Summary | ZeroBOX

Install_Rental_LL12_2018_4.exe

Emotet Gen1 PDF Suspicious Link Generic Malware ASPack UPX Malicious Library Malicious Packer Admin Tool (Sysinternals etc ...) PWS PDF Anti_VM OS Processor Check MSOffice File PNG Format PE File PE32 .NET EXE DLL
Category Machine Started Completed
FILE s1_win7_x6402 Sept. 3, 2021, 8:49 a.m. Sept. 3, 2021, 8:51 a.m.
Size 13.8MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 2a4bcd31051a5656d118ca1617da35d6
SHA256 e2672839a0439ff00d5e97781bb024c4dfc275092b1a4b53faa5d77b83cfea93
CRC32 7517D5EE
ssdeep 393216:X6SnbdU8E+QATHQogSEOzVmOOc1HTJ47O2bK:X6S5UiQATG7OzRJn
Yara
  • PE_Header_Zero - PE File Signature
  • Malicious_Library_Zero - Malicious_Library
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
file C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
landlord12+0x4f23 @ 0x404f23
landlord12+0x95914 @ 0x495914
landlord12+0x73504 @ 0x473504
landlord12+0x9503b @ 0x49503b
landlord12+0x31c12 @ 0x431c12
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x755762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75576d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x755777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75577bca
landlord12+0x7b9a9 @ 0x47b9a9

exception.instruction_r: 3a 50 40 74 08 88 50 40 e8 67 ff ff ff c3 8b c0
exception.symbol: landlord12+0x5e580
exception.instruction: cmp dl, byte ptr [eax + 0x40]
exception.module: Landlord12.exe
exception.exception_code: 0xc0000005
exception.offset: 386432
exception.address: 0x45e580
registers.esp: 1637040
registers.edi: 0
registers.eax: 0
registers.ebp: 1637076
registers.edx: 0
registers.ebx: 1637544
registers.esi: 68130624
registers.ecx: 68130624
1 0 0

__exception__

stacktrace:
landlord12+0x123d4d @ 0x523d4d
landlord12+0x395c16 @ 0x795c16
landlord12+0x125196 @ 0x525196
landlord12+0x130cc8 @ 0x530cc8
landlord12+0x127ca7 @ 0x527ca7
landlord12+0x127d64 @ 0x527d64
landlord12+0x131831 @ 0x531831
landlord12+0x65d952 @ 0xa5d952
landlord12+0x65dea5 @ 0xa5dea5
landlord12+0x65bb65 @ 0xa5bb65
landlord12+0x65d059 @ 0xa5d059
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637580
registers.edi: 1637840
registers.eax: 1637580
registers.ebp: 1637660
registers.edx: 0
registers.ebx: 83829216
registers.esi: 85373200
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x101815 @ 0x501815
landlord12+0xf92f3 @ 0x4f92f3
landlord12+0xfa5c4 @ 0x4fa5c4
landlord12+0x129c6d @ 0x529c6d
landlord12+0x11eadd @ 0x51eadd
landlord12+0x11ed0f @ 0x51ed0f
landlord12+0x76a243 @ 0xb6a243
landlord12+0x130514 @ 0x530514
landlord12+0xfab6f @ 0x4fab6f
landlord12+0xfac08 @ 0x4fac08
landlord12+0x125310 @ 0x525310
landlord12+0xf9aa2 @ 0x4f9aa2
landlord12+0x1239ec @ 0x5239ec
landlord12+0x123c2c @ 0x523c2c
landlord12+0x123d7d @ 0x523d7d
landlord12+0x395c16 @ 0x795c16
landlord12+0x125196 @ 0x525196
landlord12+0x130cc8 @ 0x530cc8
landlord12+0x65a937 @ 0xa5a937
landlord12+0x65aad7 @ 0xa5aad7
landlord12+0x65d0f5 @ 0xa5d0f5
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637292
registers.edi: 1637664
registers.eax: 1637292
registers.ebp: 1637372
registers.edx: 0
registers.ebx: 85614560
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68469400
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68469176
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68467800
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68463192
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68468600
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68468664
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68469368
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 46181272
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68463192
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68469432
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x7df651 @ 0xbdf651
landlord12+0x7de9c8 @ 0xbde9c8
landlord12+0x5da6f5 @ 0x9da6f5
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1636988
registers.edi: 46173136
registers.eax: 1636988
registers.ebp: 1637068
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 46179952
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x7df651 @ 0xbdf651
landlord12+0x7de9c8 @ 0xbde9c8
landlord12+0x5da6f5 @ 0x9da6f5
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1636988
registers.edi: 46188040
registers.eax: 1636988
registers.ebp: 1637068
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68463192
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 46186144
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 46181392
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68468504
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68468856
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68468600
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 46177024
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 46177312
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68469464
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 46173184
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68469368
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68467896
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68468536
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68468376
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 46173016
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 46188016
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 46179952
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68469432
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 46186048
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68463192
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 46181272
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 46184128
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 46177024
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68469432
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 46173136
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68467800
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 46177312
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68467736
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68468536
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68468824
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68468600
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68468632
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68468376
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0

