Call KERNEL32.GetLastError() ret=006072a7
0009:Ret KERNEL32.GetLastError() retval=00000583 ret=006072a7
0009:Call KERNEL32.DeactivateActCtx(00000000,001cda20) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e364) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,00144c5c L"Afx:00400000:b:00010040:00000006:00030188",0032e3ac) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=00000000 ret=0060727b
0009:Call KERNEL32.GetLastError() ret=006072a7
0009:Ret KERNEL32.GetLastError() retval=00000583 ret=006072a7
0009:Call KERNEL32.DeactivateActCtx(00000000,001cda20) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e36c) ret=006071d3
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006071d3
0009:Call user32.RegisterClassW(0032e3fc) ret=006071ea
0009:Ret user32.RegisterClassW() retval=0000c0ee ret=006071ea
0009:Call KERNEL32.DeactivateActCtx(00000000,001cda20) ret=0060722c
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=0060722c
0009:Call user32.SendMessageW(000100b8,00000220,00000000,0032e480) ret=0063a59e
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032e32c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032e32c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032e32c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100b8,msg=WM_MDICREATE,wp=00000000,lp=0032e480)
0009:Call user32.CallWindowProcW(7ed17752,000100b8,00000220,00000000,0032e480) ret=00605c53
0009:Call window proc 0x7ed17752 (hwnd=0x100b8,msg=WM_MDICREATE,wp=00000000,lp=0032e480)
0009:Call winex11.drv.SystemParametersInfo(00000029,00000000,0032d688,00000000) ret=7ecf3732
0009:Ret winex11.drv.SystemParametersInfo() retval=00000000 ret=7ecf3732
0009:Call hook proc 0x60b3f4 (id=WH_CBT,code=3,wp=00020198,lp=0032de24)
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032d6e4) ret=006168cf
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006168cf
0009:Call user32.GetParent(00020198) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b8 ret=0060d29d
0009:Call user32.SetWindowLongW(00020198,fffffffc,00609f5a) ret=0060b526
0009:Ret user32.SetWindowLongW() retval=7ec6acf0 ret=0060b526
0009:Call KERNEL32.DeactivateActCtx(00000000,00168808) ret=00615a3e
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=00615a3e
0009:Call user32.CallNextHookEx(000100b0,00000003,00020198,0032de24) ret=0060b5e3
0009:Ret user32.CallNextHookEx() retval=00000000 ret=0060b5e3
0009:Ret hook proc 0x60b3f4 (id=WH_CBT,code=3,wp=00020198,lp=0032de24) retval=00000000
0009:Call winex11.drv.SystemParametersInfo(00000029,00000000,0032d6c8,00000000) ret=7ecf3732
0009:Ret winex11.drv.SystemParametersInfo() retval=00000000 ret=7ecf3732
0009:Call winex11.drv.SystemParametersInfo(00000029,00000000,0032d108,00000000) ret=7ecf3732
0009:Ret winex11.drv.SystemParametersInfo() retval=00000000 ret=7ecf3732
0009:Call winex11.drv.EnumDisplayMonitors(00000000,00000000,7ecf18e4,0032d5ec) ret=7ecdb265
0009:Ret winex11.drv.EnumDisplayMonitors() retval=00000001 ret=7ecdb265
0009:Call winex11.drv.EnumDisplayMonitors(00000000,00000000,7ecf18e4,0032d5ec) ret=7ecdb265
0009:Ret winex11.drv.EnumDisplayMonitors() retval=00000001 ret=7ecdb265
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dafc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dafc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dafc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg=WM_GETMINMAXINFO,wp=00000000,lp=0032dc64)
0009:Call user32.DefMDIChildProcW(00020198,00000024,00000000,0032dc64) ret=00639d0d
0009:Call winex11.drv.SystemParametersInfo(00000029,00000000,0032d1c8,00000000) ret=7ecf3732
0009:Ret winex11.drv.SystemParametersInfo() retval=00000000 ret=7ecf3732
0009:Ret user32.DefMDIChildProcW() retval=00000000 ret=00639d0d
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg=WM_GETMINMAXINFO,wp=00000000,lp=0032dc64) retval=00000000
0009:Call winex11.drv.EnumDisplayMonitors(00000000,00000000,7ecdab74,0032dad4) ret=7ecdb265
0009:Call winex11.drv.GetMonitorInfo(00000001,0032d954) ret=7ecdb195
0009:Ret winex11.drv.GetMonitorInfo() retval=00000001 ret=7ecdb195
0009:Ret winex11.drv.EnumDisplayMonitors() retval=00000001 ret=7ecdb265
0009:Call winex11.drv.GetMonitorInfo(00000001,0032dc1c) ret=7ecdb195
0009:Ret winex11.drv.GetMonitorInfo() retval=00000001 ret=7ecdb195
0009:Call winex11.drv.WindowPosChanging(00020198,00000000,00000014,0032de50,0032de50,0032dc88,0032dc64) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.ReleaseDC(00020184,000103af) ret=7ece27ee
0009:Ret winex11.drv.ReleaseDC() retval=00000001 ret=7ece27ee
0009:Call winex11.drv.WindowPosChanged(00020198,00000000,00000014,0032de50,0032de50,0032dc88,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbfc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbfc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbfc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg=WM_NCCREATE,wp=00000000,lp=0032df20)
0009:Call user32.DefMDIChildProcW(00020198,00000081,00000000,0032df20) ret=00639d0d
0009:Call winex11.drv.SetWindowText(00020198,00168808 L"") ret=7ec90761
0009:Ret winex11.drv.SetWindowText() retval=00000000 ret=7ec90761
0009:Ret user32.DefMDIChildProcW() retval=00000001 ret=00639d0d
0009:Call user32.SetWindowLongW(00020198,ffffffec,00000340) ret=0063ab3f
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d73c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d73c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d73c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg=WM_STYLECHANGING,wp=ffffffec,lp=0032d8ac)
0009:Call user32.DefMDIChildProcW(00020198,0000007c,ffffffec,0032d8ac) ret=00639d0d
0009:Ret user32.DefMDIChildProcW() retval=00000000 ret=00639d0d
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg=WM_STYLECHANGING,wp=ffffffec,lp=0032d8ac) retval=00000000
0009:Call winex11.drv.SetWindowStyle(00020198,ffffffec,0032d8ac) ret=7ed08b10
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed08b10
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d73c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d73c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d73c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg=WM_STYLECHANGED,wp=ffffffec,lp=0032d8ac)
0009:Call user32.DefMDIChildProcW(00020198,0000007d,ffffffec,0032d8ac) ret=00639d0d
0009:Ret user32.DefMDIChildProcW() retval=00000000 ret=00639d0d
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg=WM_STYLECHANGED,wp=ffffffec,lp=0032d8ac) retval=00000000
0009:Ret user32.SetWindowLongW() retval=00000140 ret=0063ab3f
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg=WM_NCCREATE,wp=00000000,lp=0032df20) retval=00000001
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbfc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbfc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbfc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg=WM_NCCALCSIZE,wp=00000000,lp=0032ddc0)
0009:Call user32.IsZoomed(00020198) ret=00bd4043
0009:Ret user32.IsZoomed() retval=00000000 ret=00bd4043
0009:Call user32.GetWindowLongW(00020198,fffffff0) ret=0060cd58
0009:Ret user32.GetWindowLongW() retval=46c70000 ret=0060cd58
0009:Call user32.DefMDIChildProcW(00020198,00000083,00000000,0032ddc0) ret=00639d0d
0009:Call winex11.drv.SystemParametersInfo(00000029,00000000,0032d0d8,00000000) ret=7ecf3732
0009:Ret winex11.drv.SystemParametersInfo() retval=00000000 ret=7ecf3732
0009:Ret user32.DefMDIChildProcW() retval=00000300 ret=00639d0d
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg=WM_NCCALCSIZE,wp=00000000,lp=0032ddc0) retval=00000000
0009:Call winex11.drv.WindowPosChanging(00020198,00000001,00000010,0032de50,0032ddc0,0032dc88,0032dc64) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(00020198,00000001,00000010,0032de50,0032ddc0,0032dc88,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbfc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbfc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbfc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg=WM_CREATE,wp=00000000,lp=0032df20)
0009:Call user32.GetParent(00020198) ret=00639e29
0009:Ret user32.GetParent() retval=000100b8 ret=00639e29
0009:Call user32.GetParent(000100b8) ret=00639e2c
0009:Ret user32.GetParent() retval=000100b2 ret=00639e2c
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.GetWindowLongW(00020198,fffffff0) ret=0060cd58
0009:Ret user32.GetWindowLongW() retval=46c70000 ret=0060cd58
0009:Call user32.GetParent(00020198) ret=00bd4f9c
0009:Ret user32.GetParent() retval=000100b8 ret=00bd4f9c
0009:Call user32.GetParent(000100b8) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.SendMessageW(000100b8,0000000b,00000000,00000000) ret=00bd4fb2
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d81c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d81c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d81c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100b8,msg=WM_SETREDRAW,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7ed17752,000100b8,0000000b,00000000,00000000) ret=00605c53
0009:Call window proc 0x7ed17752 (hwnd=0x100b8,msg=WM_SETREDRAW,wp=00000000,lp=00000000)
0009:Call winex11.drv.SetWindowStyle(000100b8,fffffff0,0032d21c) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Ret window proc 0x7ed17752 (hwnd=0x100b8,msg=WM_SETREDRAW,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100b8,msg=WM_SETREDRAW,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=00bd4fb2
0009:Call user32.GetClientRect(000100b8,0032d95c) ret=00bd500b
0009:Ret user32.GetClientRect() retval=00000001 ret=00bd500b
0009:Call user32.GetClientRect(00020198,0032d96c) ret=00bd5025
0009:Ret user32.GetClientRect() retval=00000001 ret=00bd5025
0009:Call user32.ClientToScreen(00020198,0032d96c) ret=0060ffdb
0009:Ret user32.ClientToScreen() retval=00000001 ret=0060ffdb
0009:Call user32.ClientToScreen(00020198,0032d974) ret=0060ffe8
0009:Ret user32.ClientToScreen() retval=00000001 ret=0060ffe8
0009:Call user32.GetWindowLongW(00020198,ffffffec) ret=0060cd72
0009:Ret user32.GetWindowLongW() retval=00000340 ret=0060cd72
0009:Call user32.GetWindowRect(00020198,0032d94c) ret=00bd504a
0009:Ret user32.GetWindowRect() retval=00000001 ret=00bd504a
0009:Call user32.GetParent(00020198) ret=00bd5054
0009:Ret user32.GetParent() retval=000100b8 ret=00bd5054
0009:Call user32.GetParent(000100b8) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.SendMessageW(000100b8,0000000b,00000001,00000000) ret=00bd5069
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d81c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d81c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d81c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100b8,msg=WM_SETREDRAW,wp=00000001,lp=00000000)
0009:Call user32.CallWindowProcW(7ed17752,000100b8,0000000b,00000001,00000000) ret=00605c53
0009:Call window proc 0x7ed17752 (hwnd=0x100b8,msg=WM_SETREDRAW,wp=00000001,lp=00000000)
0009:Call winex11.drv.SetWindowStyle(000100b8,fffffff0,0032d21c) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call winex11.drv.WindowPosChanging(000100b8,00000000,0000181f,0032d160,0032d150,0032d0e8,0032d0c4) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000100b8,00000000,0000181f,0032d160,0032d150,0032d0e8,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Ret window proc 0x7ed17752 (hwnd=0x100b8,msg=WM_SETREDRAW,wp=00000001,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100b8,msg=WM_SETREDRAW,wp=00000001,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=00bd5069
0009:Call user32.DefMDIChildProcW(00020198,00000001,00000000,0032df20) ret=00639d0d
0009:Ret user32.DefMDIChildProcW() retval=00000000 ret=00639d0d
0009:Call user32.LoadIconW(00400000,00007a01) ret=0060c766
0009:Ret user32.LoadIconW() retval=00000000 ret=0060c766
0009:Call user32.LoadIconW(00000000,00007f00) ret=0060c775
0009:Ret user32.LoadIconW() retval=00010086 ret=0060c775
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032d79c) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018e3f58 L"AfxMDIFrame100su",0032d7e4) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=00000000 ret=0060727b
0009:Call KERNEL32.GetLastError() ret=006072a7
0009:Ret KERNEL32.GetLastError() retval=00000583 ret=006072a7
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032d7a4) ret=006071d3
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006071d3
0009:Call user32.RegisterClassW(0032d850) ret=006071ea
0009:Ret user32.RegisterClassW() retval=0000c0ef ret=006071ea
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=0060722c
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=0060722c
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032d7cc) ret=00607376
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=00607376
0009:Call user32.CreateWindowExW(00000000,018e3f58 L"AfxMDIFrame100su",00000000,50000001,00000000,00000000,00000000,00000000,00020198,0000e900,00400000,00000000) ret=006073ae
0009:Call hook proc 0x60b3f4 (id=WH_CBT,code=3,wp=000201a2,lp=0032d5f4)
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032ceb4) ret=006168cf
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006168cf
0009:Call user32.GetParent(000201a2) ret=0060d29d
0009:Ret user32.GetParent() retval=00020198 ret=0060d29d
0009:Call user32.SetWindowLongW(000201a2,fffffffc,00609f5a) ret=0060b526
0009:Ret user32.SetWindowLongW() retval=7ec6acf0 ret=0060b526
0009:Call KERNEL32.DeactivateActCtx(00000000,001cda20) ret=00615a3e
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=00615a3e
0009:Call user32.CallNextHookEx(000100b0,00000003,000201a2,0032d5f4) ret=0060b5e3
0009:Ret user32.CallNextHookEx() retval=00000000 ret=0060b5e3
0009:Ret hook proc 0x60b3f4 (id=WH_CBT,code=3,wp=000201a2,lp=0032d5f4) retval=00000000
0009:Call winex11.drv.WindowPosChanging(000201a2,00000000,00000014,0032d620,0032d620,0032d458,0032d434) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201a2,00000000,00000014,0032d620,0032d620,0032d458,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d3cc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d3cc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d3cc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a2,msg=WM_NCCREATE,wp=00000000,lp=0032d6f0)
0009:Call user32.CallWindowProcW(7ec6acf0,000201a2,00000081,00000000,0032d6f0) ret=00605c53
0009:Call window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_NCCREATE,wp=00000000,lp=0032d6f0)
0009:Call user32.DefWindowProcW(000201a2,00000081,00000000,0032d6f0) ret=7ed14b5a
0009:Ret user32.DefWindowProcW() retval=00000001 ret=7ed14b5a
0009:Ret window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_NCCREATE,wp=00000000,lp=0032d6f0) retval=00000001
0009:Ret user32.CallWindowProcW() retval=00000001 ret=00605c53
0009:Call user32.GetParent(000201a2) ret=0062f55e
0009:Ret user32.GetParent() retval=00020198 ret=0062f55e
0009:Call user32.GetParent(00020198) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b8 ret=0060d29d
0009:Call user32.GetWindowLongW(00020198,ffffffec) ret=00605b73
0009:Ret user32.GetWindowLongW() retval=00000340 ret=00605b73
0009:Call user32.SetWindowLongW(00020198,ffffffec,00000140) ret=00605b92
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032cecc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032cecc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032cecc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg=WM_STYLECHANGING,wp=ffffffec,lp=0032d03c)
0009:Call user32.DefMDIChildProcW(00020198,0000007c,ffffffec,0032d03c) ret=00639d0d
0009:Ret user32.DefMDIChildProcW() retval=00000000 ret=00639d0d
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg=WM_STYLECHANGING,wp=ffffffec,lp=0032d03c) retval=00000000
0009:Call winex11.drv.SetWindowStyle(00020198,ffffffec,0032d03c) ret=7ed08b10
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed08b10
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032cecc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032cecc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032cecc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg=WM_STYLECHANGED,wp=ffffffec,lp=0032d03c)
0009:Call user32.DefMDIChildProcW(00020198,0000007d,ffffffec,0032d03c) ret=00639d0d
0009:Ret user32.DefMDIChildProcW() retval=00000000 ret=00639d0d
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg=WM_STYLECHANGED,wp=ffffffec,lp=0032d03c) retval=00000000
0009:Ret user32.SetWindowLongW() retval=00000340 ret=00605b92
0009:Call user32.SetWindowPos(00020198,00000000,00000000,00000000,00000000,00000000,00000037) ret=00605bad
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032ce1c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032ce1c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032ce1c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg=WM_WINDOWPOSCHANGING,wp=00000000,lp=0032d058)
0009:Call user32.DefMDIChildProcW(00020198,00000046,00000000,0032d058) ret=00639d0d
0009:Ret user32.DefMDIChildProcW() retval=00000000 ret=00639d0d
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg=WM_WINDOWPOSCHANGING,wp=00000000,lp=0032d058) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032cdec)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032cdec) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032cdec) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg=WM_NCCALCSIZE,wp=00000001,lp=0032cef4)
0009:Call user32.IsZoomed(00020198) ret=00bd4043
0009:Ret user32.IsZoomed() retval=00000000 ret=00bd4043
0009:Call user32.GetWindowLongW(00020198,fffffff0) ret=0060cd58
0009:Ret user32.GetWindowLongW() retval=46c70000 ret=0060cd58
0009:Call user32.DefMDIChildProcW(00020198,00000083,00000001,0032cef4) ret=00639d0d
0009:Call winex11.drv.SystemParametersInfo(00000029,00000000,0032c2c8,00000000) ret=7ecf3732
0009:Ret winex11.drv.SystemParametersInfo() retval=00000000 ret=7ecf3732
0009:Ret user32.DefMDIChildProcW() retval=00000300 ret=00639d0d
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg=WM_NCCALCSIZE,wp=00000001,lp=0032cef4) retval=00000000
0009:Call winex11.drv.WindowPosChanging(00020198,00000000,0000003f,0032cfe8,0032cfd8,0032cf48,0032cf24) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(00020198,00000000,0000003f,0032cfe8,0032cfd8,0032cf48,0032cfb8,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032cebc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032cebc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032cebc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg=WM_WINDOWPOSCHANGED,wp=00000000,lp=0032d058)
0009:Call user32.DefMDIChildProcW(00020198,00000047,00000000,0032d058) ret=00639d0d
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032c82c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032c82c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032c82c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg=WM_MOVE,wp=00000000,lp=002d001a)
0009:Call user32.DefMDIChildProcW(00020198,00000003,00000000,002d001a) ret=00639d0d
0009:Ret user32.DefMDIChildProcW() retval=00000000 ret=00639d0d
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg=WM_MOVE,wp=00000000,lp=002d001a) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032c82c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032c82c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032c82c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg=WM_SIZE,wp=00000000,lp=00f20384)
0009:Call user32.GetWindowRect(00020198,0032c5a4) ret=00bd344a
0009:Ret user32.GetWindowRect() retval=00000001 ret=00bd344a
0009:Call user32.DefMDIChildProcW(00020198,00000005,00000000,00f20384) ret=00639d0d
0009:Call winex11.drv.GetKeyboardLayout(00000000) ret=7ecaf9ef
0009:Ret winex11.drv.GetKeyboardLayout() retval=04090409 ret=7ecaf9ef
0009:Ret user32.DefMDIChildProcW() retval=00000000 ret=00639d0d
0009:Call user32.GetParent(00020198) ret=00639e29
0009:Ret user32.GetParent() retval=000100b8 ret=00639e29
0009:Call user32.GetParent(000100b8) ret=00639e2c
0009:Ret user32.GetParent() retval=000100b2 ret=00639e2c
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100b8,00000229,00000000,00000000) ret=00639c9c
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032c3dc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032c3dc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032c3dc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100b8,msg=WM_MDIGETACTIVE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7ed17752,000100b8,00000229,00000000,00000000) ret=00605c53
0009:Call window proc 0x7ed17752 (hwnd=0x100b8,msg=WM_MDIGETACTIVE,wp=00000000,lp=00000000)
0009:Ret window proc 0x7ed17752 (hwnd=0x100b8,msg=WM_MDIGETACTIVE,wp=00000000,lp=00000000) retval=00030192
0009:Ret user32.CallWindowProcW() retval=00030192 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100b8,msg=WM_MDIGETACTIVE,wp=00000000,lp=00000000) retval=00030192
0009:Ret user32.SendMessageW() retval=00030192 ret=00639c9c
0009:Call user32.SendMessageW(000100b8,00000229,00000000,00000000) ret=00639c9c
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032c3dc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032c3dc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032c3dc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100b8,msg=WM_MDIGETACTIVE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7ed17752,000100b8,00000229,00000000,00000000) ret=00605c53
0009:Call window proc 0x7ed17752 (hwnd=0x100b8,msg=WM_MDIGETACTIVE,wp=00000000,lp=00000000)
0009:Ret window proc 0x7ed17752 (hwnd=0x100b8,msg=WM_MDIGETACTIVE,wp=00000000,lp=00000000) retval=00030192
0009:Ret user32.CallWindowProcW() retval=00030192 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100b8,msg=WM_MDIGETACTIVE,wp=00000000,lp=00000000) retval=00030192
0009:Ret user32.SendMessageW() retval=00030192 ret=00639c9c
0009:Call user32.GetWindowTextLengthW(000100b2) ret=0060aaf1
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032c3cc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032c3cc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032c3cc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100b2,msg=WM_GETTEXTLENGTH,wp=00000000,lp=00000000)
0009:Call user32.DefFrameProcW(000100b2,000100b8,0000000e,00000000,00000000) ret=00639b80
0009:Ret user32.DefFrameProcW() retval=00000014 ret=00639b80
0009:Ret window proc 0x609f5a (hwnd=0x100b2,msg=WM_GETTEXTLENGTH,wp=00000000,lp=00000000) retval=00000014
0009:Ret user32.GetWindowTextLengthW() retval=00000014 ret=0060aaf1
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000003a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076132b8 ret=007aa8ca
0009:Call user32.GetWindowTextW(000100b2,076132c8,00000015) ret=0060ab08
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032c3ac)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032c3ac) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032c3ac) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100b2,msg=WM_GETTEXT,wp=00000015,lp=076132c8)
0009:Call user32.DefFrameProcW(000100b2,000100b8,0000000d,00000015,076132c8) ret=00639b80
0009:Ret user32.DefFrameProcW() retval=00000014 ret=00639b80
0009:Ret window proc 0x609f5a (hwnd=0x100b2,msg=WM_GETTEXT,wp=00000015,lp=076132c8) retval=00000014
0009:Ret user32.GetWindowTextW() retval=00000014 ret=0060ab08
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000014) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07613300 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000028) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619b38 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000024) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619b68 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000028) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619b98 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000022) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619bc8 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000003c) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619bf8 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619bc8) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call KERNEL32.GetModuleFileNameW(00000000,0032c244,00000104) ret=004d744c
0009:Ret KERNEL32.GetModuleFileNameW() retval=0000003d ret=004d744c
0009:Call KERNEL32.lstrcpyW(0032c29e,07619c04 L"ProfStore\\ProfStore.xml") ret=004d747c
0009:Ret KERNEL32.lstrcpyW() retval=0032c29e ret=004d747c
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000096) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619c40 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619bf8) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619b98) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call KERNEL32.GetFullPathNameW(07619c4c L"C:\\Program Files\\Foxit Software\\Foxit Reader\\ProfStore\\ProfStore.xml",00000104,0032c1f0,0032bf4c) ret=0061b12a
0009:Ret KERNEL32.GetFullPathNameW() retval=00000044 ret=0061b12a
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000021a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619ce0 ret=007aa8ca
0009:Call shlwapi.PathStripToRootW(07619cf0 L"C:\\Program Files\\Foxit Software\\Foxit Reader\\ProfStore\\ProfStore.xml") ret=0061af75
0009:Ret shlwapi.PathStripToRootW() retval=00000001 ret=0061af75
0009:Call shlwapi.PathIsUNCW(07619cf0 L"C:\\") ret=0061b1a6
0009:Ret shlwapi.PathIsUNCW() retval=00000000 ret=0061b1a6
0009:Call KERNEL32.GetVolumeInformationW(07619cf0 L"C:\\",00000000,00000000,00000000,0032bf44,0032bf48,00000000,00000000) ret=0061b1cd
0021:Ret KERNEL32.WaitForMultipleObjects() retval=00000001 ret=7ed21227
0021:Call ntdll.RtlFreeHeap(00110000,00000000,0011d568) ret=7ed21135
0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed21135
0021:Call ntdll.RtlAllocateHeap(00110000,00000000,00000324) ret=7ed21165