__exception__

stacktrace:
landlord12+0x2d489a @ 0x6d489a
landlord12+0x24b85d @ 0x64b85d
landlord12+0x24d09b @ 0x64d09b
landlord12+0x255da1 @ 0x655da1
landlord12+0x252e5c @ 0x652e5c
landlord12+0x25ab68 @ 0x65ab68
landlord12+0x2e0f2d @ 0x6e0f2d
landlord12+0x2e10fe @ 0x6e10fe
landlord12+0x2dcb81 @ 0x6dcb81
landlord12+0xf0403 @ 0x4f0403
landlord12+0x7e234a @ 0xbe234a
landlord12+0x5da752 @ 0x9da752
landlord12+0x5daba1 @ 0x9daba1
landlord12+0x65d0fa @ 0xa5d0fa
landlord12+0x65cf57 @ 0xa5cf57
landlord12+0x634713 @ 0xa34713
landlord12+0x634e22 @ 0xa34e22
landlord12+0x8c3277 @ 0xcc3277
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x76a433ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xb727
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xeedfade
exception.offset: 46887
exception.address: 0x7566b727
registers.esp: 1637044
registers.edi: 68468856
registers.eax: 1637044
registers.ebp: 1637124
registers.edx: 0
registers.ebx: 11010
registers.esi: 0
registers.ecx: 7
1 0 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 1052
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x737d2000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1052
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73373000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2088
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0045d000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2088
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0045d000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2088
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x737d2000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00a00000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 720896
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x03e40000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2088
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x03eb0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2088
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73373000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1936
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x737d2000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1936
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x01200000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1936
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00493000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1936
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00496000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1936
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73373000
process_handle: 0xffffffff
1 0 0
Time & API Arguments Status Return Repeated

GetDiskFreeSpaceExW

total_number_of_free_bytes: 0
free_bytes_available: 10873098240
root_path: C:
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 0
free_bytes_available: 10873098240
root_path: C:
total_number_of_bytes: 34252779520
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 0
free_bytes_available: 10831880192
root_path: C:\Users\test22\AppData\Local\Microsoft\Windows\Explorer
total_number_of_bytes: 0
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 10831880192
free_bytes_available: 10831880192
root_path: C:\
total_number_of_bytes: 34252779520
1 1 0
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\465BD09E\Release History 2014.pdf
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\465BD09E\Release 2018-2.pdf
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\465BD09E\Release 2017-3.pdf
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\465BD09E\Release 2017-1.pdf
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\465BD09E\Release History 2016.pdf
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\465BD09E\Release 2018-3.pdf
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\465BD09E\Release 2017-5.pdf
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\465BD09E\Release 2018-1.pdf
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\465BD09E\Release 2018-4.pdf
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\465BD09E\Release 2017-2.pdf
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\465BD09E\Release History 2015.pdf
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\B21C7FEA\PublishingManager6_20173.exe
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\B21C7FEA\PublishingManager7.exe
file C:\Users\test22\AppData\Local\IIIQF\7z.dll
file C:\ProgramData\mia796F.tmp\Install_Rental_LL12_2018_4.msi
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\B21C7FEA\PublishingManager5_20111.exe
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\B21C7FEA\PublishingManager6_20154.exe
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\3F943650\dbsys.exe
file C:\ProgramData\mia796F.tmp\Install_Rental_LL12_2018_4.exe
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\B21C7FEA\PublishingManager5.exe
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\B21C7FEA\PROMASCentral.exe
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\B21C7FEA\Landlord12.exe
file C:\ProgramData\mia796F.tmp\data\OFFLINE\mMSI.dll\mMSIExec.dll
file C:\ProgramData\{EA5BECAE-CF5A-44BE-B357-0B73427F81A9}\Install_Rental_LL12_2018_4.lnk
file C:\Users\test22\AppData\Local\Temp\mia1\mMSIExec.dll
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\B21C7FEA\PublishingManager6_20181.exe
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\B21C7FEA\PublishingManager6.exe
file C:\ProgramData\mia796F.tmp\data\Install_Rental_LL12_2018_4.msi
Time & API Arguments Status Return Repeated

SetFileAttributesW

file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: C:\ProgramData\{EA5BECAE-CF5A-44BE-B357-0B73427F81A9}\
filepath: C:\ProgramData\{EA5BECAE-CF5A-44BE-B357-0B73427F81A9}\
1 1 0

NtCreateFile

create_disposition: 5 (FILE_OVERWRITE_IF)
file_handle: 0x00000298
filepath: C:\RPromas\LL12_Training\dbisam.lck
desired_access: 0xc0100080 (FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: \??\C:\RPromas\LL12_Training\dbisam.lck
create_options: 2144 (FILE_NON_DIRECTORY_FILE|FILE_RANDOM_ACCESS|FILE_SYNCHRONOUS_IO_NONALERT)
status_info: 2 (FILE_CREATED)
share_access: 0 ()
1 0 0

NtCreateFile

create_disposition: 5 (FILE_OVERWRITE_IF)
file_handle: 0x0000029c
filepath: C:\Users\test22\AppData\Local\PROMAS\LandlordForWindows\Instance1\Workspace3\dbisam.lck
desired_access: 0xc0100080 (FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: \??\C:\Users\test22\AppData\Local\PROMAS\LandlordForWindows\Instance1\Workspace3\dbisam.lck
create_options: 2144 (FILE_NON_DIRECTORY_FILE|FILE_RANDOM_ACCESS|FILE_SYNCHRONOUS_IO_NONALERT)
status_info: 2 (FILE_CREATED)
share_access: 0 ()
1 0 0

NtCreateFile

create_disposition: 5 (FILE_OVERWRITE_IF)
file_handle: 0x000002a0
filepath: C:\Users\test22\AppData\Local\PROMAS\LandlordForWindows\Instance1\dbisam.lck
desired_access: 0xc0100080 (FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: \??\C:\Users\test22\AppData\Local\PROMAS\LandlordForWindows\Instance1\dbisam.lck
create_options: 2144 (FILE_NON_DIRECTORY_FILE|FILE_RANDOM_ACCESS|FILE_SYNCHRONOUS_IO_NONALERT)
status_info: 2 (FILE_CREATED)
share_access: 0 ()
1 0 0