0021:Ret ntdll.RtlAllocateHeap() retval=0011b9b0 ret=7ed21165
0021:Call ntdll.RtlAllocateHeap(00110000,00000000,00000324) ret=7ed20c89
0021:Ret ntdll.RtlAllocateHeap() retval=0011bce0 ret=7ed20c89
0021:Call ntdll.NtGetTickCount() ret=7ed23f21
0021:Ret ntdll.NtGetTickCount() retval=01c2f18a ret=7ed23f21
0021:Call driver dispatch 0x7ede33e1 (device=0x11b398,irp=0x53e760)
0021:Call ntoskrnl.exe.IoCompleteRequest(0053e760,00000000) ret=7ede389e
0021:Ret ntoskrnl.exe.IoCompleteRequest() retval=7ed487b4 ret=7ede389e
0021:Ret driver dispatch 0x7ede33e1 (device=0x11b398,irp=0x53e760) retval=c0000010
0021:Call ntdll.RtlFreeHeap(00110000,00000000,0011bce0) ret=7ed20eca
0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed20eca
0021:Call KERNEL32.WaitForMultipleObjects(00000002,0053e894,00000000,ffffffff) ret=7ed21227
0009:Ret KERNEL32.GetVolumeInformationW() retval=00000001 ret=0061b1cd
0009:Call KERNEL32.FindFirstFileW(07619c4c L"C:\\Program Files\\Foxit Software\\Foxit Reader\\ProfStore\\ProfStore.xml",0032bf58) ret=0061b21c
0009:Ret KERNEL32.FindFirstFileW() retval=ffffffff ret=0061b21c
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619ce0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000009a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619b98 ret=007aa8ca
0009:Call KERNEL32.CreateFileW(07619c4c L"C:\\Program Files\\Foxit Software\\Foxit Reader\\ProfStore\\ProfStore.xml",80000000,00000003,0032c1d8,00000003,00000080,00000000) ret=0061b5b4
0009:Ret KERNEL32.CreateFileW() retval=ffffffff ret=0061b5b4
0009:Call KERNEL32.GetLastError() ret=0061b0c0
0009:Ret KERNEL32.GetLastError() retval=00000003 ret=0061b0c0
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000009a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619ce0 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619ce0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619b98) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619c40) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619b68) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619b38) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call advapi32.RegOpenKeyExW(80000002,018c8ddc L"Software\\Policies",00000000,00020019,0032c468) ret=004d683b
0009:Ret advapi32.RegOpenKeyExW() retval=00000000 ret=004d683b
0009:Call advapi32.RegOpenKeyExW(000001bc,018c8db8 L"Foxit\\Reader 6.0",00000000,00020019,0032c464) ret=004d6854
0009:Ret advapi32.RegOpenKeyExW() retval=00000002 ret=004d6854
0009:Call advapi32.RegCloseKey(000001bc) ret=004d6862
0009:Ret advapi32.RegCloseKey() retval=00000000 ret=004d6862
0009:Call advapi32.RegOpenKeyExW(80000001,018c8ddc L"Software\\Policies",00000000,00020019,0032c468) ret=004d683b
0009:Ret advapi32.RegOpenKeyExW() retval=00000002 ret=004d683b
0009:Call KERNEL32.WaitForSingleObject(00000084,ffffffff) ret=00625bb5
0009:Ret KERNEL32.WaitForSingleObject() retval=00000000 ret=00625bb5
0009:Call KERNEL32.ReleaseMutex(00000084) ret=006257a9
0009:Ret KERNEL32.ReleaseMutex() retval=00000001 ret=006257a9
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000020) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619b38 ret=007aa8ca
0009:Call KERNEL32.FindResourceW(00000000,000003ba,018bfddc L"CONFIGRES") ret=00447d07
0009:Ret KERNEL32.FindResourceW() retval=00000000 ret=00447d07
0009:Call KERNEL32.MultiByteToWideChar(00000000,00000000,018b6180 "",00000000,00000000,00000000) ret=009fdd13
0009:Ret KERNEL32.MultiByteToWideChar() retval=00000000 ret=009fdd13
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619b38) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call KERNEL32.FindResourceW(00400000,00000f25,00000006) ret=004068b1
0009:Ret KERNEL32.FindResourceW() retval=022edd78 ret=004068b1
0009:Call KERNEL32.LoadResource(00400000,022edd78) ret=00401523
0009:Ret KERNEL32.LoadResource() retval=0264b22c ret=00401523
0009:Call KERNEL32.LockResource(0264b22c) ret=00401533
0009:Ret KERNEL32.LockResource() retval=0264b22c ret=00401533
0009:Call KERNEL32.SizeofResource(00400000,022edd78) ret=00401541
0009:Ret KERNEL32.SizeofResource() retval=00000a82 ret=00401541
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000002a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619b38 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000026) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619b70 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619b38) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000002c) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619b38 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07613300) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000003a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619ba0 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619b70) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619b38) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619ba0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,076132b8) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call user32.GetWindowLongW(00020198,fffffff0) ret=0060cd58
0009:Ret user32.GetWindowLongW() retval=46c70000 ret=0060cd58
0009:Call user32.GetSystemMenu(00020198,00000000) ret=00be763a
0009:Ret user32.GetSystemMenu() retval=00000000 ret=00be763a
0009:Call user32.GetSystemMetrics(00000021) ret=00be749f
0009:Ret user32.GetSystemMetrics() retval=00000004 ret=00be749f
0009:Call user32.GetSystemMetrics(00000020) ret=00be74a8
0009:Ret user32.GetSystemMetrics() retval=00000004 ret=00be74a8
0009:Call user32.IsIconic(00020198) ret=00be74b8
0009:Ret user32.IsIconic() retval=00000000 ret=00be74b8
0009:Call user32.GetWindowLongW(00020198,fffffff0) ret=0060cd58
0009:Ret user32.GetWindowLongW() retval=46c70000 ret=0060cd58
0009:Call user32.GetWindowLongW(00020198,fffffff0) ret=0060cd58
0009:Ret user32.GetWindowLongW() retval=46c70000 ret=0060cd58
0009:Call user32.GetWindowRect(00020198,0032c518) ret=00be750c
0009:Ret user32.GetWindowRect() retval=00000001 ret=00be750c
0009:Call user32.ScreenToClient(00020198,0032c518) ret=0060ff9a
0009:Ret user32.ScreenToClient() retval=00000001 ret=0060ff9a
0009:Call user32.ScreenToClient(00020198,0032c520) ret=0060ffa7
0009:Ret user32.ScreenToClient() retval=00000001 ret=0060ffa7
0009:Call user32.GetWindowLongW(00020198,ffffffec) ret=0060cd72
0009:Ret user32.GetWindowLongW() retval=00000140 ret=0060cd72
0009:Call user32.IsIconic(00020198) ret=00be7528
0009:Ret user32.IsIconic() retval=00000000 ret=00be7528
0009:Call user32.GetSystemMetrics(00000004) ret=00be7533
0009:Call winex11.drv.SystemParametersInfo(00000029,00000000,0032bfc8,00000000) ret=7ecf3732
0009:Ret winex11.drv.SystemParametersInfo() retval=00000000 ret=7ecf3732
0009:Ret user32.GetSystemMetrics() retval=00000013 ret=00be7533
0009:Call user32.OffsetRect(0032c518,00000004,00000017) ret=00be7552
0009:Ret user32.OffsetRect() retval=00000001 ret=00be7552
0009:Call user32.GetSystemMetrics(00000004) ret=00be7559
0009:Call winex11.drv.SystemParametersInfo(00000029,00000000,0032bfc8,00000000) ret=7ecf3732
0009:Ret winex11.drv.SystemParametersInfo() retval=00000000 ret=7ecf3732
0009:Ret user32.GetSystemMetrics() retval=00000013 ret=00be7559
0009:Call user32.IsIconic(00020198) ret=00be7588
0009:Ret user32.IsIconic() retval=00000000 ret=00be7588
0009:Call user32.SendMessageW(00020198,0000c0a1,00000000,00000000) ret=00be77f6
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032c41c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032c41c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032c41c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg="BCGM_ONAFTERUPDATECAPTION",wp=00000000,lp=00000000)
0009:Call user32.DefMDIChildProcW(00020198,0000c0a1,00000000,00000000) ret=00639d0d
0009:Ret user32.DefMDIChildProcW() retval=00000000 ret=00639d0d
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg="BCGM_ONAFTERUPDATECAPTION",wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=00be77f6
0009:Call user32.RedrawWindow(00020198,00000000,00000000,00000541) ret=00be780c
0009:Call winex11.drv.MsgWaitForMultipleObjectsEx(00000000,00000000,00000000,00000020,00000000) ret=7ece4cdc
0009:Ret winex11.drv.MsgWaitForMultipleObjectsEx() retval=00000102 ret=7ece4cdc
0009:Ret user32.RedrawWindow() retval=00000001 ret=00be780c
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg=WM_SIZE,wp=00000000,lp=00f20384) retval=00000000
0009:Ret user32.DefMDIChildProcW() retval=00000000 ret=00639d0d
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg=WM_WINDOWPOSCHANGED,wp=00000000,lp=0032d058) retval=00000000
0009:Ret user32.SetWindowPos() retval=00000001 ret=00605bad
0009:Ret window proc 0x609f5a (hwnd=0x201a2,msg=WM_NCCREATE,wp=00000000,lp=0032d6f0) retval=00000001
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d3cc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d3cc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d3cc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a2,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d590)
0009:Call user32.CallWindowProcW(7ec6acf0,000201a2,00000083,00000000,0032d590) ret=00605c53
0009:Call window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d590)
0009:Call user32.DefWindowProcW(000201a2,00000083,00000000,0032d590) ret=7ed14b5a
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7ed14b5a
0009:Ret window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d590) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a2,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d590) retval=00000000
0009:Call winex11.drv.WindowPosChanging(000201a2,00000001,00000010,0032d620,0032d590,0032d458,0032d434) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201a2,00000001,00000010,0032d620,0032d590,0032d458,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d3cc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d3cc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d3cc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a2,msg=WM_CREATE,wp=00000000,lp=0032d6f0)
0009:Call user32.CallWindowProcW(7ec6acf0,000201a2,00000001,00000000,0032d6f0) ret=00605c53
0009:Call window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_CREATE,wp=00000000,lp=0032d6f0)
0009:Call user32.DefWindowProcW(000201a2,00000001,00000000,0032d6f0) ret=7ed14b5a
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7ed14b5a
0009:Ret window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_CREATE,wp=00000000,lp=0032d6f0) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a2,msg=WM_CREATE,wp=00000000,lp=0032d6f0) retval=00000000
0009:Call winex11.drv.CreateWindow(000201a2) ret=7ed065e9
0009:Ret winex11.drv.CreateWindow() retval=00000001 ret=7ed065e9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d3cc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d3cc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d3cc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a2,msg=WM_SIZE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7ec6acf0,000201a2,00000005,00000000,00000000) ret=00605c53
0009:Call window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_SIZE,wp=00000000,lp=00000000)
0009:Call user32.DefWindowProcW(000201a2,00000005,00000000,00000000) ret=7ed14b5a
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7ed14b5a
0009:Ret window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_SIZE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a2,msg=WM_SIZE,wp=00000000,lp=00000000) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d3cc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d3cc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d3cc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a2,msg=WM_MOVE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7ec6acf0,000201a2,00000003,00000000,00000000) ret=00605c53
0009:Call window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_MOVE,wp=00000000,lp=00000000)
0009:Call user32.DefWindowProcW(000201a2,00000003,00000000,00000000) ret=7ed14b5a
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7ed14b5a
0009:Ret window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_MOVE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a2,msg=WM_MOVE,wp=00000000,lp=00000000) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d38c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d38c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d38c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg=WM_PARENTNOTIFY,wp=e9000001,lp=000201a2)
0009:Call user32.DefMDIChildProcW(00020198,00000210,e9000001,000201a2) ret=00639d0d
0009:Ret user32.DefMDIChildProcW() retval=00000000 ret=00639d0d
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg=WM_PARENTNOTIFY,wp=e9000001,lp=000201a2) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d2ec)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d2ec) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d2ec) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a2,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000)
0009:Call user32.CallWindowProcW(7ec6acf0,000201a2,00000018,00000001,00000000) ret=00605c53
0009:Call window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000)
0009:Call user32.DefWindowProcW(000201a2,00000018,00000001,00000000) ret=7ed14b5a
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7ed14b5a
0009:Ret window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a2,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000) retval=00000000
0009:Call winex11.drv.ShowWindow(000201a2,00000005,0032d3f0,00000057) ret=7ed0ef34
0009:Ret winex11.drv.ShowWindow() retval=00000057 ret=7ed0ef34
0009:Call winex11.drv.SetWindowStyle(000201a2,fffffff0,0032d38c) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call winex11.drv.WindowPosChanging(000201a2,00000000,0000181f,0032d2d0,0032d2c0,0032d258,0032d234) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201a2,00000000,0000181f,0032d2d0,0032d2c0,0032d258,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Ret user32.CreateWindowExW() retval=000201a2 ret=006073ae
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006073eb
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006073eb
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000018) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076132b8 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000018) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076132d8 ret=007aa8ca
0009:Call user32.GetDlgItem(000201a2,0000ea00) ret=0060cbd2
0009:Ret user32.GetDlgItem() retval=00000000 ret=0060cbd2
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,000000c4) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619b38 ret=007aa8ca
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032d730) ret=00607376
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=00607376
0009:Call user32.CreateWindowExW(00000000,018e129c L"SCROLLBAR",00000000,56000000,00000000,00000000,00000001,00000001,000201a2,0000ea00,00400000,00000000) ret=006073ae
0009:Call hook proc 0x60b3f4 (id=WH_CBT,code=3,wp=000201a0,lp=0032d554)
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032ce14) ret=006168cf
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006168cf
0009:Call user32.GetParent(000201a0) ret=0060d29d
0009:Ret user32.GetParent() retval=000201a2 ret=0060d29d
0009:Call user32.SetWindowLongW(000201a0,fffffffc,00609f5a) ret=0060b526
0009:Ret user32.SetWindowLongW() retval=7ed177e0 ret=0060b526
0009:Call KERNEL32.DeactivateActCtx(00000000,001cda20) ret=00615a3e
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=00615a3e
0009:Call user32.CallNextHookEx(000100b0,00000003,000201a0,0032d554) ret=0060b5e3
0009:Ret user32.CallNextHookEx() retval=00000000 ret=0060b5e3
0009:Ret hook proc 0x60b3f4 (id=WH_CBT,code=3,wp=000201a0,lp=0032d554) retval=00000000
0009:Call winex11.drv.WindowPosChanging(000201a0,00000000,00000014,0032d580,0032d580,0032d3b8,0032d394) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201a0,00000000,00000014,0032d580,0032d580,0032d3b8,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d32c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a0,msg=WM_NCCREATE,wp=00000000,lp=0032d650)
0009:Call user32.CallWindowProcW(7ed177e0,000201a0,00000081,00000000,0032d650) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201a0,msg=WM_NCCREATE,wp=00000000,lp=0032d650)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201a0,msg=WM_NCCREATE,wp=00000000,lp=0032d650) retval=00000001
0009:Ret user32.CallWindowProcW() retval=00000001 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a0,msg=WM_NCCREATE,wp=00000000,lp=0032d650) retval=00000001
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d32c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a0,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d4f0)
0009:Call user32.CallWindowProcW(7ed177e0,000201a0,00000083,00000000,0032d4f0) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201a0,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d4f0)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201a0,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d4f0) retval=00000300
0009:Ret user32.CallWindowProcW() retval=00000300 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a0,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d4f0) retval=00000300
0009:Call winex11.drv.WindowPosChanging(000201a0,00000001,00000010,0032d580,0032d4f0,0032d3b8,0032d394) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201a0,00000001,00000010,0032d580,0032d4f0,0032d3b8,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d32c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a0,msg=WM_CREATE,wp=00000000,lp=0032d650)
0009:Call user32.CallWindowProcW(7ed177e0,000201a0,00000001,00000000,0032d650) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201a0,msg=WM_CREATE,wp=00000000,lp=0032d650)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201a0,msg=WM_CREATE,wp=00000000,lp=0032d650) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a0,msg=WM_CREATE,wp=00000000,lp=0032d650) retval=00000000
0009:Call winex11.drv.CreateWindow(000201a0) ret=7ed065e9
0009:Ret winex11.drv.CreateWindow() retval=00000001 ret=7ed065e9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d32c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a0,msg=WM_SIZE,wp=00000000,lp=00010001)
0009:Call user32.CallWindowProcW(7ed177e0,000201a0,00000005,00000000,00010001) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201a0,msg=WM_SIZE,wp=00000000,lp=00010001)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201a0,msg=WM_SIZE,wp=00000000,lp=00010001) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a0,msg=WM_SIZE,wp=00000000,lp=00010001) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d32c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a0,msg=WM_MOVE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7ed177e0,000201a0,00000003,00000000,00000000) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201a0,msg=WM_MOVE,wp=00000000,lp=00000000)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201a0,msg=WM_MOVE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a0,msg=WM_MOVE,wp=00000000,lp=00000000) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d2ec)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d2ec) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d2ec) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a2,msg=WM_PARENTNOTIFY,wp=ea000001,lp=000201a0)
0009:Call user32.CallWindowProcW(7ec6acf0,000201a2,00000210,ea000001,000201a0) ret=00605c53
0009:Call window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_PARENTNOTIFY,wp=ea000001,lp=000201a0)
0009:Call user32.DefWindowProcW(000201a2,00000210,ea000001,000201a0) ret=7ed14b5a
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7ed14b5a
0009:Ret window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_PARENTNOTIFY,wp=ea000001,lp=000201a0) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a2,msg=WM_PARENTNOTIFY,wp=ea000001,lp=000201a0) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d24c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d24c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d24c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a0,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000)
0009:Call user32.CallWindowProcW(7ed177e0,000201a0,00000018,00000001,00000000) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201a0,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201a0,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a0,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000) retval=00000000
0009:Call winex11.drv.ShowWindow(000201a0,00000005,0032d350,00000057) ret=7ed0ef34
0009:Ret winex11.drv.ShowWindow() retval=00000057 ret=7ed0ef34
0009:Call winex11.drv.SetWindowStyle(000201a0,fffffff0,0032d2ec) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call winex11.drv.WindowPosChanging(000201a0,00000000,0000181f,0032d230,0032d220,0032d1b8,0032d194) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201a0,00000000,0000181f,0032d230,0032d220,0032d1b8,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Ret user32.CreateWindowExW() retval=000201a0 ret=006073ae
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006073eb
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006073eb
0009:Call user32.GetDlgItem(000201a2,0000ea00) ret=0060cbd2
0009:Ret user32.GetDlgItem() retval=000201a0 ret=0060cbd2
0009:Call user32.GetParent(000201a0) ret=0060d29d
0009:Ret user32.GetParent() retval=000201a2 ret=0060d29d
0009:Call user32.ShowWindow(000201a0,00000005) ret=0060ceb5
0009:Ret user32.ShowWindow() retval=00000001 ret=0060ceb5
0009:Call user32.GetDlgItem(000201a2,0000ea10) ret=0060cbd2
0009:Ret user32.GetDlgItem() retval=00000000 ret=0060cbd2
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,000000c4) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619c08 ret=007aa8ca
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032d730) ret=00607376
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=00607376
0009:Call user32.CreateWindowExW(00000000,018e129c L"SCROLLBAR",00000000,56000001,00000000,00000000,00000001,00000001,000201a2,0000ea10,00400000,00000000) ret=006073ae
0009:Call hook proc 0x60b3f4 (id=WH_CBT,code=3,wp=000201b6,lp=0032d554)
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032ce14) ret=006168cf
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006168cf
0009:Call user32.GetParent(000201b6) ret=0060d29d
0009:Ret user32.GetParent() retval=000201a2 ret=0060d29d
0009:Call user32.SetWindowLongW(000201b6,fffffffc,00609f5a) ret=0060b526
0009:Ret user32.SetWindowLongW() retval=7ed177e0 ret=0060b526
0009:Call KERNEL32.DeactivateActCtx(00000000,001cda20) ret=00615a3e
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=00615a3e
0009:Call user32.CallNextHookEx(000100b0,00000003,000201b6,0032d554) ret=0060b5e3
0009:Ret user32.CallNextHookEx() retval=00000000 ret=0060b5e3
0009:Ret hook proc 0x60b3f4 (id=WH_CBT,code=3,wp=000201b6,lp=0032d554) retval=00000000
0009:Call winex11.drv.WindowPosChanging(000201b6,00000000,00000014,0032d580,0032d580,0032d3b8,0032d394) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201b6,00000000,00000014,0032d580,0032d580,0032d3b8,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d32c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b6,msg=WM_NCCREATE,wp=00000000,lp=0032d650)
0009:Call user32.CallWindowProcW(7ed177e0,000201b6,00000081,00000000,0032d650) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201b6,msg=WM_NCCREATE,wp=00000000,lp=0032d650)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201b6,msg=WM_NCCREATE,wp=00000000,lp=0032d650) retval=00000001
0009:Ret user32.CallWindowProcW() retval=00000001 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201b6,msg=WM_NCCREATE,wp=00000000,lp=0032d650) retval=00000001
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d32c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b6,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d4f0)
0009:Call user32.CallWindowProcW(7ed177e0,000201b6,00000083,00000000,0032d4f0) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201b6,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d4f0)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201b6,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d4f0) retval=00000300
0009:Ret user32.CallWindowProcW() retval=00000300 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201b6,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d4f0) retval=00000300
0009:Call winex11.drv.WindowPosChanging(000201b6,00000001,00000010,0032d580,0032d4f0,0032d3b8,0032d394) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201b6,00000001,00000010,0032d580,0032d4f0,0032d3b8,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d32c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b6,msg=WM_CREATE,wp=00000000,lp=0032d650)
0009:Call user32.CallWindowProcW(7ed177e0,000201b6,00000001,00000000,0032d650) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201b6,msg=WM_CREATE,wp=00000000,lp=0032d650)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201b6,msg=WM_CREATE,wp=00000000,lp=0032d650) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201b6,msg=WM_CREATE,wp=00000000,lp=0032d650) retval=00000000
0009:Call winex11.drv.CreateWindow(000201b6) ret=7ed065e9
0009:Ret winex11.drv.CreateWindow() retval=00000001 ret=7ed065e9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d32c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b6,msg=WM_SIZE,wp=00000000,lp=00010001)
0009:Call user32.CallWindowProcW(7ed177e0,000201b6,00000005,00000000,00010001) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201b6,msg=WM_SIZE,wp=00000000,lp=00010001)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201b6,msg=WM_SIZE,wp=00000000,lp=00010001) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201b6,msg=WM_SIZE,wp=00000000,lp=00010001) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d32c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b6,msg=WM_MOVE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7ed177e0,000201b6,00000003,00000000,00000000) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201b6,msg=WM_MOVE,wp=00000000,lp=00000000)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201b6,msg=WM_MOVE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201b6,msg=WM_MOVE,wp=00000000,lp=00000000) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d2ec)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d2ec) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d2ec) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a2,msg=WM_PARENTNOTIFY,wp=ea100001,lp=000201b6)
0009:Call user32.CallWindowProcW(7ec6acf0,000201a2,00000210,ea100001,000201b6) ret=00605c53
0009:Call window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_PARENTNOTIFY,wp=ea100001,lp=000201b6)
0009:Call user32.DefWindowProcW(000201a2,00000210,ea100001,000201b6) ret=7ed14b5a
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7ed14b5a
0009:Ret window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_PARENTNOTIFY,wp=ea100001,lp=000201b6) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a2,msg=WM_PARENTNOTIFY,wp=ea100001,lp=000201b6) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d24c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d24c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d24c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b6,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000)
0009:Call user32.CallWindowProcW(7ed177e0,000201b6,00000018,00000001,00000000) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201b6,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201b6,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201b6,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000) retval=00000000
0009:Call winex11.drv.ShowWindow(000201b6,00000005,0032d350,00000057) ret=7ed0ef34
0009:Ret winex11.drv.ShowWindow() retval=00000057 ret=7ed0ef34
0009:Call winex11.drv.SetWindowStyle(000201b6,fffffff0,0032d2ec) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call winex11.drv.WindowPosChanging(000201b6,00000000,0000181f,0032d230,0032d220,0032d1b8,0032d194) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201b6,00000000,0000181f,0032d230,0032d220,0032d1b8,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Ret user32.CreateWindowExW() retval=000201b6 ret=006073ae
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006073eb
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006073eb
0009:Call user32.GetDlgItem(000201a2,0000ea10) ret=0060cbd2
0009:Ret user32.GetDlgItem() retval=000201b6 ret=0060cbd2
0009:Call user32.GetParent(000201b6) ret=0060d29d
0009:Ret user32.GetParent() retval=000201a2 ret=0060d29d
0009:Call user32.ShowWindow(000201b6,00000005) ret=0060ceb5
0009:Ret user32.ShowWindow() retval=00000001 ret=0060ceb5
0009:Call user32.GetDlgItem(000201a2,0000ea20) ret=0060cbd2
0009:Ret user32.GetDlgItem() retval=00000000 ret=0060cbd2
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,000000c4) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619cd8 ret=007aa8ca
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032d730) ret=00607376
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=00607376
0009:Call user32.CreateWindowExW(00000000,018e129c L"SCROLLBAR",00000000,5e000008,00000000,00000000,00000001,00000001,000201a2,0000ea20,00400000,00000000) ret=006073ae
0009:Call hook proc 0x60b3f4 (id=WH_CBT,code=3,wp=000201b4,lp=0032d554)
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032ce14) ret=006168cf
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006168cf
0009:Call user32.GetParent(000201b4) ret=0060d29d
0009:Ret user32.GetParent() retval=000201a2 ret=0060d29d
0009:Call user32.SetWindowLongW(000201b4,fffffffc,00609f5a) ret=0060b526
0009:Ret user32.SetWindowLongW() retval=7ed177e0 ret=0060b526
0009:Call KERNEL32.DeactivateActCtx(00000000,001cda20) ret=00615a3e
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=00615a3e
0009:Call user32.CallNextHookEx(000100b0,00000003,000201b4,0032d554) ret=0060b5e3
0009:Ret user32.CallNextHookEx() retval=00000000 ret=0060b5e3
0009:Ret hook proc 0x60b3f4 (id=WH_CBT,code=3,wp=000201b4,lp=0032d554) retval=00000000
0009:Call winex11.drv.WindowPosChanging(000201b4,00000000,00000014,0032d580,0032d580,0032d3b8,0032d394) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201b4,00000000,00000014,0032d580,0032d580,0032d3b8,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d32c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b4,msg=WM_NCCREATE,wp=00000000,lp=0032d650)
0009:Call user32.CallWindowProcW(7ed177e0,000201b4,00000081,00000000,0032d650) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201b4,msg=WM_NCCREATE,wp=00000000,lp=0032d650)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201b4,msg=WM_NCCREATE,wp=00000000,lp=0032d650) retval=00000001
0009:Ret user32.CallWindowProcW() retval=00000001 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201b4,msg=WM_NCCREATE,wp=00000000,lp=0032d650) retval=00000001
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d32c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b4,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d4f0)
0009:Call user32.CallWindowProcW(7ed177e0,000201b4,00000083,00000000,0032d4f0) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201b4,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d4f0)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201b4,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d4f0) retval=00000300
0009:Ret user32.CallWindowProcW() retval=00000300 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201b4,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d4f0) retval=00000300
0009:Call winex11.drv.WindowPosChanging(000201b4,00000001,00000010,0032d580,0032d4f0,0032d3b8,0032d394) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201b4,00000001,00000010,0032d580,0032d4f0,0032d3b8,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d32c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b4,msg=WM_CREATE,wp=00000000,lp=0032d650)
0009:Call user32.CallWindowProcW(7ed177e0,000201b4,00000001,00000000,0032d650) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201b4,msg=WM_CREATE,wp=00000000,lp=0032d650)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201b4,msg=WM_CREATE,wp=00000000,lp=0032d650) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201b4,msg=WM_CREATE,wp=00000000,lp=0032d650) retval=00000000
0009:Call winex11.drv.CreateWindow(000201b4) ret=7ed065e9
0009:Ret winex11.drv.CreateWindow() retval=00000001 ret=7ed065e9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d32c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b4,msg=WM_SIZE,wp=00000000,lp=00010001)
0009:Call user32.CallWindowProcW(7ed177e0,000201b4,00000005,00000000,00010001) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201b4,msg=WM_SIZE,wp=00000000,lp=00010001)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201b4,msg=WM_SIZE,wp=00000000,lp=00010001) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201b4,msg=WM_SIZE,wp=00000000,lp=00010001) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d32c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d32c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b4,msg=WM_MOVE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7ed177e0,000201b4,00000003,00000000,00000000) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201b4,msg=WM_MOVE,wp=00000000,lp=00000000)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201b4,msg=WM_MOVE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201b4,msg=WM_MOVE,wp=00000000,lp=00000000) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d2ec)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d2ec) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d2ec) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a2,msg=WM_PARENTNOTIFY,wp=ea200001,lp=000201b4)
0009:Call user32.CallWindowProcW(7ec6acf0,000201a2,00000210,ea200001,000201b4) ret=00605c53
0009:Call window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_PARENTNOTIFY,wp=ea200001,lp=000201b4)
0009:Call user32.DefWindowProcW(000201a2,00000210,ea200001,000201b4) ret=7ed14b5a
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7ed14b5a
0009:Ret window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_PARENTNOTIFY,wp=ea200001,lp=000201b4) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a2,msg=WM_PARENTNOTIFY,wp=ea200001,lp=000201b4) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d24c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d24c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d24c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b4,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000)
0009:Call user32.CallWindowProcW(7ed177e0,000201b4,00000018,00000001,00000000) ret=00605c53
0009:Call window proc 0x7ed177e0 (hwnd=0x201b4,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000)
0009:Ret window proc 0x7ed177e0 (hwnd=0x201b4,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201b4,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000) retval=00000000
0009:Call winex11.drv.ShowWindow(000201b4,00000005,0032d350,00000057) ret=7ed0ef34
0009:Ret winex11.drv.ShowWindow() retval=00000057 ret=7ed0ef34
0009:Call winex11.drv.SetWindowStyle(000201b4,fffffff0,0032d2ec) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call winex11.drv.WindowPosChanging(000201b4,00000000,0000181f,0032d230,0032d220,0032d1b8,0032d194) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201b4,00000000,0000181f,0032d230,0032d220,0032d1b8,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Ret user32.CreateWindowExW() retval=000201b4 ret=006073ae
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006073eb
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006073eb
0009:Call user32.GetDlgItem(000201a2,0000ea20) ret=0060cbd2
0009:Ret user32.GetDlgItem() retval=000201b4 ret=0060cbd2
0009:Call user32.GetParent(000201b4) ret=0060d29d
0009:Ret user32.GetParent() retval=000201a2 ret=0060d29d
0009:Call user32.ShowWindow(000201b4,00000005) ret=0060ceb5
0009:Ret user32.ShowWindow() retval=00000001 ret=0060ceb5
0009:Call KERNEL32.GetLastError() ret=0060245c
0009:Ret KERNEL32.GetLastError() retval=00000000 ret=0060245c
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000120) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619da8 ret=007aa8ca
0009:Call user32.SetRectEmpty(07619e70) ret=00576a52
0009:Ret user32.SetRectEmpty() retval=00000001 ret=00576a52
0009:Call KERNEL32.GetLastError() ret=0060245c
0009:Ret KERNEL32.GetLastError() retval=00000000 ret=0060245c
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032d734) ret=00607376
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=00607376
0009:Call user32.CreateWindowExW(00000000,018e3f7c L"AfxFrameOrView100su",00000000,50000000,00000000,00000000,00000014,00000014,000201a2,0000e900,00400000,0032e548) ret=006073ae
0009:Call hook proc 0x60b3f4 (id=WH_CBT,code=3,wp=000201b2,lp=0032d564)
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032ce24) ret=006168cf
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006168cf
0009:Call user32.GetParent(000201b2) ret=0060d29d
0009:Ret user32.GetParent() retval=000201a2 ret=0060d29d
0009:Call user32.SetWindowLongW(000201b2,fffffffc,00609f5a) ret=0060b526
0009:Ret user32.SetWindowLongW() retval=7ec6acf0 ret=0060b526
0009:Call KERNEL32.DeactivateActCtx(00000000,001cda20) ret=00615a3e
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=00615a3e
0009:Call user32.CallNextHookEx(000100b0,00000003,000201b2,0032d564) ret=0060b5e3
0009:Ret user32.CallNextHookEx() retval=00000000 ret=0060b5e3
0009:Ret hook proc 0x60b3f4 (id=WH_CBT,code=3,wp=000201b2,lp=0032d564) retval=00000000
0009:Call winex11.drv.WindowPosChanging(000201b2,00000000,00000014,0032d590,0032d590,0032d3c8,0032d3a4) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201b2,00000000,00000014,0032d590,0032d590,0032d3c8,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d33c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d33c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d33c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b2,msg=WM_NCCREATE,wp=00000000,lp=0032d660)
0009:Call user32.CallWindowProcW(7ec6acf0,000201b2,00000081,00000000,0032d660) ret=00605c53
0009:Call window proc 0x7ec6acf0 (hwnd=0x201b2,msg=WM_NCCREATE,wp=00000000,lp=0032d660)
0009:Call user32.DefWindowProcW(000201b2,00000081,00000000,0032d660) ret=7ed14b5a
0009:Ret user32.DefWindowProcW() retval=00000001 ret=7ed14b5a
0009:Ret window proc 0x7ec6acf0 (hwnd=0x201b2,msg=WM_NCCREATE,wp=00000000,lp=0032d660) retval=00000001
0009:Ret user32.CallWindowProcW() retval=00000001 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201b2,msg=WM_NCCREATE,wp=00000000,lp=0032d660) retval=00000001
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d33c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d33c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d33c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b2,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d500)
0009:Call user32.CallWindowProcW(7ec6acf0,000201b2,00000083,00000000,0032d500) ret=00605c53
0009:Call window proc 0x7ec6acf0 (hwnd=0x201b2,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d500)
0009:Call user32.DefWindowProcW(000201b2,00000083,00000000,0032d500) ret=7ed14b5a
0009:Ret user32.DefWindowProcW() retval=00000300 ret=7ed14b5a
0009:Ret window proc 0x7ec6acf0 (hwnd=0x201b2,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d500) retval=00000300
0009:Ret user32.CallWindowProcW() retval=00000300 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201b2,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d500) retval=00000300
0009:Call winex11.drv.WindowPosChanging(000201b2,00000001,00000010,0032d590,0032d500,0032d3c8,0032d3a4) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201b2,00000001,00000010,0032d590,0032d500,0032d3c8,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d33c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d33c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d33c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b2,msg=WM_CREATE,wp=00000000,lp=0032d660)
0009:Call user32.CallWindowProcW(7ec6acf0,000201b2,00000001,00000000,0032d660) ret=00605c53
0009:Call window proc 0x7ec6acf0 (hwnd=0x201b2,msg=WM_CREATE,wp=00000000,lp=0032d660)
0009:Call user32.DefWindowProcW(000201b2,00000001,00000000,0032d660) ret=7ed14b5a
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7ed14b5a
0009:Ret window proc 0x7ec6acf0 (hwnd=0x201b2,msg=WM_CREATE,wp=00000000,lp=0032d660) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000007c) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619ed0 ret=007aa8ca
0009:Call user32.IsWindowVisible(000201b2) ret=0063c829
0009:Ret user32.IsWindowVisible() retval=00000000 ret=0063c829
0009:Call user32.IsWindowVisible(000201b2) ret=0063c868
0009:Ret user32.IsWindowVisible() retval=00000000 ret=0063c868
0009:Call user32.IsWindowVisible(000201b2) ret=0063c8b2
0009:Ret user32.IsWindowVisible() retval=00000000 ret=0063c8b2
0009:Ret window proc 0x609f5a (hwnd=0x201b2,msg=WM_CREATE,wp=00000000,lp=0032d660) retval=00000000
0009:Call winex11.drv.CreateWindow(000201b2) ret=7ed065e9
0009:Ret winex11.drv.CreateWindow() retval=00000001 ret=7ed065e9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d33c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d33c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d33c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b2,msg=WM_SIZE,wp=00000000,lp=00140014)
0009:Call user32.CallWindowProcW(7ec6acf0,000201b2,00000005,00000000,00140014) ret=00605c53
0009:Call window proc 0x7ec6acf0 (hwnd=0x201b2,msg=WM_SIZE,wp=00000000,lp=00140014)
0009:Call user32.DefWindowProcW(000201b2,00000005,00000000,00140014) ret=7ed14b5a
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7ed14b5a
0009:Ret window proc 0x7ec6acf0 (hwnd=0x201b2,msg=WM_SIZE,wp=00000000,lp=00140014) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201b2,msg=WM_SIZE,wp=00000000,lp=00140014) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d33c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d33c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d33c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b2,msg=WM_MOVE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7ec6acf0,000201b2,00000003,00000000,00000000) ret=00605c53
0009:Call window proc 0x7ec6acf0 (hwnd=0x201b2,msg=WM_MOVE,wp=00000000,lp=00000000)
0009:Call user32.DefWindowProcW(000201b2,00000003,00000000,00000000) ret=7ed14b5a
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7ed14b5a
0009:Ret window proc 0x7ec6acf0 (hwnd=0x201b2,msg=WM_MOVE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201b2,msg=WM_MOVE,wp=00000000,lp=00000000) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d2fc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d2fc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d2fc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a2,msg=WM_PARENTNOTIFY,wp=e9000001,lp=000201b2)
0009:Call user32.CallWindowProcW(7ec6acf0,000201a2,00000210,e9000001,000201b2) ret=00605c53
0009:Call window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_PARENTNOTIFY,wp=e9000001,lp=000201b2)
0009:Call user32.DefWindowProcW(000201a2,00000210,e9000001,000201b2) ret=7ed14b5a
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7ed14b5a
0009:Ret window proc 0x7ec6acf0 (hwnd=0x201a2,msg=WM_PARENTNOTIFY,wp=e9000001,lp=000201b2) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a2,msg=WM_PARENTNOTIFY,wp=e9000001,lp=000201b2) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d25c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d25c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d25c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201b2,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000)
0009:Call user32.CallWindowProcW(7ec6acf0,000201b2,00000018,00000001,00000000) ret=00605c53
0009:Call window proc 0x7ec6acf0 (hwnd=0x201b2,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000)
0009:Call user32.DefWindowProcW(000201b2,00000018,00000001,00000000) ret=7ed14b5a
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7ed14b5a
0009:Ret window proc 0x7ec6acf0 (hwnd=0x201b2,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201b2,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000) retval=00000000
0009:Call winex11.drv.ShowWindow(000201b2,00000005,0032d360,00000057) ret=7ed0ef34
0009:Ret winex11.drv.ShowWindow() retval=00000057 ret=7ed0ef34
0009:Call winex11.drv.SetWindowStyle(000201b2,fffffff0,0032d2fc) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call winex11.drv.WindowPosChanging(000201b2,00000000,0000181f,0032d240,0032d230,0032d1c8,0032d1a4) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201b2,00000000,0000181f,0032d240,0032d230,0032d1c8,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Ret user32.CreateWindowExW() retval=000201b2 ret=006073ae
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006073eb
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006073eb
0009:Call user32.GetParent(000201a2) ret=0060a1e2
0009:Ret user32.GetParent() retval=00020198 ret=0060a1e2
0009:Call user32.GetParent(00020198) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b8 ret=0060d29d
0009:Call user32.GetFocus() ret=006313de
0009:Ret user32.GetFocus() retval=00020184 ret=006313de
0009:Call user32.GetParent(00020184) ret=0060d29d
0009:Ret user32.GetParent() retval=0002018c ret=0060d29d
0009:Call user32.GetDlgCtrlID(00020184) ret=0062f6ee
0009:Ret user32.GetDlgCtrlID() retval=00000000 ret=0062f6ee
0009:Call user32.IsChild(000201a2,00020184) ret=0062f6fc
0009:Ret user32.IsChild() retval=00000000 ret=0062f6fc
0009:Call user32.GetParent(000201a2) ret=0060a1e2
0009:Ret user32.GetParent() retval=00020198 ret=0060a1e2
0009:Call user32.GetParent(00020198) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b8 ret=0060d29d
0009:Call user32.GetFocus() ret=006313de
0009:Ret user32.GetFocus() retval=00020184 ret=006313de
0009:Call user32.GetParent(00020184) ret=0060d29d
0009:Ret user32.GetParent() retval=0002018c ret=0060d29d
0009:Call user32.GetDlgCtrlID(00020184) ret=0062f6ee
0009:Ret user32.GetDlgCtrlID() retval=00000000 ret=0062f6ee
0009:Call user32.IsChild(000201a2,00020184) ret=0062f6fc
0009:Ret user32.IsChild() retval=00000000 ret=0062f6fc
0009:Call user32.PostMessageW(00020198,00000362,0000e001,00000000) ret=0061c7e0
0009:Ret user32.PostMessageW() retval=00000001 ret=0061c7e0
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000000c) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076132f8 ret=007aa8ca
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg=WM_CREATE,wp=00000000,lp=0032df20) retval=00000000
0009:Call winex11.drv.CreateWindow(00020198) ret=7ed065e9
0009:Ret winex11.drv.CreateWindow() retval=00000001 ret=7ed065e9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbfc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbfc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbfc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg=WM_SIZE,wp=00000000,lp=00f20384)
0009:Call user32.GetWindowRect(00020198,0032d974) ret=00bd344a
0009:Ret user32.GetWindowRect() retval=00000001 ret=00bd344a
0009:Call user32.DefMDIChildProcW(00020198,00000005,00000000,00f20384) ret=00639d0d
0009:Ret user32.DefMDIChildProcW() retval=00000000 ret=00639d0d
0009:Call user32.GetParent(00020198) ret=00639e29
0009:Ret user32.GetParent() retval=000100b8 ret=00639e29
0009:Call user32.GetParent(000100b8) ret=00639e2c
0009:Ret user32.GetParent() retval=000100b2 ret=00639e2c
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100b8,00000229,00000000,00000000) ret=00639c9c
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7ac)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d7ac) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7ac) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100b8,msg=WM_MDIGETACTIVE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7ed17752,000100b8,00000229,00000000,00000000) ret=00605c53
0009:Call window proc 0x7ed17752 (hwnd=0x100b8,msg=WM_MDIGETACTIVE,wp=00000000,lp=00000000)
0009:Ret window proc 0x7ed17752 (hwnd=0x100b8,msg=WM_MDIGETACTIVE,wp=00000000,lp=00000000) retval=00030192
0009:Ret user32.CallWindowProcW() retval=00030192 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100b8,msg=WM_MDIGETACTIVE,wp=00000000,lp=00000000) retval=00030192
0009:Ret user32.SendMessageW() retval=00030192 ret=00639c9c
0009:Call user32.SendMessageW(000100b8,00000229,00000000,00000000) ret=00639c9c
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7ac)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d7ac) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7ac) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100b8,msg=WM_MDIGETACTIVE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7ed17752,000100b8,00000229,00000000,00000000) ret=00605c53
0009:Call window proc 0x7ed17752 (hwnd=0x100b8,msg=WM_MDIGETACTIVE,wp=00000000,lp=00000000)
0009:Ret window proc 0x7ed17752 (hwnd=0x100b8,msg=WM_MDIGETACTIVE,wp=00000000,lp=00000000) retval=00030192
0009:Ret user32.CallWindowProcW() retval=00030192 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100b8,msg=WM_MDIGETACTIVE,wp=00000000,lp=00000000) retval=00030192
0009:Ret user32.SendMessageW() retval=00030192 ret=00639c9c
0009:Call user32.GetWindowTextLengthW(000100b2) ret=0060aaf1
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d79c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d79c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d79c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100b2,msg=WM_GETTEXTLENGTH,wp=00000000,lp=00000000)
0009:Call user32.DefFrameProcW(000100b2,000100b8,0000000e,00000000,00000000) ret=00639b80
0009:Ret user32.DefFrameProcW() retval=00000014 ret=00639b80
0009:Ret window proc 0x609f5a (hwnd=0x100b2,msg=WM_GETTEXTLENGTH,wp=00000000,lp=00000000) retval=00000014
0009:Ret user32.GetWindowTextLengthW() retval=00000014 ret=0060aaf1
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000003a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619f58 ret=007aa8ca
0009:Call user32.GetWindowTextW(000100b2,07619f68,00000015) ret=0060ab08
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d77c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d77c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d77c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100b2,msg=WM_GETTEXT,wp=00000015,lp=07619f68)
0009:Call user32.DefFrameProcW(000100b2,000100b8,0000000d,00000015,07619f68) ret=00639b80
0009:Ret user32.DefFrameProcW() retval=00000014 ret=00639b80
0009:Ret window proc 0x609f5a (hwnd=0x100b2,msg=WM_GETTEXT,wp=00000015,lp=07619f68) retval=00000014
0009:Ret user32.GetWindowTextW() retval=00000014 ret=0060ab08