NtCreateFile

create_disposition: 5 (FILE_OVERWRITE_IF)
file_handle: 0x000002a8
filepath: C:\Program Files (x86)\RPROMAS\Bins\dbisam.lck
desired_access: 0xc0100080 (FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: \??\C:\Program Files (x86)\RPROMAS\Bins\dbisam.lck
create_options: 2144 (FILE_NON_DIRECTORY_FILE|FILE_RANDOM_ACCESS|FILE_SYNCHRONOUS_IO_NONALERT)
status_info: 2 (FILE_CREATED)
share_access: 0 ()
1 0 0

NtCreateFile

create_disposition: 5 (FILE_OVERWRITE_IF)
file_handle: 0x000002b4
filepath: C:\Program Files (x86)\RPROMAS\Ref\dbisam.lck
desired_access: 0xc0100080 (FILE_READ_ATTRIBUTES|SYNCHRONIZE|GENERIC_WRITE)
file_attributes: 2 (FILE_ATTRIBUTE_HIDDEN)
filepath_r: \??\C:\Program Files (x86)\RPROMAS\REF\dbisam.lck
create_options: 2144 (FILE_NON_DIRECTORY_FILE|FILE_RANDOM_ACCESS|FILE_SYNCHRONOUS_IO_NONALERT)
status_info: 2 (FILE_CREATED)
share_access: 0 ()
1 0 0
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Professional Landlord - 2018.4 Build 10\Uninstall The Professional Landlord - 2018.4 Build 10.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Chrome.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk
file C:\Users\Public\Desktop\Landlord12.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Professional Landlord - 2018.4 Build 10\Landlord12.lnk
file C:\ProgramData\{EA5BECAE-CF5A-44BE-B357-0B73427F81A9}\Install_Rental_LL12_2018_4.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\displayswitch.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
file C:\Users\test22\Desktop\Landlord12.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk
file C:\Users\test22\AppData\Local\Temp\mia1\mMSIExec.dll
file C:\Users\test22\AppData\Local\IIIQF\7z.dll
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeShutdownPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeCreateTokenPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeAssignPrimaryTokenPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeMachineAccountPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeTcbPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeSecurityPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeTakeOwnershipPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeLoadDriverPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeBackupPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeRestorePrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeShutdownPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeRemoteShutdownPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeEnableDelegationPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeManageVolumePrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeCreateGlobalPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeShutdownPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeShutdownPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeShutdownPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeShutdownPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeShutdownPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeShutdownPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeShutdownPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeShutdownPrivilege
1 1 0
Time & API Arguments Status Return Repeated

RegOpenKeyExW

regkey_r: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\The Professional Landlord - 2018.4 Build 10
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00020019
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\The Professional Landlord - 2018.4 Build 10
2 0
Time & API Arguments Status Return Repeated