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000014) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07613310 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000028) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619fa0 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000024) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619fd0 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000028) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a000 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000022) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a030 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000003c) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a060 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a030) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call KERNEL32.GetModuleFileNameW(00000000,0032d614,00000104) ret=004d744c
0009:Ret KERNEL32.GetModuleFileNameW() retval=0000003d ret=004d744c
0009:Call KERNEL32.lstrcpyW(0032d66e,0761a06c L"ProfStore\\ProfStore.xml") ret=004d747c
0009:Ret KERNEL32.lstrcpyW() retval=0032d66e ret=004d747c
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000096) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a0a8 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a060) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a000) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call KERNEL32.GetFullPathNameW(0761a0b4 L"C:\\Program Files\\Foxit Software\\Foxit Reader\\ProfStore\\ProfStore.xml",00000104,0032d5c0,0032d31c) ret=0061b12a
0009:Ret KERNEL32.GetFullPathNameW() retval=00000044 ret=0061b12a
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000021a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a148 ret=007aa8ca
0009:Call shlwapi.PathStripToRootW(0761a158 L"C:\\Program Files\\Foxit Software\\Foxit Reader\\ProfStore\\ProfStore.xml") ret=0061af75
0009:Ret shlwapi.PathStripToRootW() retval=00000001 ret=0061af75
0009:Call shlwapi.PathIsUNCW(0761a158 L"C:\\") ret=0061b1a6
0009:Ret shlwapi.PathIsUNCW() retval=00000000 ret=0061b1a6
0009:Call KERNEL32.GetVolumeInformationW(0761a158 L"C:\\",00000000,00000000,00000000,0032d314,0032d318,00000000,00000000) ret=0061b1cd
0021:Ret KERNEL32.WaitForMultipleObjects() retval=00000001 ret=7ed21227
0021:Call ntdll.RtlFreeHeap(00110000,00000000,0011b9b0) ret=7ed21135
0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed21135
0021:Call ntdll.RtlAllocateHeap(00110000,00000000,00000324) ret=7ed21165
0021:Ret ntdll.RtlAllocateHeap() retval=0011b9b0 ret=7ed21165
0021:Call ntdll.RtlAllocateHeap(00110000,00000000,00000324) ret=7ed20c89
0021:Ret ntdll.RtlAllocateHeap() retval=0011bce0 ret=7ed20c89
0021:Call ntdll.NtGetTickCount() ret=7ed23f21
0021:Ret ntdll.NtGetTickCount() retval=01c2f18f ret=7ed23f21
0021:Call driver dispatch 0x7ede33e1 (device=0x11b398,irp=0x53e760)
0021:Call ntoskrnl.exe.IoCompleteRequest(0053e760,00000000) ret=7ede389e
0021:Ret ntoskrnl.exe.IoCompleteRequest() retval=7ed487b4 ret=7ede389e
0021:Ret driver dispatch 0x7ede33e1 (device=0x11b398,irp=0x53e760) retval=c0000010
0021:Call ntdll.RtlFreeHeap(00110000,00000000,0011bce0) ret=7ed20eca
0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed20eca
0021:Call KERNEL32.WaitForMultipleObjects(00000002,0053e894,00000000,ffffffff) ret=7ed21227
0009:Ret KERNEL32.GetVolumeInformationW() retval=00000001 ret=0061b1cd
0009:Call KERNEL32.FindFirstFileW(0761a0b4 L"C:\\Program Files\\Foxit Software\\Foxit Reader\\ProfStore\\ProfStore.xml",0032d328) ret=0061b21c
0009:Ret KERNEL32.FindFirstFileW() retval=ffffffff ret=0061b21c
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a148) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000009a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a000 ret=007aa8ca
0009:Call KERNEL32.CreateFileW(0761a0b4 L"C:\\Program Files\\Foxit Software\\Foxit Reader\\ProfStore\\ProfStore.xml",80000000,00000003,0032d5a8,00000003,00000080,00000000) ret=0061b5b4
0009:Ret KERNEL32.CreateFileW() retval=ffffffff ret=0061b5b4
0009:Call KERNEL32.GetLastError() ret=0061b0c0
0009:Ret KERNEL32.GetLastError() retval=00000003 ret=0061b0c0
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000009a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a148 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a148) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a000) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a0a8) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619fd0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619fa0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call advapi32.RegOpenKeyExW(80000002,018c8ddc L"Software\\Policies",00000000,00020019,0032d838) ret=004d683b
0009:Ret advapi32.RegOpenKeyExW() retval=00000000 ret=004d683b
0009:Call advapi32.RegOpenKeyExW(000001bc,018c8db8 L"Foxit\\Reader 6.0",00000000,00020019,0032d834) ret=004d6854
0009:Ret advapi32.RegOpenKeyExW() retval=00000002 ret=004d6854
0009:Call advapi32.RegCloseKey(000001bc) ret=004d6862
0009:Ret advapi32.RegCloseKey() retval=00000000 ret=004d6862
0009:Call advapi32.RegOpenKeyExW(80000001,018c8ddc L"Software\\Policies",00000000,00020019,0032d838) ret=004d683b
0009:Ret advapi32.RegOpenKeyExW() retval=00000002 ret=004d683b
0009:Call KERNEL32.WaitForSingleObject(00000084,ffffffff) ret=00625bb5
0009:Ret KERNEL32.WaitForSingleObject() retval=00000000 ret=00625bb5
0009:Call KERNEL32.ReleaseMutex(00000084) ret=006257a9
0009:Ret KERNEL32.ReleaseMutex() retval=00000001 ret=006257a9
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000020) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619fa0 ret=007aa8ca
0009:Call KERNEL32.FindResourceW(00000000,000003ba,018bfddc L"CONFIGRES") ret=00447d07
0009:Ret KERNEL32.FindResourceW() retval=00000000 ret=00447d07
0009:Call KERNEL32.MultiByteToWideChar(00000000,00000000,018b6180 "",00000000,00000000,00000000) ret=009fdd13
0009:Ret KERNEL32.MultiByteToWideChar() retval=00000000 ret=009fdd13
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619fa0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call KERNEL32.FindResourceW(00400000,00000f25,00000006) ret=004068b1
0009:Ret KERNEL32.FindResourceW() retval=022edd78 ret=004068b1
0009:Call KERNEL32.LoadResource(00400000,022edd78) ret=00401523
0009:Ret KERNEL32.LoadResource() retval=0264b22c ret=00401523
0009:Call KERNEL32.LockResource(0264b22c) ret=00401533
0009:Ret KERNEL32.LockResource() retval=0264b22c ret=00401533
0009:Call KERNEL32.SizeofResource(00400000,022edd78) ret=00401541
0009:Ret KERNEL32.SizeofResource() retval=00000a82 ret=00401541
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000002a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619fa0 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000026) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619fd8 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619fa0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000002c) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619fa0 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07613310) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000003a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a008 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619fd8) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619fa0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a008) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619f58) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call user32.GetWindowLongW(00020198,fffffff0) ret=0060cd58
0009:Ret user32.GetWindowLongW() retval=46c70000 ret=0060cd58
0009:Call user32.GetSystemMenu(00020198,00000000) ret=00be763a
0009:Ret user32.GetSystemMenu() retval=00000000 ret=00be763a
0009:Call user32.GetSystemMetrics(00000021) ret=00be749f
0009:Ret user32.GetSystemMetrics() retval=00000004 ret=00be749f
0009:Call user32.GetSystemMetrics(00000020) ret=00be74a8
0009:Ret user32.GetSystemMetrics() retval=00000004 ret=00be74a8
0009:Call user32.IsIconic(00020198) ret=00be74b8
0009:Ret user32.IsIconic() retval=00000000 ret=00be74b8
0009:Call user32.GetWindowLongW(00020198,fffffff0) ret=0060cd58
0009:Ret user32.GetWindowLongW() retval=46c70000 ret=0060cd58
0009:Call user32.GetWindowLongW(00020198,fffffff0) ret=0060cd58
0009:Ret user32.GetWindowLongW() retval=46c70000 ret=0060cd58
0009:Call user32.GetWindowRect(00020198,0032d8e8) ret=00be750c
0009:Ret user32.GetWindowRect() retval=00000001 ret=00be750c
0009:Call user32.ScreenToClient(00020198,0032d8e8) ret=0060ff9a
0009:Ret user32.ScreenToClient() retval=00000001 ret=0060ff9a
0009:Call user32.ScreenToClient(00020198,0032d8f0) ret=0060ffa7
0009:Ret user32.ScreenToClient() retval=00000001 ret=0060ffa7
0009:Call user32.GetWindowLongW(00020198,ffffffec) ret=0060cd72
0009:Ret user32.GetWindowLongW() retval=00000140 ret=0060cd72
0009:Call user32.IsIconic(00020198) ret=00be7528
0009:Ret user32.IsIconic() retval=00000000 ret=00be7528
0009:Call user32.GetSystemMetrics(00000004) ret=00be7533
0009:Call winex11.drv.SystemParametersInfo(00000029,00000000,0032d398,00000000) ret=7ecf3732
0009:Ret winex11.drv.SystemParametersInfo() retval=00000000 ret=7ecf3732
0009:Ret user32.GetSystemMetrics() retval=00000013 ret=00be7533
0009:Call user32.OffsetRect(0032d8e8,00000004,00000017) ret=00be7552
0009:Ret user32.OffsetRect() retval=00000001 ret=00be7552
0009:Call user32.GetSystemMetrics(00000004) ret=00be7559
0009:Call winex11.drv.SystemParametersInfo(00000029,00000000,0032d398,00000000) ret=7ecf3732
0009:Ret winex11.drv.SystemParametersInfo() retval=00000000 ret=7ecf3732
0009:Ret user32.GetSystemMetrics() retval=00000013 ret=00be7559
0009:Call user32.IsIconic(00020198) ret=00be7588
0009:Ret user32.IsIconic() retval=00000000 ret=00be7588
0009:Call user32.SendMessageW(00020198,0000c0a1,00000000,00000000) ret=00be77f6
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7ec)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d7ec) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7ec) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg="BCGM_ONAFTERUPDATECAPTION",wp=00000000,lp=00000000)
0009:Call user32.DefMDIChildProcW(00020198,0000c0a1,00000000,00000000) ret=00639d0d
0009:Ret user32.DefMDIChildProcW() retval=00000000 ret=00639d0d
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg="BCGM_ONAFTERUPDATECAPTION",wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=00be77f6
0009:Call user32.RedrawWindow(00020198,00000000,00000000,00000541) ret=00be780c
0009:Call winex11.drv.MsgWaitForMultipleObjectsEx(00000000,00000000,00000000,00000020,00000000) ret=7ece4cdc
0009:Ret winex11.drv.MsgWaitForMultipleObjectsEx() retval=00000102 ret=7ece4cdc
0009:Ret user32.RedrawWindow() retval=00000001 ret=00be780c
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg=WM_SIZE,wp=00000000,lp=00f20384) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbfc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbfc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbfc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x20198,msg=WM_MOVE,wp=00000000,lp=002d001a)
0009:Call user32.DefMDIChildProcW(00020198,00000003,00000000,002d001a) ret=00639d0d
0009:Ret user32.DefMDIChildProcW() retval=00000000 ret=00639d0d
0009:Ret window proc 0x609f5a (hwnd=0x20198,msg=WM_MOVE,wp=00000000,lp=002d001a) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbbc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100b8,msg=WM_PARENTNOTIFY,wp=ff010001,lp=00020198)
0009:Call user32.CallWindowProcW(7ed17752,000100b8,00000210,ff010001,00020198) ret=00605c53
0009:Call window proc 0x7ed17752 (hwnd=0x100b8,msg=WM_PARENTNOTIFY,wp=ff010001,lp=00020198)
0009:Ret window proc 0x7ed17752 (hwnd=0x100b8,msg=WM_PARENTNOTIFY,wp=ff010001,lp=00020198) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100b8,msg=WM_PARENTNOTIFY,wp=ff010001,lp=00020198) retval=00000000
0009:Ret window proc 0x7ed17752 (hwnd=0x100b8,msg=WM_MDICREATE,wp=00000000,lp=0032e480) retval=00020198
0009:Ret user32.CallWindowProcW() retval=00020198 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100b8,msg=WM_MDICREATE,wp=00000000,lp=0032e480) retval=00020198
0009:Ret user32.SendMessageW() retval=00020198 ret=0063a59e
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,076128c0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619a90) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call user32.SetCursor(0001004a) ret=006350bd
0009:Call winex11.drv.SetCursor(0001004a) ret=7ec8027e
0009:Call winex11.drv.WindowMessage(000100b2,80001003,00000000,0001004a) ret=7ecd3138
0009:Ret winex11.drv.WindowMessage() retval=00000000 ret=7ecd3138
0009:Ret winex11.drv.SetCursor() retval=00000001 ret=7ec8027e
0009:Ret user32.SetCursor() retval=00030166 ret=006350bd
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000184) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619f58 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000018) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07613310 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000038) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619a90 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000250) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a0e8 ret=007aa8ca
0009:Call KERNEL32.InitializeCriticalSectionAndSpinCount(0761a230,00000000) ret=00a0fa6f
0009:Ret KERNEL32.InitializeCriticalSectionAndSpinCount() retval=00000001 ret=00a0fa6f
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000008) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076128c0 ret=007aa8ca
0009:Call KERNEL32.CreateFileW(07618f64 L"C:\\Program Files\\Foxit Software\\Foxit Reader\\file:\\C:\\users\\lizhenbo\\My%20Documents\\Documents\\Science%202013-11-01.pdf",80000000,00000003,00000000,00000003,00000080,00000000) ret=00a0f451
0009:Ret KERNEL32.CreateFileW() retval=ffffffff ret=00a0f451
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,076128c0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlDeleteCriticalSection(0761a230) ret=00a0fa8d
0009:Ret ntdll.RtlDeleteCriticalSection() retval=00000000 ret=00a0fa8d
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a0e8) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000004) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076128c0 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,000000fa) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a0e8 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000004) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076128d8 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000016) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619ad0 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619ad0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,076128d8) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a0e8) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,076128c0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ole32.CoCreateInstance(0628f638,00000000,00000017,06265cc8,0032e474) ret=06141c1a
0009:Call ntdll.RtlInitUnicodeString(0032e1d0,0032e222 L"CLSID\\{A910187F-0C7A-45AC-92CC-59EDAFB77B53}") ret=7e45c6f8
0009:Ret ntdll.RtlInitUnicodeString() retval=0032e1d0 ret=7e45c6f8
0009:Call ntdll.NtOpenKey(0032e21c,00020019,0032e1d8) ret=7e45c714
0009:Ret ntdll.NtOpenKey() retval=c0000034 ret=7e45c714
0009:Call ntdll.RtlNtStatusToDosError(c0000034) ret=7e45c71f
0009:Ret ntdll.RtlNtStatusToDosError() retval=00000002 ret=7e45c71f
0009:Call KERNEL32.FindActCtxSectionGuid(00000001,00000000,00000004,0032e388,0032e26c) ret=7e46277f
0009:Ret KERNEL32.FindActCtxSectionGuid() retval=00000000 ret=7e46277f
0009:Call ntdll.RtlInitUnicodeString(0032e180,0032e1d2 L"CLSID\\{A910187F-0C7A-45AC-92CC-59EDAFB77B53}") ret=7e45c6f8
0009:Ret ntdll.RtlInitUnicodeString() retval=0032e180 ret=7e45c6f8
0009:Call ntdll.NtOpenKey(0032e1cc,00020019,0032e188) ret=7e45c714
0009:Ret ntdll.NtOpenKey() retval=c0000034 ret=7e45c714
0009:Call ntdll.RtlNtStatusToDosError(c0000034) ret=7e45c71f
0009:Ret ntdll.RtlNtStatusToDosError() retval=00000002 ret=7e45c71f
0009:err:ole:CoGetClassObject class {a910187f-0c7a-45ac-92cc-59edafb77b53} not registered
0009:Call ntdll.RtlInitUnicodeString(0032e180,0032e1d2 L"CLSID\\{A910187F-0C7A-45AC-92CC-59EDAFB77B53}") ret=7e45c6f8
0009:Ret ntdll.RtlInitUnicodeString() retval=0032e180 ret=7e45c6f8
0009:Call ntdll.NtOpenKey(0032e1cc,00020019,0032e188) ret=7e45c714
0009:Ret ntdll.NtOpenKey() retval=c0000034 ret=7e45c714
0009:Call ntdll.RtlNtStatusToDosError(c0000034) ret=7e45c71f
0009:Ret ntdll.RtlNtStatusToDosError() retval=00000002 ret=7e45c71f
0009:err:ole:CoGetClassObject class {a910187f-0c7a-45ac-92cc-59edafb77b53} not registered
0009:Call KERNEL32.WaitNamedPipeW(0032e0e8 L"\\\\.\\pipe\\{A910187F-0C7A-45AC-92CC-59EDAFB77B53}",ffffffff) ret=7e4a14af
0009:Ret KERNEL32.WaitNamedPipeW() retval=00000000 ret=7e4a14af
0009:Call KERNEL32.CreateFileW(0032e0e8 L"\\\\.\\pipe\\{A910187F-0C7A-45AC-92CC-59EDAFB77B53}",c0000000,00000000,00000000,00000003,00000000,00000000) ret=7e4a14f0
0009:Ret KERNEL32.CreateFileW() retval=ffffffff ret=7e4a14f0
0009:Call ntdll.RtlInitUnicodeString(0032dd50,0032dda2 L"CLSID\\{A910187F-0C7A-45AC-92CC-59EDAFB77B53}") ret=7e45c6f8
0009:Ret ntdll.RtlInitUnicodeString() retval=0032dd50 ret=7e45c6f8
0009:Call ntdll.NtOpenKey(0032dd9c,00020019,0032dd58) ret=7e45c714
0009:Ret ntdll.NtOpenKey() retval=c0000034 ret=7e45c714
0009:Call ntdll.RtlNtStatusToDosError(c0000034) ret=7e45c71f
0009:Ret ntdll.RtlNtStatusToDosError() retval=00000002 ret=7e45c71f
0009:Call ntdll.RtlInitUnicodeString(0032dc10,0032dc62 L"CLSID\\{A910187F-0C7A-45AC-92CC-59EDAFB77B53}") ret=7e45c6f8
0009:Ret ntdll.RtlInitUnicodeString() retval=0032dc10 ret=7e45c6f8
0009:Call ntdll.NtOpenKey(0032dc5c,00020019,0032dc18) ret=7e45c714
0009:Ret ntdll.NtOpenKey() retval=c0000034 ret=7e45c714
0009:Call ntdll.RtlNtStatusToDosError(c0000034) ret=7e45c71f
0009:Ret ntdll.RtlNtStatusToDosError() retval=00000002 ret=7e45c71f
0009:err:ole:create_server class {a910187f-0c7a-45ac-92cc-59edafb77b53} not registered
0009:fixme:ole:CoGetClassObject CLSCTX_REMOTE_SERVER not supported
0009:err:ole:CoGetClassObject no class object {a910187f-0c7a-45ac-92cc-59edafb77b53} could be created for context 0x17
0009:Ret ole32.CoCreateInstance() retval=80040154 ret=06141c1a
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,000000fa) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a0e8 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000021) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076128c0 ret=007aa8ca
0009:Call KERNEL32.CreateFileW(0761a0f4 L"C:\\Program Files\\Foxit Software\\Foxit Reader\\file:\\C:\\users\\lizhenbo\\My%20Documents\\Documents\\Science%202013-11-01.pdf",80000000,00000003,0032e3c0,00000003,00000080,00000000) ret=007d46f9
0009:Ret KERNEL32.CreateFileW() retval=ffffffff ret=007d46f9
0009:Call KERNEL32.GetLastError() ret=007d475a
0009:Ret KERNEL32.GetLastError() retval=00000003 ret=007d475a
0009:Call KERNEL32.GetLastError() ret=007b3c71
0009:Ret KERNEL32.GetLastError() retval=00000003 ret=007b3c71
0009:Call KERNEL32.GetLastError() ret=007b3c71
0009:Ret KERNEL32.GetLastError() retval=00000003 ret=007b3c71
0009:Call KERNEL32.GetLastError() ret=007b3c71
0009:Ret KERNEL32.GetLastError() retval=00000003 ret=007b3c71
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,076128c0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call shlwapi.PathFileExistsW(0761a0f4 L"C:\\Program Files\\Foxit Software\\Foxit Reader\\file:\\C:\\users\\lizhenbo\\My%20Documents\\Documents\\Science%202013-11-01.pdf") ret=00569034
0009:Call KERNEL32.SetErrorMode(00000001) ret=7e725d6f
0009:Ret KERNEL32.SetErrorMode() retval=00008001 ret=7e725d6f
0009:Call KERNEL32.GetFileAttributesW(0761a0f4 L"C:\\Program Files\\Foxit Software\\Foxit Reader\\file:\\C:\\users\\lizhenbo\\My%20Documents\\Documents\\Science%202013-11-01.pdf") ret=7e725d7f
0009:Ret KERNEL32.GetFileAttributesW() retval=ffffffff ret=7e725d7f
0009:Call KERNEL32.SetErrorMode(00008001) ret=7e725d90
0009:Ret KERNEL32.SetErrorMode() retval=00000001 ret=7e725d90
0009:Ret shlwapi.PathFileExistsW() retval=00000000 ret=00569034
0009:Call KERNEL32.WaitForSingleObject(00000084,ffffffff) ret=00625bb5
0009:Ret KERNEL32.WaitForSingleObject() retval=00000000 ret=00625bb5
0009:Call KERNEL32.ReleaseMutex(00000084) ret=006257a9
002d:Ret KERNEL32.WaitForSingleObject() retval=00000102 ret=06563c87
0009:Ret KERNEL32.ReleaseMutex() retval=00000001 ret=006257a9
002d:Call KERNEL32.WaitForSingleObject(0000014c,ffffffff) ret=065aff9e
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000020) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076128c0 ret=007aa8ca
0009:Call KERNEL32.FindResourceW(00000000,000003ba,018bfddc L"CONFIGRES") ret=00447d07
0009:Ret KERNEL32.FindResourceW() retval=00000000 ret=00447d07
0009:Call KERNEL32.MultiByteToWideChar(00000000,00000000,018b6180 "",00000000,00000000,00000000) ret=009fdd13
0009:Ret KERNEL32.MultiByteToWideChar() retval=00000000 ret=009fdd13
002d:Ret KERNEL32.WaitForSingleObject() retval=00000000 ret=065aff9e
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,076128c0) ret=007a94f7
002d:Call KERNEL32.ReleaseMutex(0000014c) ret=065afedc
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call KERNEL32.FindResourceW(00400000,00000f02,00000006) ret=004068b1
0009:Ret KERNEL32.FindResourceW() retval=022edce8 ret=004068b1
0009:Call KERNEL32.LoadResource(00400000,022edce8) ret=00401523
0009:Ret KERNEL32.LoadResource() retval=02649740 ret=00401523
0009:Call KERNEL32.LockResource(02649740) ret=00401533
002d:Ret KERNEL32.ReleaseMutex() retval=00000001 ret=065afedc
0009:Ret KERNEL32.LockResource() retval=02649740 ret=00401533
0009:Call KERNEL32.SizeofResource(00400000,022edce8) ret=00401541
0009:Ret KERNEL32.SizeofResource() retval=00000252 ret=00401541
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000096) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a1f0 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000092) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a290 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a1f0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000017e) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a330 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000028) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076128c0 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000024) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619ad0 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000028) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619b00 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000022) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a1f0 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000003c) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a220 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a1f0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call KERNEL32.GetModuleFileNameW(00000000,0032dea0,00000104) ret=004d744c
0009:Ret KERNEL32.GetModuleFileNameW() retval=0000003d ret=004d744c
0009:Call KERNEL32.lstrcpyW(0032defa,0761a22c L"ProfStore\\ProfStore.xml") ret=004d747c
0009:Ret KERNEL32.lstrcpyW() retval=0032defa ret=004d747c
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000096) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a4b8 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a220) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619b00) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call KERNEL32.GetFullPathNameW(0761a4c4 L"C:\\Program Files\\Foxit Software\\Foxit Reader\\ProfStore\\ProfStore.xml",00000104,0032de4c,0032dba8) ret=0061b12a
0009:Ret KERNEL32.GetFullPathNameW() retval=00000044 ret=0061b12a
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000021a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a558 ret=007aa8ca
0009:Call shlwapi.PathStripToRootW(0761a568 L"C:\\Program Files\\Foxit Software\\Foxit Reader\\ProfStore\\ProfStore.xml") ret=0061af75
0009:Ret shlwapi.PathStripToRootW() retval=00000001 ret=0061af75
0009:Call shlwapi.PathIsUNCW(0761a568 L"C:\\") ret=0061b1a6
0009:Ret shlwapi.PathIsUNCW() retval=00000000 ret=0061b1a6
0009:Call KERNEL32.GetVolumeInformationW(0761a568 L"C:\\",00000000,00000000,00000000,0032dba0,0032dba4,00000000,00000000) ret=0061b1cd
0021:Ret KERNEL32.WaitForMultipleObjects() retval=00000001 ret=7ed21227
0021:Call ntdll.RtlFreeHeap(00110000,00000000,0011b9b0) ret=7ed21135
0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed21135
0021:Call ntdll.RtlAllocateHeap(00110000,00000000,00000324) ret=7ed21165
0021:Ret ntdll.RtlAllocateHeap() retval=0011b9b0 ret=7ed21165
0021:Call ntdll.RtlAllocateHeap(00110000,00000000,00000324) ret=7ed20c89
0021:Ret ntdll.RtlAllocateHeap() retval=0011bce0 ret=7ed20c89
0021:Call ntdll.NtGetTickCount() ret=7ed23f21
0021:Ret ntdll.NtGetTickCount() retval=01c2f192 ret=7ed23f21
0021:Call driver dispatch 0x7ede33e1 (device=0x11b398,irp=0x53e760)
0021:Call ntoskrnl.exe.IoCompleteRequest(0053e760,00000000) ret=7ede389e
0021:Ret ntoskrnl.exe.IoCompleteRequest() retval=7ed487b4 ret=7ede389e
0021:Ret driver dispatch 0x7ede33e1 (device=0x11b398,irp=0x53e760) retval=c0000010
0021:Call ntdll.RtlFreeHeap(00110000,00000000,0011bce0) ret=7ed20eca
0021:Ret ntdll.RtlFreeHeap() retval=00000001 ret=7ed20eca
0021:Call KERNEL32.WaitForMultipleObjects(00000002,0053e894,00000000,ffffffff) ret=7ed21227
0009:Ret KERNEL32.GetVolumeInformationW() retval=00000001 ret=0061b1cd
0009:Call KERNEL32.FindFirstFileW(0761a4c4 L"C:\\Program Files\\Foxit Software\\Foxit Reader\\ProfStore\\ProfStore.xml",0032dbb4) ret=0061b21c
0009:Ret KERNEL32.FindFirstFileW() retval=ffffffff ret=0061b21c
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a558) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000009a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a558 ret=007aa8ca
0009:Call KERNEL32.CreateFileW(0761a4c4 L"C:\\Program Files\\Foxit Software\\Foxit Reader\\ProfStore\\ProfStore.xml",80000000,00000003,0032de34,00000003,00000080,00000000) ret=0061b5b4
0009:Ret KERNEL32.CreateFileW() retval=ffffffff ret=0061b5b4
0009:Call KERNEL32.GetLastError() ret=0061b0c0
0009:Ret KERNEL32.GetLastError() retval=00000003 ret=0061b0c0
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000009a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a600 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a600) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a558) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a4b8) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619ad0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,076128c0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call advapi32.RegOpenKeyExW(80000002,018c8ddc L"Software\\Policies",00000000,00020019,0032e0c4) ret=004d683b
0009:Ret advapi32.RegOpenKeyExW() retval=00000000 ret=004d683b
0009:Call advapi32.RegOpenKeyExW(000001bc,018c8db8 L"Foxit\\Reader 6.0",00000000,00020019,0032e0c0) ret=004d6854
0009:Ret advapi32.RegOpenKeyExW() retval=00000002 ret=004d6854
0009:Call advapi32.RegCloseKey(000001bc) ret=004d6862
0009:Ret advapi32.RegCloseKey() retval=00000000 ret=004d6862
0009:Call advapi32.RegOpenKeyExW(80000001,018c8ddc L"Software\\Policies",00000000,00020019,0032e0c4) ret=004d683b
0009:Ret advapi32.RegOpenKeyExW() retval=00000002 ret=004d683b
0009:Call KERNEL32.WaitForSingleObject(00000084,ffffffff) ret=00625bb5
0009:Ret KERNEL32.WaitForSingleObject() retval=00000000 ret=00625bb5
0009:Call KERNEL32.ReleaseMutex(00000084) ret=006257a9
0009:Ret KERNEL32.ReleaseMutex() retval=00000001 ret=006257a9
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000020) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076128c0 ret=007aa8ca
0009:Call KERNEL32.FindResourceW(00000000,000003ba,018bfddc L"CONFIGRES") ret=00447d07
0009:Ret KERNEL32.FindResourceW() retval=00000000 ret=00447d07
0009:Call KERNEL32.MultiByteToWideChar(00000000,00000000,018b6180 "",00000000,00000000,00000000) ret=009fdd13
0009:Ret KERNEL32.MultiByteToWideChar() retval=00000000 ret=009fdd13
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,076128c0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call KERNEL32.FindResourceW(00400000,00000f25,00000006) ret=004068b1
0009:Ret KERNEL32.FindResourceW() retval=022edd78 ret=004068b1
0009:Call KERNEL32.LoadResource(00400000,022edd78) ret=00401523
0009:Ret KERNEL32.LoadResource() retval=0264b22c ret=00401523
0009:Call KERNEL32.LockResource(0264b22c) ret=00401533
0009:Ret KERNEL32.LockResource() retval=0264b22c ret=00401533
0009:Call KERNEL32.SizeofResource(00400000,022edd78) ret=00401541
0009:Ret KERNEL32.SizeofResource() retval=00000a82 ret=00401541
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000002a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076128c0 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000026) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619ad0 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,076128c0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call KERNEL32.GetModuleHandleW(00000000) ret=004ed102
0009:Ret KERNEL32.GetModuleHandleW() retval=00400000 ret=004ed102
0009:Call user32.SetRectEmpty(0032e308) ret=00b6ea89
0009:Ret user32.SetRectEmpty() retval=00000001 ret=00b6ea89
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SetRectEmpty(0032e4a8) ret=00600b69
0009:Ret user32.SetRectEmpty() retval=00000001 ret=00600b69
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000001c) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=076128c0 ret=007aa8ca
0009:Call ntdll.RtlReAllocateHeap(028d0000,00000000,076128c0,0000002a) ret=007a955a
0009:Ret ntdll.RtlReAllocateHeap() retval=076128c0 ret=007a955a
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000182) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a4b8 ret=007aa8ca
0009:Call KERNEL32.GlobalAlloc(00000040,00000400) ret=00600ccf
0009:Ret KERNEL32.GlobalAlloc() retval=00204e28 ret=00600ccf
0009:Call user32.SetRect(0032e4d8,00000007,00000007,00000005,00000007) ret=00600d7e
0009:Ret user32.SetRect() retval=00000001 ret=00600d7e
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000008) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619b00 ret=007aa8ca
0009:Call gdi32.CreateFontW(0000000f,00000000,00000000,00000000,00000190,00000000,00000000,00000000,00000001,00000000,00000000,00000000,00000020,018b5ff0 L"Tahoma") ret=00600e22
0009:Ret gdi32.CreateFontW() retval=028803ca ret=00600e22
0009:Call user32.GetWindowLongW(000100b2,fffffff0) ret=006387f2
0009:Ret user32.GetWindowLongW() retval=14c7c000 ret=006387f2
0009:Call user32.GetParent(000100b2) ret=0063880f
0009:Ret user32.GetParent() retval=00000000 ret=0063880f
0009:Call user32.IsWindowEnabled(000100b2) ret=00638838
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=00638838
0009:Call user32.GetDesktopWindow() ret=0061451b
0009:Ret user32.GetDesktopWindow() retval=00010020 ret=0061451b
0009:Call user32.IsWindowEnabled(000100b2) ret=00614529
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=00614529
0009:Call user32.EnableWindow(000100b2,00000000) ret=00614538
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032df8c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032df8c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032df8c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100b2,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.DefFrameProcW(000100b2,000100b8,0000001f,00000000,00000000) ret=00639b80
0009:Ret user32.DefFrameProcW() retval=00000000 ret=00639b80
0009:Ret window proc 0x609f5a (hwnd=0x100b2,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Call winex11.drv.SetWindowStyle(000100b2,fffffff0,0032e02c) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032df8c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032df8c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032df8c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100b2,msg=WM_ENABLE,wp=00000000,lp=00000000)
0009:Call user32.GetParent(000100b2) ret=0061dea6
0009:Ret user32.GetParent() retval=00000000 ret=0061dea6
0009:Call user32.GetParent(000100b2) ret=00443661
0009:Ret user32.GetParent() retval=00000000 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.GetDesktopWindow() ret=0061dd95
0009:Ret user32.GetDesktopWindow() retval=00010020 ret=0061dd95
0009:Call user32.GetWindow(00010020,00000005) ret=0061dd9c
0009:Ret user32.GetWindow() retval=00020186 ret=0061dd9c
0009:Call user32.IsWindowEnabled(00020186) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetWindow(00020186,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=0002018a ret=0061ddfb
0009:Call user32.IsWindowEnabled(0002018a) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetWindow(0002018a,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=000201b0 ret=0061ddfb
0009:Call user32.IsWindowEnabled(000201b0) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetWindow(000201b0,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=0001017a ret=0061ddfb
0009:Call user32.IsWindowEnabled(0001017a) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetParent(000200f2) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(0001017a,0000036c,00000000,00000000) ret=0061ddd9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbbc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x1017a,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(0001017a,00000401,00000000,00000000) ret=0060dcc9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d82c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x1017a,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,0001017a,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x1017a,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(0001017a,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=001d45a8 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x1017a,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x1017a,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dcc9
0009:Ret window proc 0x609f5a (hwnd=0x1017a,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061ddd9
0009:Call user32.EnableWindow(0001017a,00000000) ret=0061dde5
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x1017a,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,0001017a,0000001f,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x1017a,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(0001017a,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=001d45a8 ret=7e67deab
0009:Call user32.DefWindowProcW(0001017a,0000001f,00000000,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x1017a,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x1017a,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Call winex11.drv.SetWindowStyle(0001017a,fffffff0,0032dbfc) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x1017a,msg=WM_ENABLE,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(0001017a,00000401,00000000,00000000) ret=0060dce6
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d7cc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x1017a,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,0001017a,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x1017a,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(0001017a,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=001d45a8 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x1017a,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x1017a,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dce6
0009:Ret window proc 0x609f5a (hwnd=0x1017a,msg=WM_ENABLE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.EnableWindow() retval=00000000 ret=0061dde5
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000004) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=07619b18 ret=007aa8ca
0009:Call user32.GetWindow(0001017a,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=00010160 ret=0061ddfb
0009:Call user32.IsWindowEnabled(00010160) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetWindow(00010160,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=00010156 ret=0061ddfb
0009:Call user32.IsWindowEnabled(00010156) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetWindow(00010156,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=00010150 ret=0061ddfb
0009:Call user32.IsWindowEnabled(00010150) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetWindow(00010150,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=000100fa ret=0061ddfb
0009:Call user32.IsWindowEnabled(000100fa) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetParent(000100f8) ret=0060d29d
0009:Ret user32.GetParent() retval=000200da ret=0060d29d
0009:Call user32.GetParent(000100f8) ret=00443661
0009:Ret user32.GetParent() retval=000200da ret=00443661
0009:Call user32.GetParent(000200da) ret=0060d29d
0009:Ret user32.GetParent() retval=000100ba ret=0060d29d
0009:Call user32.GetParent(000200da) ret=00443661
0009:Ret user32.GetParent() retval=000100ba ret=00443661
0009:Call user32.GetParent(000100ba) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100ba) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100fa,0000036c,00000000,00000000) ret=0061ddd9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbbc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100fa,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100fa,00000401,00000000,00000000) ret=0060dcc9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d82c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100fa,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100fa,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100fa,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100fa,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0017a780 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x100fa,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100fa,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dcc9
0009:Ret window proc 0x609f5a (hwnd=0x100fa,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061ddd9
0009:Call user32.EnableWindow(000100fa,00000000) ret=0061dde5
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100fa,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100fa,0000001f,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100fa,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100fa,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0017a780 ret=7e67deab
0009:Call user32.DefWindowProcW(000100fa,0000001f,00000000,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100fa,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100fa,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Call winex11.drv.SetWindowStyle(000100fa,fffffff0,0032dbfc) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100fa,msg=WM_ENABLE,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100fa,00000401,00000000,00000000) ret=0060dce6
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d7cc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100fa,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100fa,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100fa,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100fa,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0017a780 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x100fa,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100fa,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dce6
0009:Ret window proc 0x609f5a (hwnd=0x100fa,msg=WM_ENABLE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.EnableWindow() retval=00000000 ret=0061dde5
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000014) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a1f0 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,07619b18) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call user32.GetWindow(000100fa,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=000100d6 ret=0061ddfb
0009:Call user32.IsWindowEnabled(000100d6) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetParent(000100d4) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100d4) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100d6,0000036c,00000000,00000000) ret=0061ddd9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbbc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100d6,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100d6,00000401,00000000,00000000) ret=0060dcc9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d82c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100d6,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100d6,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100d6,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100d6,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=00171168 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x100d6,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100d6,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dcc9
0009:Ret window proc 0x609f5a (hwnd=0x100d6,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061ddd9
0009:Call user32.EnableWindow(000100d6,00000000) ret=0061dde5
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100d6,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100d6,0000001f,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100d6,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100d6,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=00171168 ret=7e67deab
0009:Call user32.DefWindowProcW(000100d6,0000001f,00000000,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100d6,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100d6,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Call winex11.drv.SetWindowStyle(000100d6,fffffff0,0032dbfc) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100d6,msg=WM_ENABLE,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100d6,00000401,00000000,00000000) ret=0060dce6
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d7cc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100d6,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100d6,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100d6,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100d6,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=00171168 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x100d6,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100d6,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dce6
0009:Ret window proc 0x609f5a (hwnd=0x100d6,msg=WM_ENABLE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.EnableWindow() retval=00000000 ret=0061dde5
0009:Call user32.GetWindow(000100d6,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=000100d2 ret=0061ddfb
0009:Call user32.IsWindowEnabled(000100d2) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetParent(000100d0) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100d0) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100d2,0000036c,00000000,00000000) ret=0061ddd9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbbc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100d2,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100d2,00000401,00000000,00000000) ret=0060dcc9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d82c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100d2,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100d2,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100d2,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100d2,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016edc0 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x100d2,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100d2,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dcc9
0009:Ret window proc 0x609f5a (hwnd=0x100d2,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061ddd9
0009:Call user32.EnableWindow(000100d2,00000000) ret=0061dde5
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100d2,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100d2,0000001f,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100d2,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100d2,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016edc0 ret=7e67deab
0009:Call user32.DefWindowProcW(000100d2,0000001f,00000000,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100d2,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100d2,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Call winex11.drv.SetWindowStyle(000100d2,fffffff0,0032dbfc) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100d2,msg=WM_ENABLE,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100d2,00000401,00000000,00000000) ret=0060dce6
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d7cc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100d2,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100d2,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100d2,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100d2,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016edc0 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x100d2,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100d2,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dce6
0009:Ret window proc 0x609f5a (hwnd=0x100d2,msg=WM_ENABLE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.EnableWindow() retval=00000000 ret=0061dde5
0009:Call user32.GetWindow(000100d2,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=000100ce ret=0061ddfb
0009:Call user32.IsWindowEnabled(000100ce) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetParent(000100ba) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100ba) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100ce,0000036c,00000000,00000000) ret=0061ddd9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbbc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100ce,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100ce,00000401,00000000,00000000) ret=0060dcc9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d82c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c) retval=00000000
0046:Ret KERNEL32.WaitForSingleObject() retval=00000102 ret=103ad018
0046:Call KERNEL32.QueryPerformanceCounter(111fe860) ret=6af7a0e3
0046:Ret KERNEL32.QueryPerformanceCounter() retval=00000001 ret=6af7a0e3
0046:Call KERNEL32.GetTickCount64() ret=6af7a10b
0009:Call user32.CallWindowProcW(7e67de79,000100ce,00000401,00000000,00000000) ret=00605c53
0046:Ret KERNEL32.GetTickCount64() retval=0000000001c2f194 ret=6af7a10b
0009:Call window proc 0x7e67de79 (hwnd=0x100ce,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0046:Call msvcrt.memmove(115c9f00,115c9f04,00000028) ret=6a08ab01
0009:Ret user32.GetWindowLongW() retval=0016d2e8 ret=7e67deab
0046:Ret msvcrt.memmove() retval=115c9f00 ret=6a08ab01
0009:Ret window proc 0x7e67de79 (hwnd=0x100ce,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0046:Call KERNEL32.GetTickCount64() ret=6af7a10b
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0046:Ret KERNEL32.GetTickCount64() retval=0000000001c2f194 ret=6af7a10b
0009:Ret window proc 0x609f5a (hwnd=0x100ce,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0046:Call user32.PostMessageW(000201b0,0000c0e0,00000000,10dc0ba0) ret=69d80d90
0009:Ret window proc 0x609f5a (hwnd=0x100ce,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061ddd9
0009:Call user32.EnableWindow(000100ce,00000000) ret=0061dde5
0046:Ret user32.PostMessageW() retval=00000001 ret=69d80d90
0046:Call KERNEL32.QueryPerformanceCounter(111fe860) ret=6af7a0e3
0046:Ret KERNEL32.QueryPerformanceCounter() retval=00000001 ret=6af7a0e3
0046:Call KERNEL32.GetTickCount64() ret=6af7a10b
0046:Ret KERNEL32.GetTickCount64() retval=0000000001c2f194 ret=6af7a10b
0046:Call KERNEL32.WaitForSingleObject(000002b4,000005a5) ret=103ad018
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100ce,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100ce,0000001f,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100ce,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100ce,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016d2e8 ret=7e67deab
0009:Call user32.DefWindowProcW(000100ce,0000001f,00000000,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100ce,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100ce,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Call winex11.drv.SetWindowStyle(000100ce,fffffff0,0032dbfc) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100ce,msg=WM_ENABLE,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100ce,00000401,00000000,00000000) ret=0060dce6
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d7cc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100ce,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100ce,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100ce,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100ce,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016d2e8 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x100ce,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100ce,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dce6
0009:Ret window proc 0x609f5a (hwnd=0x100ce,msg=WM_ENABLE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.EnableWindow() retval=00000000 ret=0061dde5
0009:Call user32.GetWindow(000100ce,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=000100cc ret=0061ddfb
0009:Call user32.IsWindowEnabled(000100cc) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetParent(000100ba) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100ba) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100cc,0000036c,00000000,00000000) ret=0061ddd9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbbc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100cc,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100cc,00000401,00000000,00000000) ret=0060dcc9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d82c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100cc,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100cc,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100cc,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100cc,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016c848 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x100cc,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100cc,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dcc9
0009:Ret window proc 0x609f5a (hwnd=0x100cc,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061ddd9
0009:Call user32.EnableWindow(000100cc,00000000) ret=0061dde5
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100cc,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100cc,0000001f,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100cc,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100cc,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016c848 ret=7e67deab
0009:Call user32.DefWindowProcW(000100cc,0000001f,00000000,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100cc,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100cc,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Call winex11.drv.SetWindowStyle(000100cc,fffffff0,0032dbfc) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100cc,msg=WM_ENABLE,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100cc,00000401,00000000,00000000) ret=0060dce6
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d7cc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100cc,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100cc,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100cc,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100cc,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016c848 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x100cc,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100cc,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dce6