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0

FindWindowW

class_name: TApplication
window_name: Install_Rental_LL12_2018_4
1 393666 0
McAfee Artemis!2A4BCD31051A
BitDefender Gen:Variant.Fugrafa.154688
Kaspersky HEUR:Trojan.PDF.Skoba.gen
Zillya Trojan.Prikormka.Win32.65
McAfee-GW-Edition Artemis!Trojan
FireEye Gen:Variant.Fugrafa.154688
Jiangmin Trojan.Prikormka.bx
MAX malware (ai score=83)
Antiy-AVL Trojan/Generic.ASMalwS.2A3646C
Kingsoft Win32.Troj.Undef.(kcloud)
ZoneAlarm HEUR:Trojan.PDF.Skoba.gen
GData Gen:Variant.Fugrafa.154688
ALYac Gen:Variant.Fugrafa.154688
VBA32 BScope.Trojan.Prikormka
Malwarebytes Malware.AI.1440764066
file C:\RPromas\LL12_Training\LL12_RECRXFER.ibk
file C:\Users\test22\AppData\Local\PROMAS\LandlordForWindows\Instance1\LL12_BXCOPY.ibk
file C:\RPromas\LL12_Training\LL12_PARLINE.ibk
file C:\RPromas\LL12_Training\LL12_Manager.idx
file C:\Users\test22\AppData\Local\PROMAS\LandlordForWindows\Instance1\LL12_CATGCOPY.idx
file C:\RPromas\LL12_Training\LL12_XGl.idx
file C:\RPromas\LL12_Training\LL12_RTABLE.ibk
file C:\Users\test22\AppData\Local\PROMAS\LandlordForWindows\Instance1\LL12_CXOCOPY.idx
file C:\RPromas\LL12_Training\LL12_Network.idx
file C:\RPromas\LL12_Training\LL12_Mxbrand.idx
file C:\RPromas\LL12_Training\LL12_RJLINE.ibk
file C:\RPromas\LL12_Training\LL12_MOLLINE.ibk
file C:\RPromas\LL12_Training\LL12_MGMTFEE.ibk
file C:\Users\test22\AppData\Local\PROMAS\LandlordForWindows\Instance1\LL12_PROCOPY.idx
file C:\RPromas\LL12_Training\LL12_Recrxfer.idx
file C:\RPromas\LL12_Training\LL12_MXWO.ibk
file C:\RPromas\LL12_Training\LL12_Charge.idx
file C:\RPromas\LL12_Training\LL12_PROLINE.ibk
file C:\Users\test22\AppData\Local\PROMAS\LandlordForWindows\Instance1\LL12_RECRCOPY.idx
file C:\RPromas\LL12_Training\LL12_ACCTLIST.ibk
file C:\RPromas\LL12_Training\LL12_XGL.ibk
file C:\RPromas\LL12_Training\LL12_Ptable.idx
file C:\Users\test22\AppData\Local\PROMAS\LandlordForWindows\Instance1\LL12_XJLTEMP.idx
file C:\RPromas\LL12_Training\LL12_MXMTYPE.ibk
file C:\RPromas\LL12_Training\LL12_Publish.idx
file C:\RPromas\LL12_Training\LL12_CXELINE.ibk
file C:\RPromas\LL12_Training\LL12_XAR.ibk
file C:\RPromas\LL12_Training\LL12_UNIT.ibk
file C:\Users\test22\AppData\Local\PROMAS\LandlordForWindows\Instance1\LL12_DOCCOPY.ibk
file C:\RPromas\LL12_Training\LL12_Rjline.idx
file C:\RPromas\LL12_Training\LL12_Notice.idx
file C:\RPromas\LL12_Training\LL12_STMT.ibk
file C:\RPromas\LL12_Training\LL12_SystemLock.ibk
file C:\RPromas\LL12_Training\LL12_Owner.idx
file C:\RPromas\LL12_Training\LL12_RECLOCK.idx
file C:\RPromas\LL12_Training\LL12_ENTITY.idx
file C:\RPromas\LL12_Training\LL12_DOCLINE.ibk
file C:\RPromas\LL12_Training\LL12_Latefee.idx
file C:\RPromas\LL12_Training\LL12_Prolist.idx
file C:\RPromas\LL12_Training\LL12_XBL.ibk
file C:\RPromas\LL12_Training\LL12_XAP.ibk
file C:\RPromas\LL12_Training\LL12_XARBL.dat
file C:\RPromas\LL12_Training\LL12_TENANT.ibk
file C:\RPromas\LL12_Training\LL12_STMTTEN.ibk
file C:\RPromas\LL12_Training\LL12_ENTITY.dat
file C:\Users\test22\AppData\Local\PROMAS\LandlordForWindows\Instance1\LL12_CXSCOPY.idx
file C:\RPromas\LL12_Training\LL12_Noteitem.idx
file C:\RPromas\LL12_Training\LL12_Bill.idx
file C:\Users\test22\AppData\Local\PROMAS\LandlordForWindows\Instance1\LL12_ACCTCOPY.idx
file C:\Users\test22\AppData\Local\PROMAS\LandlordForWindows\Instance1\LL12_XAPTEMP.idx
file C:\RPromas\LL12_Training\LL12_Defaults.dat
file C:\RPromas\LL12_Training\LL12_Rentline.idx
file C:\Users\test22\AppData\Local\PROMAS\LandlordForWindows\Instance1\LL12_XJLTEMP.dat
file C:\RPromas\LL12_Training\LL12_NOTEITEM.ibk
file C:\RPromas\LL12_Training\LL12_XARBL.dat
file C:\RPromas\LL12_Training\LL12_XAR.ibk
file C:\RPromas\LL12_Training\LL12_Vendor.dat
file C:\RPromas\LL12_Training\LL12_PROPERTY.ibk
file C:\Users\test22\AppData\Local\PROMAS\LandlordForWindows\Instance1\LL12_RJCOPY.dat
file C:\RPromas\LL12_Training\LL12_Mxbrand.idx
file C:\RPromas\LL12_Training\LL12_Parline.idx
file C:\RPromas\LL12_Training\LL12_XGL.ibk
file C:\RPromas\LL12_Training\LL12_MXWO.ibk
file C:\Users\test22\AppData\Local\Temp\mia1\welcome.dfm
file C:\RPromas\LL12_Training\LL12_PROLIST.ibk
file C:\RPromas\LL12_Training\LL12_XARBL.ibk
file C:\Users\test22\AppData\Local\Temp\mia1\setuptype.dfm
file C:\RPromas\LL12_Training\LL12_Letter.blb
file C:\RPromas\LL12_Training\LL12_ENTITY.ibk
file C:\RPromas\LL12_Training\LL12_Integration.dat
file C:\RPromas\LL12_Training\LL12_Noteitem.dat
file C:\RPromas\LL12_Training\LL12_RENTLINE.idx
file C:\RPromas\LL12_Training\LL12_VENDOR.idx
file C:\RPromas\LL12_Training\LL12_Tenant.idx
file C:\RPromas\LL12_Training\LL12_Defaults.idx
file C:\RPromas\LL12_Training\LL12_ENTITY.dat
file C:\RPromas\LL12_Training\LL12_Cxoline.dat
file C:\RPromas\LL12_Training\LL12_BILL.ibk
file C:\RPromas\LL12_Training\LL12_Mxbrand.dat
file C:\RPromas\LL12_Training\LL12_CHARGE.ibk
file C:\RPromas\LL12_Training\LL12_Rcheck.idx
file C:\RPromas\LL12_Training\LL12_SystemLock.dat
file C:\RPromas\LL12_Training\LL12_Mxmtype.idx
file C:\RPromas\LL12_Training\LL12_XGL.idx
file C:\RPromas\LL12_Training\LL12_Xap.dat
file C:\RPromas\LL12_Training\LL12_MGMTFEE.ibk
file C:\RPromas\LL12_Training\LL12_MANAGER.ibk
file C:\RPromas\LL12_Training\LL12_Catgline.dat
file C:\Users\test22\AppData\Local\PROMAS\LandlordForWindows\Instance1\LL12_CXSCOPY.dat
file C:\RPromas\LL12_Training\LL12_XAP.idx
file C:\RPromas\LL12_Training\LL12_TENANT.ibk
file C:\RPromas\LL12_Training\LL12_Xar.dat
file C:\RPromas\LL12_Training\LL12_Entity.idx
file C:\RPromas\LL12_Training\LL12_Bxline.idx
file C:\RPromas\LL12_Training\LL12_XAP.ibk
file C:\RPromas\LL12_Training\LL12_Cxcline.dat
file c:\rpromas\ll12_training\ll12_advsched.dbk
file C:\RPromas\LL12_Training\LL12_Ptable.dat
file C:\ProgramData\mia796F.tmp\data\The Professional Landlord\A056D2F4\3F943650\LL12_REPORT.dat
file C:\RPromas\LL12_Training\LL12_TENANT.idx