0009:Ret window proc 0x609f5a (hwnd=0x100cc,msg=WM_ENABLE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.EnableWindow() retval=00000000 ret=0061dde5
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000024) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a210 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a1f0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call user32.GetWindow(000100cc,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=000100ca ret=0061ddfb
0009:Call user32.IsWindowEnabled(000100ca) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetParent(000100c0) ret=0060d29d
0009:Ret user32.GetParent() retval=000100ba ret=0060d29d
0009:Call user32.GetParent(000100c0) ret=00443661
0009:Ret user32.GetParent() retval=000100ba ret=00443661
0009:Call user32.GetParent(000100ba) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100ba) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100ca,0000036c,00000000,00000000) ret=0061ddd9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbbc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100ca,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100ca,00000401,00000000,00000000) ret=0060dcc9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d82c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100ca,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100ca,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100ca,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100ca,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016bd58 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x100ca,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100ca,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dcc9
0009:Ret window proc 0x609f5a (hwnd=0x100ca,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061ddd9
0009:Call user32.EnableWindow(000100ca,00000000) ret=0061dde5
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100ca,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100ca,0000001f,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100ca,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100ca,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016bd58 ret=7e67deab
0009:Call user32.DefWindowProcW(000100ca,0000001f,00000000,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100ca,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100ca,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Call winex11.drv.SetWindowStyle(000100ca,fffffff0,0032dbfc) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100ca,msg=WM_ENABLE,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100ca,00000401,00000000,00000000) ret=0060dce6
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d7cc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100ca,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100ca,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100ca,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100ca,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016bd58 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x100ca,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100ca,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dce6
0009:Ret window proc 0x609f5a (hwnd=0x100ca,msg=WM_ENABLE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.EnableWindow() retval=00000000 ret=0061dde5
0009:Call user32.GetWindow(000100ca,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=000100c8 ret=0061ddfb
0009:Call user32.IsWindowEnabled(000100c8) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetParent(000100be) ret=0060d29d
0009:Ret user32.GetParent() retval=000100ba ret=0060d29d
0009:Call user32.GetParent(000100be) ret=00443661
0009:Ret user32.GetParent() retval=000100ba ret=00443661
0009:Call user32.GetParent(000100ba) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100ba) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100c8,0000036c,00000000,00000000) ret=0061ddd9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbbc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c8,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100c8,00000401,00000000,00000000) ret=0060dcc9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d82c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c8,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100c8,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100c8,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100c8,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016b268 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x100c8,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100c8,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dcc9
0009:Ret window proc 0x609f5a (hwnd=0x100c8,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061ddd9
0009:Call user32.EnableWindow(000100c8,00000000) ret=0061dde5
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c8,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100c8,0000001f,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100c8,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100c8,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016b268 ret=7e67deab
0009:Call user32.DefWindowProcW(000100c8,0000001f,00000000,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100c8,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100c8,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Call winex11.drv.SetWindowStyle(000100c8,fffffff0,0032dbfc) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c8,msg=WM_ENABLE,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100c8,00000401,00000000,00000000) ret=0060dce6
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d7cc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c8,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100c8,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100c8,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100c8,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016b268 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x100c8,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100c8,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dce6
0009:Ret window proc 0x609f5a (hwnd=0x100c8,msg=WM_ENABLE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.EnableWindow() retval=00000000 ret=0061dde5
0009:Call user32.GetWindow(000100c8,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=000100c6 ret=0061ddfb
0009:Call user32.IsWindowEnabled(000100c6) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetParent(000100bc) ret=0060d29d
0009:Ret user32.GetParent() retval=000100ba ret=0060d29d
0009:Call user32.GetParent(000100bc) ret=00443661
0009:Ret user32.GetParent() retval=000100ba ret=00443661
0009:Call user32.GetParent(000100ba) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100ba) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100c6,0000036c,00000000,00000000) ret=0061ddd9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbbc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c6,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100c6,00000401,00000000,00000000) ret=0060dcc9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d82c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c6,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100c6,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100c6,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100c6,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016a9f8 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x100c6,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100c6,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dcc9
0009:Ret window proc 0x609f5a (hwnd=0x100c6,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061ddd9
0009:Call user32.EnableWindow(000100c6,00000000) ret=0061dde5
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c6,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100c6,0000001f,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100c6,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100c6,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016a9f8 ret=7e67deab
0009:Call user32.DefWindowProcW(000100c6,0000001f,00000000,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100c6,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100c6,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Call winex11.drv.SetWindowStyle(000100c6,fffffff0,0032dbfc) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c6,msg=WM_ENABLE,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100c6,00000401,00000000,00000000) ret=0060dce6
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d7cc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c6,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100c6,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100c6,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100c6,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016a9f8 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x100c6,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100c6,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dce6
0009:Ret window proc 0x609f5a (hwnd=0x100c6,msg=WM_ENABLE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.EnableWindow() retval=00000000 ret=0061dde5
0009:Call user32.GetWindow(000100c6,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=000100c4 ret=0061ddfb
0009:Call user32.IsWindowEnabled(000100c4) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetParent(000100c2) ret=0060d29d
0009:Ret user32.GetParent() retval=000100ba ret=0060d29d
0009:Call user32.GetParent(000100c2) ret=00443661
0009:Ret user32.GetParent() retval=000100ba ret=00443661
0009:Call user32.GetParent(000100ba) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100ba) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100c4,0000036c,00000000,00000000) ret=0061ddd9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbbc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbbc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c4,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100c4,00000401,00000000,00000000) ret=0060dcc9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d82c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d82c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c4,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100c4,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100c4,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100c4,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016a188 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x100c4,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100c4,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dcc9
0009:Ret window proc 0x609f5a (hwnd=0x100c4,msg=WM_DISABLEMODAL,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061ddd9
0009:Call user32.EnableWindow(000100c4,00000000) ret=0061dde5
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c4,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100c4,0000001f,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100c4,msg=WM_CANCELMODE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100c4,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016a188 ret=7e67deab
0009:Call user32.DefWindowProcW(000100c4,0000001f,00000000,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100c4,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100c4,msg=WM_CANCELMODE,wp=00000000,lp=00000000) retval=00000000
0009:Call winex11.drv.SetWindowStyle(000100c4,fffffff0,0032dbfc) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032db5c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032db5c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c4,msg=WM_ENABLE,wp=00000000,lp=00000000)
0009:Call user32.SendMessageW(000100c4,00000401,00000000,00000000) ret=0060dce6
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d7cc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d7cc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c4,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100c4,00000401,00000000,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100c4,msg=TTM_ACTIVATE,wp=00000000,lp=00000000)
0009:Call user32.GetWindowLongW(000100c4,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016a188 ret=7e67deab
0009:Ret window proc 0x7e67de79 (hwnd=0x100c4,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100c4,msg=TTM_ACTIVATE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060dce6
0009:Ret window proc 0x609f5a (hwnd=0x100c4,msg=WM_ENABLE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.EnableWindow() retval=00000000 ret=0061dde5
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000034) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a240 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a210) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call user32.GetWindow(000100c4,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=000100b2 ret=0061ddfb
0009:Call user32.IsWindowEnabled(000100b2) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000000 ret=0061ddad
0009:Call user32.GetWindow(000100b2,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=00010038 ret=0061ddfb
0009:Call user32.IsWindowEnabled(00010038) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetWindow(00010038,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=00010036 ret=0061ddfb
0009:Call user32.IsWindowEnabled(00010036) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetWindow(00010036,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=00010034 ret=0061ddfb
0009:Call user32.IsWindowEnabled(00010034) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetWindow(00010034,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=00010032 ret=0061ddfb
0009:Call user32.IsWindowEnabled(00010032) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetWindow(00010032,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=0001002e ret=0061ddfb
0009:Call user32.IsWindowEnabled(0001002e) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetWindow(0001002e,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=00010176 ret=0061ddfb
0009:Call user32.IsWindowEnabled(00010176) ret=0061ddad
0009:Ret user32.IsWindowEnabled() retval=00000001 ret=0061ddad
0009:Call user32.GetWindow(00010176,00000002) ret=0061ddfb
0009:Ret user32.GetWindow() retval=00000000 ret=0061ddfb
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000002c) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a1f0 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a240) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call user32.GetWindowLongW(000100b2,fffffff0) ret=0060cd58
0009:Ret user32.GetWindowLongW() retval=1cc7c000 ret=0060cd58
0009:Call user32.GetParent(000100b2) ret=0060a1e2
0009:Ret user32.GetParent() retval=00000000 ret=0060a1e2
0009:Call user32.GetDesktopWindow() ret=0061c6b3
0009:Ret user32.GetDesktopWindow() retval=00010020 ret=0061c6b3
0009:Call user32.GetWindow(00010020,00000005) ret=0061c6d9
0009:Ret user32.GetWindow() retval=00020186 ret=0061c6d9
0009:Call user32.GetWindowLongW(00020186,fffffff0) ret=0060ad7e
0009:Ret user32.GetWindowLongW() retval=84000000 ret=0060ad7e
0009:Call user32.GetWindow(00020186,00000004) ret=0060ad97
0009:Ret user32.GetWindow() retval=00000000 ret=0060ad97
0009:Call user32.GetWindow(00020186,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=0002018a ret=0061c6d9
0009:Call user32.GetWindowLongW(0002018a,fffffff0) ret=0060ad7e
0009:Ret user32.GetWindowLongW() retval=84000000 ret=0060ad7e
0009:Call user32.GetWindow(0002018a,00000004) ret=0060ad97
0009:Ret user32.GetWindow() retval=00000000 ret=0060ad97
0009:Call user32.GetWindow(0002018a,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=000201b0 ret=0061c6d9
0009:Call user32.GetWindowLongW(000201b0,fffffff0) ret=0060ad7e
0009:Ret user32.GetWindowLongW() retval=04c00000 ret=0060ad7e
0009:Call user32.GetWindow(000201b0,00000004) ret=0060ad97
0009:Ret user32.GetWindow() retval=00000000 ret=0060ad97
0009:Call user32.GetWindow(000201b0,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=0001017a ret=0061c6d9
0009:Call user32.GetParent(000200f2) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(0001017a,0000036d,00000020,00000000) ret=0061c6d0
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbdc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x1017a,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,0001017a,0000036d,00000020,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x1017a,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.GetWindowLongW(0001017a,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=001d45a8 ret=7e67deab
0009:Call user32.DefWindowProcW(0001017a,0000036d,00000020,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x1017a,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x1017a,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061c6d0
0009:Call user32.GetWindow(0001017a,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=00010160 ret=0061c6d9
0009:Call user32.GetWindowLongW(00010160,fffffff0) ret=0060ad7e
0009:Ret user32.GetWindowLongW() retval=8408004c ret=0060ad7e
0009:Call user32.GetWindow(00010160,00000004) ret=0060ad97
0009:Ret user32.GetWindow() retval=000100b2 ret=0060ad97
0009:Call user32.SendMessageW(00010160,0000036d,00000020,00000000) ret=0061c6d0
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbdc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc) retval=00000000
0009:Call window proc 0x60b28d (hwnd=0x10160,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.GetPropW(00010160,018e3fcc L"AfxOldWndProc423") ret=0060b2b2
0009:Ret user32.GetPropW() retval=065b6756 ret=0060b2b2
0009:Call user32.CallWindowProcW(065b6756,00010160,0000036d,00000020,00000000) ret=0060b3b1
0009:Call window proc 0x65b6756 (hwnd=0x10160,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.CallWindowProcW(7ec8fe8f,00010160,0000036d,00000020,00000000) ret=065b30d6
0009:Call window proc 0x7ec8fe8f (hwnd=0x10160,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call dialog proc 0x65bac3c (hwnd=0x10160,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Ret dialog proc 0x65bac3c (hwnd=0x10160,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000 result=00000000
0009:Ret window proc 0x7ec8fe8f (hwnd=0x10160,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=065b30d6
0009:Ret window proc 0x65b6756 (hwnd=0x10160,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=0060b3b1
0009:Ret window proc 0x60b28d (hwnd=0x10160,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061c6d0
0009:Call user32.GetWindow(00010160,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=00010156 ret=0061c6d9
0009:Call user32.GetWindowLongW(00010156,fffffff0) ret=0060ad7e
0009:Ret user32.GetWindowLongW() retval=84800000 ret=0060ad7e
0009:Call user32.GetWindow(00010156,00000004) ret=0060ad97
0009:Ret user32.GetWindow() retval=00010150 ret=0060ad97
0009:Call user32.GetWindowLongW(00010150,fffffff0) ret=0060ad7e
0009:Ret user32.GetWindowLongW() retval=8408004c ret=0060ad7e
0009:Call user32.GetWindow(00010150,00000004) ret=0060ad97
0009:Ret user32.GetWindow() retval=000100b2 ret=0060ad97
0009:Call user32.SendMessageW(00010156,0000036d,00000020,00000000) ret=0061c6d0
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbdc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc) retval=00000000
0009:Call window proc 0x60b28d (hwnd=0x10156,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.GetPropW(00010156,018e3fcc L"AfxOldWndProc423") ret=0060b2b2
0009:Ret user32.GetPropW() retval=065b6756 ret=0060b2b2
0009:Call user32.CallWindowProcW(065b6756,00010156,0000036d,00000020,00000000) ret=0060b3b1
0009:Call window proc 0x65b6756 (hwnd=0x10156,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,00010156,0000036d,00000020,00000000) ret=065b30d6
0009:Call window proc 0x7e67de79 (hwnd=0x10156,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.GetWindowLongW(00010156,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=001c5138 ret=7e67deab
0009:Call user32.DefWindowProcW(00010156,0000036d,00000020,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x10156,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=065b30d6
0009:Ret window proc 0x65b6756 (hwnd=0x10156,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=0060b3b1
0009:Ret window proc 0x60b28d (hwnd=0x10156,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061c6d0
0009:Call user32.GetWindow(00010156,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=00010150 ret=0061c6d9
0009:Call user32.GetWindowLongW(00010150,fffffff0) ret=0060ad7e
0009:Ret user32.GetWindowLongW() retval=8408004c ret=0060ad7e
0009:Call user32.GetWindow(00010150,00000004) ret=0060ad97
0009:Ret user32.GetWindow() retval=000100b2 ret=0060ad97
0009:Call user32.SendMessageW(00010150,0000036d,00000020,00000000) ret=0061c6d0
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbdc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc) retval=00000000
0009:Call window proc 0x60b28d (hwnd=0x10150,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.GetPropW(00010150,018e3fcc L"AfxOldWndProc423") ret=0060b2b2
0009:Ret user32.GetPropW() retval=065b6756 ret=0060b2b2
0009:Call user32.CallWindowProcW(065b6756,00010150,0000036d,00000020,00000000) ret=0060b3b1
0009:Call window proc 0x65b6756 (hwnd=0x10150,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.CallWindowProcW(7ec8fe8f,00010150,0000036d,00000020,00000000) ret=065b30d6
0009:Call window proc 0x7ec8fe8f (hwnd=0x10150,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call dialog proc 0x65bac3c (hwnd=0x10150,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Ret dialog proc 0x65bac3c (hwnd=0x10150,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000 result=00000000
0009:Ret window proc 0x7ec8fe8f (hwnd=0x10150,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=065b30d6
0009:Ret window proc 0x65b6756 (hwnd=0x10150,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=0060b3b1
0009:Ret window proc 0x60b28d (hwnd=0x10150,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061c6d0
0009:Call user32.GetWindow(00010150,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=000100fa ret=0061c6d9
0009:Call user32.GetParent(000100f8) ret=0060d29d
0009:Ret user32.GetParent() retval=000200da ret=0060d29d
0009:Call user32.GetParent(000100f8) ret=00443661
0009:Ret user32.GetParent() retval=000200da ret=00443661
0009:Call user32.GetParent(000200da) ret=0060d29d
0009:Ret user32.GetParent() retval=000100ba ret=0060d29d
0009:Call user32.GetParent(000200da) ret=00443661
0009:Ret user32.GetParent() retval=000100ba ret=00443661
0009:Call user32.GetParent(000100ba) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100ba) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100fa,0000036d,00000020,00000000) ret=0061c6d0
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbdc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100fa,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100fa,0000036d,00000020,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100fa,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.GetWindowLongW(000100fa,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0017a780 ret=7e67deab
0009:Call user32.DefWindowProcW(000100fa,0000036d,00000020,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100fa,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100fa,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061c6d0
0009:Call user32.GetWindow(000100fa,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=000100d6 ret=0061c6d9
0009:Call user32.GetParent(000100d4) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100d4) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100d6,0000036d,00000020,00000000) ret=0061c6d0
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbdc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100d6,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100d6,0000036d,00000020,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100d6,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.GetWindowLongW(000100d6,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=00171168 ret=7e67deab
0009:Call user32.DefWindowProcW(000100d6,0000036d,00000020,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100d6,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100d6,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061c6d0
0009:Call user32.GetWindow(000100d6,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=000100d2 ret=0061c6d9
0009:Call user32.GetParent(000100d0) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100d0) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100d2,0000036d,00000020,00000000) ret=0061c6d0
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbdc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100d2,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100d2,0000036d,00000020,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100d2,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.GetWindowLongW(000100d2,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016edc0 ret=7e67deab
0009:Call user32.DefWindowProcW(000100d2,0000036d,00000020,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100d2,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100d2,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061c6d0
0009:Call user32.GetWindow(000100d2,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=000100ce ret=0061c6d9
0009:Call user32.GetParent(000100ba) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100ba) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100ce,0000036d,00000020,00000000) ret=0061c6d0
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbdc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100ce,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100ce,0000036d,00000020,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100ce,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.GetWindowLongW(000100ce,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016d2e8 ret=7e67deab
0009:Call user32.DefWindowProcW(000100ce,0000036d,00000020,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100ce,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100ce,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061c6d0
0009:Call user32.GetWindow(000100ce,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=000100cc ret=0061c6d9
0009:Call user32.GetParent(000100ba) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100ba) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100cc,0000036d,00000020,00000000) ret=0061c6d0
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbdc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100cc,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100cc,0000036d,00000020,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100cc,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.GetWindowLongW(000100cc,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016c848 ret=7e67deab
0009:Call user32.DefWindowProcW(000100cc,0000036d,00000020,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100cc,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100cc,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061c6d0
0009:Call user32.GetWindow(000100cc,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=000100ca ret=0061c6d9
0009:Call user32.GetParent(000100c0) ret=0060d29d
0009:Ret user32.GetParent() retval=000100ba ret=0060d29d
0009:Call user32.GetParent(000100c0) ret=00443661
0009:Ret user32.GetParent() retval=000100ba ret=00443661
0009:Call user32.GetParent(000100ba) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100ba) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100ca,0000036d,00000020,00000000) ret=0061c6d0
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbdc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100ca,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100ca,0000036d,00000020,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100ca,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.GetWindowLongW(000100ca,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016bd58 ret=7e67deab
0009:Call user32.DefWindowProcW(000100ca,0000036d,00000020,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100ca,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100ca,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061c6d0
0009:Call user32.GetWindow(000100ca,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=000100c8 ret=0061c6d9
0009:Call user32.GetParent(000100be) ret=0060d29d
0009:Ret user32.GetParent() retval=000100ba ret=0060d29d
0009:Call user32.GetParent(000100be) ret=00443661
0009:Ret user32.GetParent() retval=000100ba ret=00443661
0009:Call user32.GetParent(000100ba) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100ba) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100c8,0000036d,00000020,00000000) ret=0061c6d0
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbdc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c8,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100c8,0000036d,00000020,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100c8,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.GetWindowLongW(000100c8,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016b268 ret=7e67deab
0009:Call user32.DefWindowProcW(000100c8,0000036d,00000020,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100c8,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100c8,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061c6d0
0009:Call user32.GetWindow(000100c8,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=000100c6 ret=0061c6d9
0009:Call user32.GetParent(000100bc) ret=0060d29d
0009:Ret user32.GetParent() retval=000100ba ret=0060d29d
0009:Call user32.GetParent(000100bc) ret=00443661
0009:Ret user32.GetParent() retval=000100ba ret=00443661
0009:Call user32.GetParent(000100ba) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100ba) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100c6,0000036d,00000020,00000000) ret=0061c6d0
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbdc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c6,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100c6,0000036d,00000020,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100c6,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.GetWindowLongW(000100c6,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016a9f8 ret=7e67deab
0009:Call user32.DefWindowProcW(000100c6,0000036d,00000020,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100c6,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100c6,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061c6d0
0009:Call user32.GetWindow(000100c6,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=000100c4 ret=0061c6d9
0009:Call user32.GetParent(000100c2) ret=0060d29d
0009:Ret user32.GetParent() retval=000100ba ret=0060d29d
0009:Call user32.GetParent(000100c2) ret=00443661
0009:Ret user32.GetParent() retval=000100ba ret=00443661
0009:Call user32.GetParent(000100ba) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.GetParent(000100ba) ret=00443661
0009:Ret user32.GetParent() retval=000100b2 ret=00443661
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call user32.SendMessageW(000100c4,0000036d,00000020,00000000) ret=0061c6d0
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbdc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100c4,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.CallWindowProcW(7e67de79,000100c4,0000036d,00000020,00000000) ret=00605c53
0009:Call window proc 0x7e67de79 (hwnd=0x100c4,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.GetWindowLongW(000100c4,00000000) ret=7e67deab
0009:Ret user32.GetWindowLongW() retval=0016a188 ret=7e67deab
0009:Call user32.DefWindowProcW(000100c4,0000036d,00000020,00000000) ret=7e67e751
0009:Ret user32.DefWindowProcW() retval=00000000 ret=7e67e751
0009:Ret window proc 0x7e67de79 (hwnd=0x100c4,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x100c4,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061c6d0
0009:Call user32.GetWindow(000100c4,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=000100b2 ret=0061c6d9
0009:Call user32.SendMessageW(000100b2,0000036d,00000020,00000000) ret=0061c6d0
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbdc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbdc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x100b2,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000)
0009:Call user32.DefFrameProcW(000100b2,000100b8,0000036d,00000020,00000000) ret=00639b80
0009:Ret user32.DefFrameProcW() retval=00000000 ret=00639b80
0009:Ret window proc 0x609f5a (hwnd=0x100b2,msg=WM_FLOATSTATUS,wp=00000020,lp=00000000) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0061c6d0
0009:Call user32.GetWindow(000100b2,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=00010038 ret=0061c6d9
0009:Call user32.GetWindowLongW(00010038,fffffff0) ret=0060ad7e
0009:Ret user32.GetWindowLongW() retval=84000000 ret=0060ad7e
0009:Call user32.GetWindow(00010038,00000004) ret=0060ad97
0009:Ret user32.GetWindow() retval=00000000 ret=0060ad97
0009:Call user32.GetWindow(00010038,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=00010036 ret=0061c6d9
0009:Call user32.GetWindowLongW(00010036,fffffff0) ret=0060ad7e
0009:Ret user32.GetWindowLongW() retval=84000000 ret=0060ad7e
0009:Call user32.GetWindow(00010036,00000004) ret=0060ad97
0009:Ret user32.GetWindow() retval=00000000 ret=0060ad97
0009:Call user32.GetWindow(00010036,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=00010034 ret=0061c6d9
0009:Call user32.GetWindowLongW(00010034,fffffff0) ret=0060ad7e
0009:Ret user32.GetWindowLongW() retval=84000000 ret=0060ad7e
0009:Call user32.GetWindow(00010034,00000004) ret=0060ad97
0009:Ret user32.GetWindow() retval=00000000 ret=0060ad97
0009:Call user32.GetWindow(00010034,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=00010032 ret=0061c6d9
0009:Call user32.GetWindowLongW(00010032,fffffff0) ret=0060ad7e
0009:Ret user32.GetWindowLongW() retval=84000000 ret=0060ad7e
0009:Call user32.GetWindow(00010032,00000004) ret=0060ad97
0009:Ret user32.GetWindow() retval=00000000 ret=0060ad97
0009:Call user32.GetWindow(00010032,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=0001002e ret=0061c6d9
0009:Call user32.GetWindowLongW(0001002e,fffffff0) ret=0060ad7e
0009:Ret user32.GetWindowLongW() retval=84000000 ret=0060ad7e
0009:Call user32.GetWindow(0001002e,00000004) ret=0060ad97
0009:Ret user32.GetWindow() retval=00000000 ret=0060ad97
0009:Call user32.GetWindow(0001002e,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=00010176 ret=0061c6d9
0009:Call user32.GetWindowLongW(00010176,fffffff0) ret=0060ad7e
0009:Ret user32.GetWindowLongW() retval=40000000 ret=0060ad7e
0009:Call user32.GetParent(00010176) ret=0060ad8c
0009:Ret user32.GetParent() retval=00010020 ret=0060ad8c
0009:Call user32.GetWindowLongW(00010020,fffffff0) ret=0060ad7e
0009:Ret user32.GetWindowLongW() retval=96000000 ret=0060ad7e
0009:Call user32.GetWindow(00010020,00000004) ret=0060ad97
0009:Ret user32.GetWindow() retval=00000000 ret=0060ad97
0009:Call user32.GetWindow(00010176,00000002) ret=0061c6d9
0009:Ret user32.GetWindow() retval=00000000 ret=0061c6d9
0009:Ret window proc 0x609f5a (hwnd=0x100b2,msg=WM_ENABLE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.EnableWindow() retval=00000000 ret=00614538
0009:Call user32.IsWindowEnabled(000100b2) ret=0060ced4
0009:Ret user32.IsWindowEnabled() retval=00000000 ret=0060ced4
0009:Call user32.GetParent(000100b2) ret=0060d29d
0009:Ret user32.GetParent() retval=00000000 ret=0060d29d
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e00c) ret=00608729
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=00608729
0009:Call comctl32.InitCommonControlsEx(0032e084) ret=0060875a
0009:Ret comctl32.InitCommonControlsEx() retval=00000001 ret=0060875a
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=00608799
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=00608799
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e00c) ret=00608729
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=00608729
0009:Call comctl32.InitCommonControlsEx(0032e084) ret=0060875a
0009:Ret comctl32.InitCommonControlsEx() retval=00000001 ret=0060875a
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=00608799
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=00608799
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e00c) ret=00608729
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=00608729
0009:Call comctl32.InitCommonControlsEx(0032e084) ret=0060875a
0009:Ret comctl32.InitCommonControlsEx() retval=00000001 ret=0060875a
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=00608799
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=00608799
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e00c) ret=00608729
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=00608729
0009:Call comctl32.InitCommonControlsEx(0032e084) ret=0060875a
0009:Ret comctl32.InitCommonControlsEx() retval=00000001 ret=0060875a
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=00608799
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=00608799
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e00c) ret=00608729
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=00608729
0009:Call comctl32.InitCommonControlsEx(0032e084) ret=0060875a
0009:Ret comctl32.InitCommonControlsEx() retval=00000001 ret=0060875a
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=00608799
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=00608799
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e00c) ret=00608729
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=00608729
0009:Call comctl32.InitCommonControlsEx(0032e084) ret=0060875a
0009:Ret comctl32.InitCommonControlsEx() retval=00000001 ret=0060875a
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=00608799
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=00608799
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e00c) ret=00608729
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=00608729
0009:Call comctl32.InitCommonControlsEx(0032e084) ret=0060875a
0009:Ret comctl32.InitCommonControlsEx() retval=00000001 ret=0060875a
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=00608799
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=00608799
0009:Call KERNEL32.GetVersionExW(0032df7c) ret=006096ac
0009:Ret KERNEL32.GetVersionExW() retval=00000001 ret=006096ac
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e01c) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018df2b0 L"Button",0032e058) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=0000c008 ret=0060727b
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dfc4) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018ee0c8 L"MFCButton",0032e00c) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=00000000 ret=0060727b
0009:Call KERNEL32.GetLastError() ret=006072a7
0009:Ret KERNEL32.GetLastError() retval=00000583 ret=006072a7
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dfcc) ret=006071d3
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006071d3
0009:Call user32.RegisterClassW(0032e058) ret=006071ea
0009:Ret user32.RegisterClassW() retval=0000c0c8 ret=006071ea
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=0060722c
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=0060722c
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e014) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018df2b0 L"Button",0032e050) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=0000c008 ret=0060727b
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dfbc) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018ee0a8 L"MFCColorButton",0032e004) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=00000000 ret=0060727b
0009:Call KERNEL32.GetLastError() ret=006072a7
0009:Ret KERNEL32.GetLastError() retval=00000583 ret=006072a7
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dfc4) ret=006071d3
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006071d3
0009:Call user32.RegisterClassW(0032e050) ret=006071ea
0009:Ret user32.RegisterClassW() retval=0000c0c9 ret=006071ea
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=0060722c
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=0060722c
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e00c) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018df2a4 L"Edit",0032e048) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=0000c00b ret=0060727b
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dfb4) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018ee08c L"MFCEditBrowse",0032dffc) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=00000000 ret=0060727b
0009:Call KERNEL32.GetLastError() ret=006072a7
0009:Ret KERNEL32.GetLastError() retval=00000583 ret=006072a7
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dfbc) ret=006071d3
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006071d3
0009:Call user32.RegisterClassW(0032e048) ret=006071ea
0009:Ret user32.RegisterClassW() retval=0000c0ca ret=006071ea
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=0060722c
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=0060722c
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e004) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018df290 L"ComboBox",0032e040) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=0000c009 ret=0060727b
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dfac) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018ee06c L"MFCFontComboBox",0032dff4) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=00000000 ret=0060727b
0009:Call KERNEL32.GetLastError() ret=006072a7
0009:Ret KERNEL32.GetLastError() retval=00000583 ret=006072a7
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dfb4) ret=006071d3
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006071d3
0009:Call user32.RegisterClassW(0032e040) ret=006071ea
0009:Ret user32.RegisterClassW() retval=0000c0cb ret=006071ea
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=0060722c
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=0060722c
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dffc) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018df2b0 L"Button",0032e038) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=0000c008 ret=0060727b
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dfa4) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018ee05c L"MFCLink",0032dfec) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=00000000 ret=0060727b
0009:Call KERNEL32.GetLastError() ret=006072a7
0009:Ret KERNEL32.GetLastError() retval=00000583 ret=006072a7
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dfac) ret=006071d3
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006071d3
0009:Call user32.RegisterClassW(0032e038) ret=006071ea
0009:Ret user32.RegisterClassW() retval=0000c0cc ret=006071ea
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=0060722c
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=0060722c
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dff4) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018df2a4 L"Edit",0032e030) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=0000c00b ret=0060727b
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032df9c) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018ee040 L"MFCMaskedEdit",0032dfe4) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=00000000 ret=0060727b
0009:Call KERNEL32.GetLastError() ret=006072a7
0009:Ret KERNEL32.GetLastError() retval=00000583 ret=006072a7
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dfa4) ret=006071d3
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006071d3
0009:Call user32.RegisterClassW(0032e030) ret=006071ea
0009:Ret user32.RegisterClassW() retval=0000c0cd ret=006071ea
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=0060722c
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=0060722c
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dfec) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018df2b0 L"Button",0032e028) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=0000c008 ret=0060727b
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032df94) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018ee024 L"MFCMenuButton",0032dfdc) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=00000000 ret=0060727b
0009:Call KERNEL32.GetLastError() ret=006072a7
0009:Ret KERNEL32.GetLastError() retval=00000583 ret=006072a7
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032df9c) ret=006071d3
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006071d3
0009:Call user32.RegisterClassW(0032e028) ret=006071ea
0009:Ret user32.RegisterClassW() retval=0000c0ce ret=006071ea
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=0060722c
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=0060722c
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dfe4) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018df2c0 L"Static",0032e020) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=0000c00f ret=0060727b
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032df8c) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018ee004 L"MFCPropertyGrid",0032dfd4) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=00000000 ret=0060727b
0009:Call KERNEL32.GetLastError() ret=006072a7
0009:Ret KERNEL32.GetLastError() retval=00000583 ret=006072a7
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032df94) ret=006071d3
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006071d3
0009:Call user32.RegisterClassW(0032e020) ret=006071ea
0009:Ret user32.RegisterClassW() retval=0000c0cf ret=006071ea
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=0060722c
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=0060722c
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e01c) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018c5f18 L"SysListView32",0032e058) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=0000c02d ret=0060727b
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dfc4) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018edfe8 L"MFCShellList",0032e00c) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=0000c0d0 ret=0060727b
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e014) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018e6448 L"SysTreeView32",0032e050) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=0000c039 ret=0060727b
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dfbc) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018edfcc L"MFCShellTree",0032e004) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=0000c0d1 ret=0060727b
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032e00c) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018df2c0 L"Static",0032e048) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=0000c00f ret=0060727b
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dfb4) ret=0060725e
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=0060725e
0009:Call user32.GetClassInfoW(00400000,018edfb0 L"MFCVSListBox",0032dffc) ret=0060727b
0009:Ret user32.GetClassInfoW() retval=00000000 ret=0060727b
0009:Call KERNEL32.GetLastError() ret=006072a7
0009:Ret KERNEL32.GetLastError() retval=00000583 ret=006072a7
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=006072b8
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006072b8
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032dfbc) ret=006071d3
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006071d3
0009:Call user32.RegisterClassW(0032e048) ret=006071ea
0009:Ret user32.RegisterClassW() retval=0000c0d2 ret=006071ea
0009:Call KERNEL32.DeactivateActCtx(00000000,001fcc10) ret=0060722c
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=0060722c
0009:Call ntdll.RtlAllocateHeap(028d0000,00000008,00000004) ret=007c56ea
0009:Ret ntdll.RtlAllocateHeap() retval=07619b18 ret=007c56ea
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000001) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a240 ret=007aa8ca
0009:Call KERNEL32.GlobalAlloc(00000040,00000058) ret=006564b9
0009:Ret KERNEL32.GlobalAlloc() retval=11ebe368 ret=006564b9
0009:Call KERNEL32.GlobalLock(11ebe368) ret=006564c7
0009:Ret KERNEL32.GlobalLock() retval=11ebe368 ret=006564c7
0009:Call KERNEL32.GlobalUnlock(11ebe368) ret=006564f0
0009:Ret KERNEL32.GlobalUnlock() retval=00000001 ret=006564f0
0009:Call gdi32.GetStockObject(00000011) ret=006566af
0009:Ret gdi32.GetStockObject() retval=00010021 ret=006566af
0009:Call gdi32.GetObjectW(00010021,0000005c,0032e030) ret=006566c8
0009:Ret gdi32.GetObjectW() retval=0000005c ret=006566c8
0009:Call user32.GetDC(00000000) ret=006566d7
0009:Call winex11.drv.GetDC(000103af,00010020,00010020,0032dec8,0032deb8,00000013) ret=7ece265a
0009:Ret winex11.drv.GetDC() retval=00000001 ret=7ece265a
0009:Call winex11.drv.EnumDisplayMonitors(00000000,00000000,7ecf18e4,0032ddec) ret=7ecdb265
0009:Ret winex11.drv.EnumDisplayMonitors() retval=00000001 ret=7ecdb265
0009:Ret user32.GetDC() retval=000103af ret=006566d7
0009:Call gdi32.GetDeviceCaps(000103af,0000005a) ret=006566eb
0009:Ret gdi32.GetDeviceCaps() retval=00000060 ret=006566eb
0009:Call KERNEL32.MulDiv(0000000b,00000048,00000060) ret=006566f7
0009:Ret KERNEL32.MulDiv() retval=00000008 ret=006566f7
0009:Call user32.ReleaseDC(00000000,000103af) ret=00656703
0009:Ret user32.ReleaseDC() retval=00000001 ret=00656703
0009:Call KERNEL32.GlobalLock(11ebe368) ret=00656583
0009:Ret KERNEL32.GlobalLock() retval=11ebe368 ret=00656583
0009:Call KERNEL32.lstrlenW(0032e04c L"MS Shell Dlg") ret=006565cd
0009:Ret KERNEL32.lstrlenW() retval=0000000c ret=006565cd
0009:Call KERNEL32.GlobalUnlock(11ebe368) ret=00656677
0009:Ret KERNEL32.GlobalUnlock() retval=00000001 ret=00656677
0009:Call KERNEL32.GlobalLock(11ebe368) ret=006143bb
0009:Ret KERNEL32.GlobalLock() retval=11ebe368 ret=006143bb
0009:Call user32.CreateDialogIndirectParamW(00400000,11ebe368,000100b2,00613b7b,00000000) ret=006143ea
0009:Call winex11.drv.SystemParametersInfo(00000029,00000000,0032d728,00000000) ret=7ecf3732
0009:Ret winex11.drv.SystemParametersInfo() retval=00000000 ret=7ecf3732
0009:Call winex11.drv.EnumDisplayMonitors(00000000,00000000,7ecdab74,0032dba4) ret=7ecdb265
0009:Call winex11.drv.GetMonitorInfo(00000001,0032da24) ret=7ecdb195
0009:Ret winex11.drv.GetMonitorInfo() retval=00000001 ret=7ecdb195
0009:Ret winex11.drv.EnumDisplayMonitors() retval=00000001 ret=7ecdb265
0009:Call winex11.drv.GetMonitorInfo(00000001,0032dcfc) ret=7ecdb195
0009:Ret winex11.drv.GetMonitorInfo() retval=00000001 ret=7ecdb195
0009:Call hook proc 0x60b3f4 (id=WH_CBT,code=3,wp=000201ae,lp=0032db64)
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032d424) ret=006168cf
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006168cf
0009:Call user32.GetParent(000201ae) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Call user32.SetWindowLongW(000201ae,fffffffc,00609f5a) ret=0060b526
0009:Ret user32.SetWindowLongW() retval=7ec8fe8f ret=0060b526
0009:Call KERNEL32.DeactivateActCtx(00000000,0017a1c8) ret=00615a3e
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=00615a3e
0009:Call user32.CallNextHookEx(000100b0,00000003,000201ae,0032db64) ret=0060b5e3
0009:Ret user32.CallNextHookEx() retval=00000000 ret=0060b5e3
0009:Ret hook proc 0x60b3f4 (id=WH_CBT,code=3,wp=000201ae,lp=0032db64) retval=00000000
0009:Call winex11.drv.WindowPosChanging(000201ae,00000000,00000014,0032db90,0032db90,0032d9c8,0032d9a4) ret=7ed11c5e
0009:Call winex11.drv.SystemParametersInfo(00000029,00000000,0032c8f8,00000000) ret=7ecf3732
0009:Ret winex11.drv.SystemParametersInfo() retval=00000000 ret=7ecf3732
0009:Call winex11.drv.SystemParametersInfo(00000029,00000000,0032d248,00000000) ret=7ecf3732
0009:Ret winex11.drv.SystemParametersInfo() retval=00000000 ret=7ecf3732
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201ae,00000000,00000014,0032db90,0032db90,0032d9c8,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d93c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d93c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d93c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201ae,msg=WM_NCCREATE,wp=00000000,lp=0032dc60)
0009:Call user32.CallWindowProcW(7ec8fe8f,000201ae,00000081,00000000,0032dc60) ret=00605c53
0009:Call window proc 0x7ec8fe8f (hwnd=0x201ae,msg=WM_NCCREATE,wp=00000000,lp=0032dc60)
0009:Call winex11.drv.SetWindowText(000201ae,0017a1c8 L"") ret=7ec90761
0009:Ret winex11.drv.SetWindowText() retval=00000001 ret=7ec90761
0009:Ret window proc 0x7ec8fe8f (hwnd=0x201ae,msg=WM_NCCREATE,wp=00000000,lp=0032dc60) retval=00000001
0009:Ret user32.CallWindowProcW() retval=00000001 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201ae,msg=WM_NCCREATE,wp=00000000,lp=0032dc60) retval=00000001
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d93c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d93c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d93c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201ae,msg=WM_NCCALCSIZE,wp=00000000,lp=0032db00)
0009:Call user32.CallWindowProcW(7ec8fe8f,000201ae,00000083,00000000,0032db00) ret=00605c53
0009:Call window proc 0x7ec8fe8f (hwnd=0x201ae,msg=WM_NCCALCSIZE,wp=00000000,lp=0032db00)
0009:Call winex11.drv.SystemParametersInfo(00000029,00000000,0032cd98,00000000) ret=7ecf3732
0009:Ret winex11.drv.SystemParametersInfo() retval=00000000 ret=7ecf3732
0009:Ret window proc 0x7ec8fe8f (hwnd=0x201ae,msg=WM_NCCALCSIZE,wp=00000000,lp=0032db00) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201ae,msg=WM_NCCALCSIZE,wp=00000000,lp=0032db00) retval=00000000
0009:Call winex11.drv.WindowPosChanging(000201ae,00000000,00000010,0032db90,0032db00,0032d9c8,0032d9a4) ret=7ed11c5e
0009:Call winex11.drv.SystemParametersInfo(00000029,00000000,0032d248,00000000) ret=7ecf3732
0009:Ret winex11.drv.SystemParametersInfo() retval=00000000 ret=7ecf3732
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201ae,00000000,00000010,0032db90,0032db00,0032d9c8,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d93c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d93c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d93c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201ae,msg=WM_CREATE,wp=00000000,lp=0032dc60)
0009:Call user32.CallWindowProcW(7ec8fe8f,000201ae,00000001,00000000,0032dc60) ret=00605c53
0009:Call window proc 0x7ec8fe8f (hwnd=0x201ae,msg=WM_CREATE,wp=00000000,lp=0032dc60)
0009:Ret window proc 0x7ec8fe8f (hwnd=0x201ae,msg=WM_CREATE,wp=00000000,lp=0032dc60) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Call user32.GetParent(000201ae) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Ret window proc 0x609f5a (hwnd=0x201ae,msg=WM_CREATE,wp=00000000,lp=0032dc60) retval=00000000
0009:Call winex11.drv.CreateWindow(000201ae) ret=7ed065e9
0009:Ret winex11.drv.CreateWindow() retval=00000001 ret=7ed065e9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d93c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d93c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d93c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201ae,msg=WM_SIZE,wp=00000000,lp=0041005d)
0009:Call user32.GetParent(000201ae) ret=0060d29d
0009:Ret user32.GetParent() retval=000100b2 ret=0060d29d
0009:Ret window proc 0x609f5a (hwnd=0x201ae,msg=WM_SIZE,wp=00000000,lp=0041005d) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d93c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d93c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d93c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201ae,msg=WM_MOVE,wp=00000000,lp=015b027d)
0009:Call user32.CallWindowProcW(7ec8fe8f,000201ae,00000003,00000000,015b027d) ret=00605c53
0009:Call window proc 0x7ec8fe8f (hwnd=0x201ae,msg=WM_MOVE,wp=00000000,lp=015b027d)
0009:Ret window proc 0x7ec8fe8f (hwnd=0x201ae,msg=WM_MOVE,wp=00000000,lp=015b027d) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201ae,msg=WM_MOVE,wp=00000000,lp=015b027d) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbcc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbcc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbcc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201ae,msg=WM_SETFONT,wp=019503d3,lp=00000000)
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000034) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a648 ret=007aa8ca
0009:Call user32.CallWindowProcW(7ec8fe8f,000201ae,00000030,019503d3,00000000) ret=00605c53
0009:Call window proc 0x7ec8fe8f (hwnd=0x201ae,msg=WM_SETFONT,wp=019503d3,lp=00000000)
0009:Call dialog proc 0x613b7b (hwnd=0x201ae,msg=WM_SETFONT,wp=019503d3,lp=00000000)
0009:Ret dialog proc 0x613b7b (hwnd=0x201ae,msg=WM_SETFONT,wp=019503d3,lp=00000000) retval=00000000 result=00000000
0009:Ret window proc 0x7ec8fe8f (hwnd=0x201ae,msg=WM_SETFONT,wp=019503d3,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201ae,msg=WM_SETFONT,wp=019503d3,lp=00000000) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbcc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032dbcc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032dbcc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201ae,msg=WM_INITDIALOG,wp=00000000,lp=00000000)
0009:Call user32.GetWindowRect(000201ae,0032da84) ret=0060773f
0009:Ret user32.GetWindowRect() retval=00000001 ret=0060773f
0009:Call user32.GetWindowLongW(000201ae,fffffff0) ret=0060cd58
0009:Ret user32.GetWindowLongW() retval=84c808c4 ret=0060cd58
0009:Call user32.SystemParametersInfoW(00000029,00000000,0032d71c,00000000) ret=00601198
0009:Call winex11.drv.SystemParametersInfo(00000029,00000000,0032d71c,00000000) ret=7ecf3732
0009:Ret winex11.drv.SystemParametersInfo() retval=00000000 ret=7ecf3732
0009:Ret user32.SystemParametersInfoW() retval=00000001 ret=00601198
0009:Call gdi32.CreateFontIndirectW(0032d8b4) ret=006011c1
0009:Ret gdi32.CreateFontIndirectW() retval=003a03e8 ret=006011c1
0009:Call user32.MapDialogRect(000201ae,0032e4d8) ret=006011e0
0009:Ret user32.MapDialogRect() retval=00000001 ret=006011e0
0009:Call user32.MapDialogRect(000201ae,0032d930) ret=0060120e
0009:Ret user32.MapDialogRect() retval=00000001 ret=0060120e
0009:Call user32.MapDialogRect(000201ae,0032d930) ret=0060124e
0009:Ret user32.MapDialogRect() retval=00000001 ret=0060124e
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000026) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a258 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000021a) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a688 ret=007aa8ca
0009:Call KERNEL32.GetSystemDirectoryW(0761a698,00000104) ret=004b7daf
0009:Ret KERNEL32.GetSystemDirectoryW() retval=00000013 ret=004b7daf
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000014) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a8b0 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a8b0) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call KERNEL32.LoadLibraryW(0761a698 L"C:\\windows\\system32\\user32.dll") ret=004b7e6c
0009:Ret KERNEL32.LoadLibraryW() retval=7ec60000 ret=004b7e6c
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a688) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a258) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000200) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a688 ret=007aa8ca
0009:Call KERNEL32.FindResourceExW(7ec60000,00000006,00000033,00000000) ret=005f7c31
0009:Ret KERNEL32.FindResourceExW() retval=00000000 ret=005f7c31
0009:Call KERNEL32.FindResourceExW(7ec60000,00000006,00000033,00000000) ret=005f7c3c
0009:Ret KERNEL32.FindResourceExW() retval=00000000 ret=005f7c3c
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a688) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000016) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a258 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000074) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a688 ret=007aa8ca
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032d58c) ret=00607376
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=00607376
0009:Call user32.CreateWindowExW(00000000,018e5498 L"BUTTON",0761a268 L"OK",50010000,00000000,00000000,0000004e,00000017,000201ae,00000001,00400000,00000000) ret=006073ae
0009:Call hook proc 0x60b3f4 (id=WH_CBT,code=3,wp=000201a8,lp=0032d3b4)
0009:Call KERNEL32.ActivateActCtx(00158fc8,0032cc74) ret=006168cf
0009:Ret KERNEL32.ActivateActCtx() retval=00000001 ret=006168cf
0009:Call user32.GetParent(000201a8) ret=0060d29d
0009:Ret user32.GetParent() retval=000201ae ret=0060d29d
0009:Call user32.SetWindowLongW(000201a8,fffffffc,00609f5a) ret=0060b526
0009:Ret user32.SetWindowLongW() retval=7ed1751a ret=0060b526
0009:Call KERNEL32.DeactivateActCtx(00000000,001cd960) ret=00615a3e
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=00615a3e
0009:Call user32.CallNextHookEx(000100b0,00000003,000201a8,0032d3b4) ret=0060b5e3
0009:Ret user32.CallNextHookEx() retval=00000000 ret=0060b5e3
0009:Ret hook proc 0x60b3f4 (id=WH_CBT,code=3,wp=000201a8,lp=0032d3b4) retval=00000000
0009:Call winex11.drv.WindowPosChanging(000201a8,00000000,00000014,0032d3e0,0032d3e0,0032d218,0032d1f4) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201a8,00000000,00000014,0032d3e0,0032d3e0,0032d218,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d18c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d18c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d18c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a8,msg=WM_NCCREATE,wp=00000000,lp=0032d4b0)
0009:Call user32.CallWindowProcW(7ed1751a,000201a8,00000081,00000000,0032d4b0) ret=00605c53
0009:Call window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_NCCREATE,wp=00000000,lp=0032d4b0)
0009:Call winex11.drv.SetWindowText(000201a8,001cd960 L"OK") ret=7ec90761
0009:Ret winex11.drv.SetWindowText() retval=00000000 ret=7ec90761
0009:Ret window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_NCCREATE,wp=00000000,lp=0032d4b0) retval=00000001
0009:Ret user32.CallWindowProcW() retval=00000001 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a8,msg=WM_NCCREATE,wp=00000000,lp=0032d4b0) retval=00000001
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d18c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d18c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d18c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a8,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d350)
0009:Call user32.CallWindowProcW(7ed1751a,000201a8,00000083,00000000,0032d350) ret=00605c53
0009:Call window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d350)
0009:Ret window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d350) retval=00000300
0009:Ret user32.CallWindowProcW() retval=00000300 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a8,msg=WM_NCCALCSIZE,wp=00000000,lp=0032d350) retval=00000300
0009:Call winex11.drv.WindowPosChanging(000201a8,00000001,00000010,0032d3e0,0032d350,0032d218,0032d1f4) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201a8,00000001,00000010,0032d3e0,0032d350,0032d218,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d18c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d18c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d18c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a8,msg=WM_CREATE,wp=00000000,lp=0032d4b0)
0009:Call user32.CallWindowProcW(7ed1751a,000201a8,00000001,00000000,0032d4b0) ret=00605c53
0009:Call window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_CREATE,wp=00000000,lp=0032d4b0)
0009:Ret window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_CREATE,wp=00000000,lp=0032d4b0) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a8,msg=WM_CREATE,wp=00000000,lp=0032d4b0) retval=00000000
0009:Call winex11.drv.CreateWindow(000201a8) ret=7ed065e9
0009:Ret winex11.drv.CreateWindow() retval=00000001 ret=7ed065e9
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d18c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d18c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d18c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a8,msg=WM_SIZE,wp=00000000,lp=0017004e)
0009:Call user32.CallWindowProcW(7ed1751a,000201a8,00000005,00000000,0017004e) ret=00605c53
0009:Call window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_SIZE,wp=00000000,lp=0017004e)
0009:Ret window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_SIZE,wp=00000000,lp=0017004e) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a8,msg=WM_SIZE,wp=00000000,lp=0017004e) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d18c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d18c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d18c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a8,msg=WM_MOVE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7ed1751a,000201a8,00000003,00000000,00000000) ret=00605c53
0009:Call window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_MOVE,wp=00000000,lp=00000000)
0009:Ret window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_MOVE,wp=00000000,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a8,msg=WM_MOVE,wp=00000000,lp=00000000) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d14c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d14c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d14c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201ae,msg=WM_PARENTNOTIFY,wp=00010001,lp=000201a8)
0009:Call user32.CallWindowProcW(7ec8fe8f,000201ae,00000210,00010001,000201a8) ret=00605c53
0009:Call window proc 0x7ec8fe8f (hwnd=0x201ae,msg=WM_PARENTNOTIFY,wp=00010001,lp=000201a8)
0009:Call dialog proc 0x613b7b (hwnd=0x201ae,msg=WM_PARENTNOTIFY,wp=00010001,lp=000201a8)
0009:Ret dialog proc 0x613b7b (hwnd=0x201ae,msg=WM_PARENTNOTIFY,wp=00010001,lp=000201a8) retval=00000000 result=00000000
0009:Ret window proc 0x7ec8fe8f (hwnd=0x201ae,msg=WM_PARENTNOTIFY,wp=00010001,lp=000201a8) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201ae,msg=WM_PARENTNOTIFY,wp=00010001,lp=000201a8) retval=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d0ac)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d0ac) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d0ac) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a8,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000)
0009:Call user32.CallWindowProcW(7ed1751a,000201a8,00000018,00000001,00000000) ret=00605c53
0009:Call window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000)
0009:Ret window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a8,msg=WM_SHOWWINDOW,wp=00000001,lp=00000000) retval=00000000
0009:Call winex11.drv.ShowWindow(000201a8,00000005,0032d1b0,00000057) ret=7ed0ef34
0009:Ret winex11.drv.ShowWindow() retval=00000057 ret=7ed0ef34
0009:Call winex11.drv.SetWindowStyle(000201a8,fffffff0,0032d14c) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Call winex11.drv.WindowPosChanging(000201a8,00000000,0000181f,0032d090,0032d080,0032d018,0032cff4) ret=7ed11c5e
0009:Ret winex11.drv.WindowPosChanging() retval=00000000 ret=7ed11c5e
0009:Call winex11.drv.WindowPosChanged(000201a8,00000000,0000181f,0032d090,0032d080,0032d018,00000000,00000000) ret=7ed12155
0009:Ret winex11.drv.WindowPosChanged() retval=00000000 ret=7ed12155
0009:Ret user32.CreateWindowExW() retval=000201a8 ret=006073ae
0009:Call KERNEL32.DeactivateActCtx(00000000,120cdef8) ret=006073eb
0009:Ret KERNEL32.DeactivateActCtx() retval=00000001 ret=006073eb
0009:Call user32.SendMessageW(000201ae,00000401,00000001,00000000) ret=00601043
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d57c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d57c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d57c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201ae,msg=WM_USER+1,wp=00000001,lp=00000000)
0009:Call user32.CallWindowProcW(7ec8fe8f,000201ae,00000401,00000001,00000000) ret=00605c53
0009:Call window proc 0x7ec8fe8f (hwnd=0x201ae,msg=WM_USER+1,wp=00000001,lp=00000000)
0009:Call dialog proc 0x613b7b (hwnd=0x201ae,msg=WM_USER+1,wp=00000001,lp=00000000)
0009:Ret dialog proc 0x613b7b (hwnd=0x201ae,msg=WM_USER+1,wp=00000001,lp=00000000) retval=00000000 result=00000000
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d10c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d10c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d10c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a8,msg=WM_GETDLGCODE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7ed1751a,000201a8,00000087,00000000,00000000) ret=00605c53
0009:Call window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_GETDLGCODE,wp=00000000,lp=00000000)
0009:Ret window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_GETDLGCODE,wp=00000000,lp=00000000) retval=00002020
0009:Ret user32.CallWindowProcW() retval=00002020 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a8,msg=WM_GETDLGCODE,wp=00000000,lp=00000000) retval=00002020
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d10c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d10c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d10c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a8,msg=WM_GETDLGCODE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7ed1751a,000201a8,00000087,00000000,00000000) ret=00605c53
0009:Call window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_GETDLGCODE,wp=00000000,lp=00000000)
0009:Ret window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_GETDLGCODE,wp=00000000,lp=00000000) retval=00002020
0009:Ret user32.CallWindowProcW() retval=00002020 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a8,msg=WM_GETDLGCODE,wp=00000000,lp=00000000) retval=00002020
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d0dc)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d0dc) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d0dc) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a8,msg=WM_GETDLGCODE,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7ed1751a,000201a8,00000087,00000000,00000000) ret=00605c53
0009:Call window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_GETDLGCODE,wp=00000000,lp=00000000)
0009:Ret window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_GETDLGCODE,wp=00000000,lp=00000000) retval=00002020
0009:Ret user32.CallWindowProcW() retval=00002020 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a8,msg=WM_GETDLGCODE,wp=00000000,lp=00000000) retval=00002020
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d10c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d10c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d10c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a8,msg=BM_SETSTYLE,wp=00000001,lp=00000001)
0009:Call user32.CallWindowProcW(7ed1751a,000201a8,000000f4,00000001,00000001) ret=00605c53
0009:Call window proc 0x7ed1751a (hwnd=0x201a8,msg=BM_SETSTYLE,wp=00000001,lp=00000001)
0009:Call winex11.drv.SetWindowStyle(000201a8,fffffff0,0032cc9c) ret=7ed03435
0009:Ret winex11.drv.SetWindowStyle() retval=00000000 ret=7ed03435
0009:Ret window proc 0x7ed1751a (hwnd=0x201a8,msg=BM_SETSTYLE,wp=00000001,lp=00000001) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a8,msg=BM_SETSTYLE,wp=00000001,lp=00000001) retval=00000000
0009:Ret window proc 0x7ec8fe8f (hwnd=0x201ae,msg=WM_USER+1,wp=00000001,lp=00000000) retval=00000001
0009:Ret user32.CallWindowProcW() retval=00000001 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201ae,msg=WM_USER+1,wp=00000001,lp=00000000) retval=00000001
0009:Ret user32.SendMessageW() retval=00000001 ret=00601043
0009:Call user32.SendMessageW(000201a8,00000030,028803ca,00000001) ret=0060105f
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d57c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d57c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d57c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a8,msg=WM_SETFONT,wp=028803ca,lp=00000001)
0009:Call user32.CallWindowProcW(7ed1751a,000201a8,00000030,028803ca,00000001) ret=00605c53
0009:Call window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_SETFONT,wp=028803ca,lp=00000001)
0009:Ret window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_SETFONT,wp=028803ca,lp=00000001) retval=00000000
0009:Ret user32.CallWindowProcW() retval=00000000 ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a8,msg=WM_SETFONT,wp=028803ca,lp=00000001) retval=00000000
0009:Ret user32.SendMessageW() retval=00000000 ret=0060105f
0009:Call user32.SendMessageW(000201a8,00000031,00000000,00000000) ret=005fbc25
0009:Call hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d52c)
0009:Call user32.CallNextHookEx(0005003e,00000000,00000001,0032d52c) ret=06540ae9
0009:Ret user32.CallNextHookEx() retval=00000000 ret=06540ae9
0009:Ret hook proc 0x6540a20 (id=WH_CALLWNDPROC,code=0,wp=00000001,lp=0032d52c) retval=00000000
0009:Call window proc 0x609f5a (hwnd=0x201a8,msg=WM_GETFONT,wp=00000000,lp=00000000)
0009:Call user32.CallWindowProcW(7ed1751a,000201a8,00000031,00000000,00000000) ret=00605c53
0009:Call window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_GETFONT,wp=00000000,lp=00000000)
0009:Ret window proc 0x7ed1751a (hwnd=0x201a8,msg=WM_GETFONT,wp=00000000,lp=00000000) retval=028803ca
0009:Ret user32.CallWindowProcW() retval=028803ca ret=00605c53
0009:Ret window proc 0x609f5a (hwnd=0x201a8,msg=WM_GETFONT,wp=00000000,lp=00000000) retval=028803ca
0009:Ret user32.SendMessageW() retval=028803ca ret=005fbc25
0009:Call user32.GetWindowDC(000201a8) ret=0061051f
0009:Call winex11.drv.GetDC(000103af,000201a8,000201ae,0032d4c8,0032d4b8,00000003) ret=7ece265a
0009:Ret winex11.drv.GetDC() retval=00000001 ret=7ece265a
0009:Call winex11.drv.EnumDisplayMonitors(00000000,00000000,7ecf18e4,0032d3ec) ret=7ecdb265
0009:Ret winex11.drv.EnumDisplayMonitors() retval=00000001 ret=7ecdb265
0009:Ret user32.GetWindowDC() retval=000103af ret=0061051f
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000044) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a708 ret=007aa8ca
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,0000007c) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a758 ret=007aa8ca
0009:Call gdi32.SelectObject(000103af,028803ca) ret=006108ad
0009:Ret gdi32.SelectObject() retval=0001001e ret=006108ad
0009:Call gdi32.GetTextExtentPoint32W(000103af,0761a268 L"OK",00000002,0032d670) ret=005fbc62
0009:Ret gdi32.GetTextExtentPoint32W() retval=00000001 ret=005fbc62
0009:Call gdi32.SelectObject(000103af,00000000) ret=006108ad
0009:Ret gdi32.SelectObject() retval=00000000 ret=006108ad
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a708) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a758) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call user32.ReleaseDC(000201a8,000103af) ret=00610564
0009:Ret user32.ReleaseDC() retval=00000001 ret=00610564
0009:Call ntdll.RtlAllocateHeap(028d0000,00000000,00000004) ret=007aa8ca
0009:Ret ntdll.RtlAllocateHeap() retval=0761a708 ret=007aa8ca
0009:Call ntdll.RtlFreeHeap(028d0000,00000000,0761a258) ret=007a94f7
0009:Ret ntdll.RtlFreeHeap() retval=00000001 ret=007a94f7
0009:Call KERNEL32.FreeLibrary(7ec60000) ret=006013b4
0009:Ret KERNEL32.FreeLibrary() retval=00000001 ret=006013b4
0009:Call user32.SystemParametersInfoW(00000030,00000000,0032d920,00000000) ret=006013f5
0009:Call winex11.drv.SystemParametersInfo(00000030,00000000,0032d920,00000000) ret=7ecf3732
0009:Ret winex11.drv.SystemParametersInfo() retval=00000000 ret=7ecf3732
0009:Ret user32.SystemParametersInfoW() retval=00000001 ret=006013f5
0009:Call user32.SetRect(0032e4b8,00000000,00000000,000002fc,000002c8) ret=00601428
0009:Ret user32.SetRect() retval=00000001 ret=00601428
0009:Call user32.IsRectEmpty(0032e4a8) ret=00601435
0009:Ret user32.IsRectEmpty() retval=00000001 ret=00601435
0009:Call user32.GetDC(00000000) ret=00601452
0009:Call winex11.drv.GetDC(000103af,00010020,00010020,0032d598,0032d588,00000013) ret=7ece265a
0009:Ret winex11.drv.GetDC() retval=00000001 ret=7ece265a
0009:Call winex11.drv.EnumDisplayMonitors(00000000,00000000,7ecf18e4,0032d4bc) ret=7ecdb265
0009:Ret winex11.drv.EnumDisplayMonitors() retval=00000001 ret=7ecdb265
0009:Ret user32.GetDC() retval=000103af ret=00601452
0009:Call gdi32.SelectObject(000103af,003a03e8) ret=0060146d
0009:Ret gdi32.SelectObject() retval=0001001e ret=0060146d
0009:Call user32.DrawTextW(000103af,0761a4c8 L"C:\\Program Files\\Foxit Software\\Foxit Reader\\file:\\C:\\users\\lizhenbo\\My%20Documents\\Documents\\Science%202013-11-01.pdf\nFile not found.\nCheck if the file was moved, renamed, or deleted.",ffffffff,0032e4b8,00002c50) ret=00601499
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment