Installing: Steam Locale: en Bottle: SteamAMDWin10Test From download url: http://crossover.codeweavers.com/redirect/steamMSI/en ***** Sat Jan 21 17:37:53 2023 Starting: '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/cxbottle' '--bottle' 'SteamAMDWin10Test' '--create' '--template' 'win10_64' '--install' '--param' 'EnvironmentVariables:CX_BOTTLE_CREATOR_APPID=com.codeweavers.c4.206' CXConfig->read(/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/etc/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/CrossOver.conf) 5395: Grabbing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock 5395: Got the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock Running '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/share/crossover/bottle_templates/win10_64/setup' '--create' ***** Sat Jan 21 17:37:53 2023 Starting: '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/share/crossover/bottle_templates/win10_64/setup' '--create' CXConfig->read(/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/etc/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/CrossOver.conf) CXRWConfig->new(/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/share/crossover/bottle_data/cxbottle.conf) system encoding='UTF-8' CXRWConfig->write(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) Running '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wine' '--wl-app' 'rundll32.exe' '--no-quotes' '--scope' 'private' '--winver' 'win10' '--desktop' 'root' '--dll' 'advpack=b;atl=b;oleaut32=b;rpcrt4=b;shdocvw=b;*iexplore.exe=b' 'setupapi.dll,InstallHinfSection' 'win10Install' '128' '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/share/crossover/bottle_data/crossover.inf' ***** Sat Jan 21 17:37:53 2023 Starting: '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wine' '--wl-app' 'rundll32.exe' '--no-quotes' '--scope' 'private' '--winver' 'win10' '--desktop' 'root' '--dll' 'advpack=b;atl=b;oleaut32=b;rpcrt4=b;shdocvw=b;*iexplore.exe=b' 'setupapi.dll,InstallHinfSection' 'win10Install' '128' '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/share/crossover/bottle_data/crossover.inf' CXConfig->read(/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/etc/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/CrossOver.conf) Product version=22.1.0.35656 CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) Mode = 'private' Environment: CX_ROOT = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver" CX_BOTTLE = "SteamAMDWin10Test" WINEPREFIX = "/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test" CX_WINDOWS_VERSION = "win10" PATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin:/usr/local/opt/docker-virtualbox/bin:/usr/local/sbin:/Users/hoshi/opt/local/bin:/usr/local/bin:/System/Cryptexes/App/usr/bin:/usr/bin:/bin:/usr/sbin:/sbin:/Applications/VMware Fusion.app/Contents/Public:/usr/local/share/dotnet:/opt/X11/bin:~/.dotnet/tools:/Library/Apple/usr/bin:/Library/Frameworks/Mono.framework/Versions/Current/Commands" DYLD_LIBRARY_PATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib64" WINEDLLPATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine" WINEDLLOVERRIDES = "advpack=b;atl=b;oleaut32=b;rpcrt4=b;shdocvw=b;*iexplore.exe=b" LD_PRELOAD = LD_ASSUME_KERNEL = WINELOADER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64" WINESERVER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineserver" WINEDEBUG = "+pid,+process,+module,+loaddll,+seh,+threadname" WINEWRAPPER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe" CX_LOG = "/Users/hoshi/crossover-beta-wine10-amd.cxlog" CX_DEBUGMSG = "+pid,+process,+module,+loaddll,+seh,+threadname" DISPLAY = "/private/tmp/com.apple.launchd.EjtXTmJGw9/org.xquartz:0" VKD3D_DEBUG = VKD3D_SHADER_DEBUG = CXConfig->read(/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/etc/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) Command: /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64 /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe --no-quotes --desktop root --run -- /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/rundll32.exe setupapi.dll,InstallHinfSection win10Install 128 /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/share/crossover/bottle_data/crossover.inf ** Sat Jan 21 17:37:53 2023 Starting '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64' '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe' '--no-quotes' '--desktop' 'root' '--run' '--' '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/rundll32.exe' 'setupapi.dll,InstallHinfSection' 'win10Install' '128' '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/share/crossover/bottle_data/crossover.inf' preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0020:0024:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\wineboot.exe" image L"C:\\windows\\system32\\wineboot.exe" cmdline L"\"C:\\windows\\system32\\wineboot.exe\" --init" parent 0x0 0020:0024:trace:process:get_pe_file_info assuming 8664 builtin for L"\\??\\C:\\windows\\system32\\wineboot.exe" 0020:0024:trace:process:send_to_cx_loader loader (null) wineserversocket 7 stdin_fd -1 stdout_fd -1 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 0020:0024:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0028:002c:trace:module:get_load_order looking for L"C:\\windows\\system32\\wineboot.exe" 0028:002c:trace:module:get_load_order got hardcoded default for L"wineboot.exe" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\wineboot.exe" at 0x140000000-0x140020000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wineboot.exe" section .text at 0x140001000 off 1000 size 8000 virt 7210 flags 60000060 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wineboot.exe" section .data at 0x140009000 off 9000 size 1000 virt 120 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wineboot.exe" section .rdata at 0x14000a000 off a000 size 8000 virt 7e10 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wineboot.exe" section .pdata at 0x140012000 off 12000 size 1000 virt 294 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wineboot.exe" section .xdata at 0x140013000 off 13000 size 1000 virt 28c flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wineboot.exe" section .bss at 0x140014000 off 0 size 0 virt 5a0 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wineboot.exe" section .idata at 0x140015000 off 14000 size 2000 virt 18d4 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wineboot.exe" section .rsrc at 0x140017000 off 16000 size 8000 virt 7ba0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wineboot.exe" section .reloc at 0x14001f000 off 1e000 size 1000 virt 80 flags 42000040 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0028:002c:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0020:0024:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\wineboot.exe" pid 0028 tid 002c handles 0x10/0x14 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wineboot.exe" 00000000004320D0 0000000140000000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wineboot.exe" at 0000000140000000: builtin 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0028:002c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 0000000000432800 000000007B000000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000432550 000000007B600000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 0028:002c:fixme:actctx:parse_depend_manifests Could not find dependent assembly L"Microsoft.Windows.Common-Controls" (6.0.0.0) 0028:002c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 0000000000432D30 00000001C8DB0000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"sechost.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 00000000004332B0 00000003AF670000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 0000000000432FD0 000000032A700000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 0000000000432A40 0000000330260000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ws2_32.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" at 0x1ec2b0000-0x1ec2d6000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .text at 0x1ec2b1000 off 1000 size 13000 virt 12500 flags 60000060 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .data at 0x1ec2c4000 off 14000 size 1000 virt 1b0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rodata at 0x1ec2c5000 off 15000 size 1000 virt 85c flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rdata at 0x1ec2c6000 off 16000 size 5000 virt 4990 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .pdata at 0x1ec2cb000 off 1b000 size 1000 virt 954 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .xdata at 0x1ec2cc000 off 1c000 size 1000 virt a3c flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .bss at 0x1ec2cd000 off 0 size 0 virt 170 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .edata at 0x1ec2ce000 off 1d000 size 3000 virt 23c6 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .idata at 0x1ec2d1000 off 20000 size 1000 virt c14 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rsrc at 0x1ec2d2000 off 21000 size 3000 virt 29b8 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .reloc at 0x1ec2d5000 off 24000 size 1000 virt 70 flags 42000040 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ws2_32.dll" 00000000004335E0 00000001EC2B0000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ws2_32.dll" at 00000001EC2B0000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ws2_32.dll" at 00000001EC2B0000 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 0028:002c:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 0028:002c:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0028:002c:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 0028:002c:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 0028:002c:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 0028:002c:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 0028:002c:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 0028:002c:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0028:002c:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 0028:002c:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 0028:002c:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0028:002c:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 0028:002c:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 0028:002c:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 0028:002c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 0028:002c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F3B0. 0028:002c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\wineboot.exe" 0028:002c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F400. 0028:002c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\wineboot.exe" 0028:002c:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0028:002c:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0028:002c:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 0028:002c:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 0028:002c:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 0028:002c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 0028:002c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 0028:002c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\wineboot.exe" 0028:002c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 0028:002c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\wineboot.exe" 0028:002c:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0028:002c:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 0028:002c:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 0028:002c:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0028:002c:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 0028:002c:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 0028:002c:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0028:002c:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 0028:002c:trace:module:process_attach (L"ws2_32.dll",000000000031FB00) - START 0028:002c:trace:module:MODULE_InitDLL (00000001EC2B0000 L"ws2_32.dll",PROCESS_ATTACH,000000000031FB00) 00000001EC2C27C0 - CALL 0028:002c:trace:module:MODULE_InitDLL (00000001EC2B0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0028:002c:trace:module:process_attach (L"ws2_32.dll",000000000031FB00) - END 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31ede8,0x00000008,0x0) 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E8D0, base 000000000031E8C8. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031EB00. 0028:002c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\wineboot.exe" 0028:002c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031EB00. 0028:002c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\wineboot.exe" 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E620, base 000000000031E618. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EAD0, base 000000000031EAC8. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:process:CreateProcessInternalW app L"C:\\windows\\system32\\services.exe" cmdline (null) 0028:002c:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\services.exe" image L"C:\\windows\\system32\\services.exe" cmdline L"\"C:\\windows\\system32\\services.exe\"" parent 0x0 0028:002c:trace:process:get_pe_file_info assuming 8664 builtin for L"\\??\\C:\\windows\\system32\\services.exe" 0028:002c:trace:process:send_to_cx_loader loader (null) wineserversocket 12 stdin_fd -1 stdout_fd -1 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 0028:002c:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0030:0034:trace:module:get_load_order looking for L"C:\\windows\\system32\\services.exe" 0030:0034:trace:module:get_load_order got hardcoded default for L"services.exe" 0030:0034:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\services.exe" at 0x140000000-0x140024000 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\services.exe" section .text at 0x140001000 off 1000 size 19000 virt 18600 flags 60000020 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\services.exe" section .data at 0x14001a000 off 1a000 size 1000 virt 2d0 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\services.exe" section .rdata at 0x14001b000 off 1b000 size 3000 virt 2ba0 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\services.exe" section .pdata at 0x14001e000 off 1e000 size 1000 virt c84 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\services.exe" section .xdata at 0x14001f000 off 1f000 size 1000 virt ac4 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\services.exe" section .bss at 0x140020000 off 0 size 0 virt 240 flags c0000080 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\services.exe" section .idata at 0x140021000 off 20000 size 2000 virt 1644 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\services.exe" section .reloc at 0x140023000 off 22000 size 1000 virt 13c flags 42000040 0030:0034:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0030:0034:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0028:002c:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\services.exe" pid 0030 tid 0034 handles 0x30/0x34 0028:002c:trace:process:CreateProcessInternalW started process pid 0030 tid 0034 0030:0034:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 0030:0034:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\services.exe" 00000000004320C0 0000000140000000 0030:0034:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\services.exe" at 0000000140000000: builtin 0030:0034:trace:module:load_dll looking for L"kernel32.dll" in (null) 0030:0034:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0030:0034:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0030:0034:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0030:0034:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0030:0034:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0030:0034:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0030:0034:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0030:0034:trace:module:load_dll looking for L"ntdll.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 00000000004327F0 000000007B000000 0030:0034:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 0030:0034:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"ntdll.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000432540 000000007B600000 0030:0034:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 0030:0034:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 0030:0034:trace:module:load_dll looking for L"advapi32.dll" in (null) 0030:0034:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0030:0034:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0030:0034:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0030:0034:trace:module:load_dll looking for L"kernel32.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0030:0034:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0030:0034:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0030:0034:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0030:0034:trace:module:load_dll looking for L"kernel32.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"ntdll.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 0000000000432D20 00000001C8DB0000 0030:0034:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 0030:0034:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"ntdll.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"sechost.dll" in (null) 0030:0034:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0030:0034:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0030:0034:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0030:0034:trace:module:load_dll looking for L"kernel32.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"ntdll.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0030:0034:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0030:0034:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0030:0034:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0030:0034:trace:module:load_dll looking for L"kernel32.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"ntdll.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 00000000004332A0 00000003AF670000 0030:0034:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 0030:0034:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 0000000000432FC0 000000032A700000 0030:0034:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 0030:0034:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 0000000000432A30 0000000330260000 0030:0034:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 0030:0034:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"kernel32.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"ntdll.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0030:0034:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" 0030:0034:trace:module:get_load_order_value got environment b for L"rpcrt4" 0030:0034:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0x231ae0000-0x231b62000 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .text at 0x231ae1000 off 1000 size 47000 virt 46400 flags 60000060 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .data at 0x231b28000 off 48000 size 1000 virt 710 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rodata at 0x231b29000 off 49000 size 2000 virt 1b44 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rdata at 0x231b2b000 off 4b000 size 15000 virt 14b90 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .pdata at 0x231b40000 off 60000 size 3000 virt 2334 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .xdata at 0x231b43000 off 63000 size 3000 virt 289c flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .bss at 0x231b46000 off 0 size 0 virt 690 flags c0000080 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .edata at 0x231b47000 off 66000 size 17000 virt 16730 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .idata at 0x231b5e000 off 7d000 size 2000 virt 19a8 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rsrc at 0x231b60000 off 7f000 size 1000 virt 3a8 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .reloc at 0x231b61000 off 80000 size 1000 virt 504 flags 42000040 0030:0034:trace:module:load_dll looking for L"advapi32.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"kernel32.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"ntdll.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rpcrt4.dll" 0000000000433550 0000000231AE0000 0030:0034:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000: builtin 0030:0034:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"setupapi.dll" in (null) 0030:0034:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" 0030:0034:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" 0030:0034:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" at 0x21a7e0000-0x21a856000 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .text at 0x21a7e1000 off 1000 size 37000 virt 365e0 flags 60000060 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .data at 0x21a818000 off 38000 size 1000 virt 230 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rodata at 0x21a819000 off 39000 size 3000 virt 244c flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rdata at 0x21a81c000 off 3c000 size e000 virt d010 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .pdata at 0x21a82a000 off 4a000 size 2000 virt 1818 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .xdata at 0x21a82c000 off 4c000 size 2000 virt 1d24 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .bss at 0x21a82e000 off 0 size 0 virt 720 flags c0000080 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .edata at 0x21a82f000 off 4e000 size 18000 virt 171c8 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .idata at 0x21a847000 off 66000 size 2000 virt 1f34 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rsrc at 0x21a849000 off 68000 size c000 virt bf00 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .reloc at 0x21a855000 off 74000 size 1000 virt d8 flags 42000040 0030:0034:trace:module:load_dll looking for L"advapi32.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"kernel32.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"ntdll.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=2 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"version.dll" in (null) 0030:0034:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0030:0034:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0030:0034:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 0030:0034:trace:module:load_dll looking for L"kernel32.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"ntdll.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 0000000000433C20 00000002F1FA0000 0030:0034:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 00000002F1FA0000: builtin 0030:0034:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 00000002F1FA0000 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\setupapi.dll" 0000000000433870 000000021A7E0000 0030:0034:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\setupapi.dll" at 000000021A7E0000: builtin 0030:0034:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\setupapi.dll" at 000000021A7E0000 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"userenv.dll" in (null) 0030:0034:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\userenv.dll" 0030:0034:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\userenv.dll" 0030:0034:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\userenv.dll" at 0x388e20000-0x388e2e000 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\userenv.dll" section .text at 0x388e21000 off 1000 size 4000 virt 35b0 flags 60000020 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\userenv.dll" section .data at 0x388e25000 off 5000 size 1000 virt 70 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\userenv.dll" section .rodata at 0x388e26000 off 6000 size 1000 virt 78 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\userenv.dll" section .rdata at 0x388e27000 off 7000 size 1000 virt a80 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\userenv.dll" section .pdata at 0x388e28000 off 8000 size 1000 virt 1ec flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\userenv.dll" section .xdata at 0x388e29000 off 9000 size 1000 virt 210 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\userenv.dll" section .bss at 0x388e2a000 off 0 size 0 virt 140 flags c0000080 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\userenv.dll" section .edata at 0x388e2b000 off a000 size 1000 virt 6b8 flags 40000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\userenv.dll" section .idata at 0x388e2c000 off b000 size 1000 virt 808 flags c0000040 0030:0034:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\userenv.dll" section .reloc at 0x388e2d000 off c000 size 1000 virt 20 flags 42000040 0030:0034:trace:module:load_dll looking for L"advapi32.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=4 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"kernel32.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"ntdll.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0030:0034:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=6 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\userenv.dll" 0000000000433F80 0000000388E20000 0030:0034:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\userenv.dll" at 0000000388E20000: builtin 0030:0034:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\userenv.dll" at 0000000388E20000 0030:0034:trace:module:import_dll is not hybrid module 0030:0034:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 0030:0034:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 0030:0034:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0030:0034:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 0030:0034:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 0030:0034:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 0030:0034:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 0030:0034:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 0030:0034:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 0030:0034:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0030:0034:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 0030:0034:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 0030:0034:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0030:0034:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 0030:0034:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 0030:0034:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 0030:0034:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 0030:0034:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F3B0. 0030:0034:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\services.exe" 0030:0034:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F400. 0030:0034:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\services.exe" 0030:0034:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0030:0034:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0030:0034:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 0030:0034:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 0030:0034:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 0030:0034:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 0030:0034:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 0030:0034:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\services.exe" 0030:0034:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 0030:0034:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\services.exe" 0030:0034:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0030:0034:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 0030:0034:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 0030:0034:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0030:0034:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 0030:0034:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 0030:0034:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0030:0034:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 0030:0034:trace:module:process_attach (L"rpcrt4.dll",000000000031FB00) - START 0030:0034:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_ATTACH,000000000031FB00) 0000000231B26040 - CALL 0030:0034:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0030:0034:trace:module:process_attach (L"rpcrt4.dll",000000000031FB00) - END 0030:0034:trace:module:process_attach (L"setupapi.dll",000000000031FB00) - START 0030:0034:trace:module:process_attach (L"version.dll",000000000031FB00) - START 0030:0034:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000031FB00) 00000002F1FA2510 - CALL 0030:0034:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0030:0034:trace:module:process_attach (L"version.dll",000000000031FB00) - END 0030:0034:trace:module:MODULE_InitDLL (000000021A7E0000 L"setupapi.dll",PROCESS_ATTACH,000000000031FB00) 000000021A816860 - CALL 0030:0034:trace:module:MODULE_InitDLL (000000021A7E0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0030:0034:trace:module:process_attach (L"setupapi.dll",000000000031FB00) - END 0030:0034:trace:module:process_attach (L"userenv.dll",000000000031FB00) - START 0030:0034:trace:module:MODULE_InitDLL (0000000388E20000 L"userenv.dll",PROCESS_ATTACH,000000000031FB00) 0000000388E23A50 - CALL 0030:0034:trace:module:MODULE_InitDLL (0000000388E20000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0030:0034:trace:module:process_attach (L"userenv.dll",000000000031FB00) - END 0030:0034:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 0030:0034:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F7B0, base 000000000031F7A8. 0030:0034:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0030:0034:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F340, base 000000000031F338. 0030:0034:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0030:0034:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F930, base 000000000031F928. 0030:0034:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0030:0034:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F620, base 000000000031F618. 0030:0034:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0030:0038:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:0038:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:0038:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:0038:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:0038:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:0038:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:0034:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F8B0, base 000000000031F8A8. 0030:0034:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0030:0034:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F5A0, base 000000000031F598. 0030:0034:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004CC0, 0000000000000000, 000000007B60C498, 00000001400158DC, 0x00000000) 0028:002c:trace:module:load_dll looking for L"shell32.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" at 0x1c69e0000-0x1c72fe000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .text at 0x1c69e1000 off 1000 size 89000 virt 88c60 flags 60000060 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .data at 0x1c6a6a000 off 8a000 size 2000 virt 13e0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rodata at 0x1c6a6c000 off 8c000 size 2000 virt 18ec flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rdata at 0x1c6a6e000 off 8e000 size 29000 virt 28e90 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .pdata at 0x1c6a97000 off b7000 size 6000 virt 5748 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .xdata at 0x1c6a9d000 off bd000 size 6000 virt 5c20 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .bss at 0x1c6aa3000 off 0 size 0 virt 570 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .edata at 0x1c6aa4000 off c3000 size 15000 virt 14070 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .idata at 0x1c6ab9000 off d8000 size 5000 virt 4aa0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rsrc at 0x1c6abe000 off dd000 size 83e000 virt 83d918 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .reloc at 0x1c72fc000 off 91b000 size 2000 virt 1264 flags 42000040 0028:002c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 0028:002c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"user32.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 0028:002c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"sechost.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"version.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 000000000043DBA0 00000002F1FA0000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 00000002F1FA0000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 00000002F1FA0000 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"win32u.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0028:002c:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" is a fake Wine dll 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\win32u.dll" 000000000043DEC0 000000006AD60000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\win32u.dll" at 000000006AD60000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\win32u.dll" at 000000006AD60000 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\user32.dll" 000000000043D7C0 000000023D820000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\user32.dll" at 000000023D820000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\user32.dll" at 000000023D820000 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"win32u.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AD60000, count=2 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\gdi32.dll" 000000000043D4A0 000000026B4C0000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"shlwapi.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" at 0x2e3540000-0x2e3591000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .text at 0x2e3541000 off 1000 size 1e000 virt 1dac0 flags 60000060 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .data at 0x2e355f000 off 1f000 size 1000 virt 210 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rodata at 0x2e3560000 off 20000 size 2000 virt 18fc flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rdata at 0x2e3562000 off 22000 size b000 virt a290 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .pdata at 0x2e356d000 off 2d000 size 2000 virt 11b8 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .xdata at 0x2e356f000 off 2f000 size 2000 virt 13a8 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .bss at 0x2e3571000 off 0 size 0 virt 1c0 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .edata at 0x2e3572000 off 31000 size 14000 virt 13ab5 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .idata at 0x2e3586000 off 45000 size 5000 virt 442c flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rsrc at 0x2e358b000 off 4a000 size 5000 virt 4ed0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .reloc at 0x2e3590000 off 4f000 size 1000 virt e0 flags 42000040 0028:002c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"shcore.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" at 0x3126f0000-0x312709000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .text at 0x3126f1000 off 1000 size 9000 virt 8b70 flags 60000020 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .data at 0x3126fa000 off a000 size 1000 virt b0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rodata at 0x3126fb000 off b000 size 1000 virt fb4 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rdata at 0x3126fc000 off c000 size 3000 virt 2360 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .pdata at 0x3126ff000 off f000 size 1000 virt 57c flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .xdata at 0x312700000 off 10000 size 1000 virt 61c flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .bss at 0x312701000 off 0 size 0 virt 160 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .edata at 0x312702000 off 11000 size 5000 virt 480e flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .idata at 0x312707000 off 16000 size 1000 virt c74 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .reloc at 0x312708000 off 17000 size 1000 virt a8 flags 42000040 0028:002c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ole32.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" at 0x2e8f10000-0x2e902b000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .text at 0x2e8f11000 off 1000 size a8000 virt a76a0 flags 60000060 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .data at 0x2e8fb9000 off a9000 size 1000 virt 480 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rodata at 0x2e8fba000 off aa000 size 1000 virt 778 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rdata at 0x2e8fbb000 off ab000 size 1e000 virt 1d750 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .pdata at 0x2e8fd9000 off c9000 size 7000 virt 6b10 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .xdata at 0x2e8fe0000 off d0000 size 7000 virt 67c4 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .bss at 0x2e8fe7000 off 0 size 0 virt 210 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .edata at 0x2e8fe8000 off d7000 size 18000 virt 17412 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .idata at 0x2e9000000 off ef000 size 4000 virt 367c flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rsrc at 0x2e9004000 off f3000 size 25000 virt 24bc0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .reloc at 0x2e9029000 off 118000 size 2000 virt 1804 flags 42000040 0028:002c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"combase.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" at 0x327020000-0x327073000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .text at 0x327021000 off 1000 size 27000 virt 26590 flags 60000060 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .data at 0x327048000 off 28000 size 1000 virt 580 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rodata at 0x327049000 off 29000 size 2000 virt 16c0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rdata at 0x32704b000 off 2b000 size d000 virt cf90 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .pdata at 0x327058000 off 38000 size 2000 virt 17a0 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .xdata at 0x32705a000 off 3a000 size 2000 virt 18e4 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .bss at 0x32705c000 off 0 size 0 virt 1a0 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .edata at 0x32705d000 off 3c000 size 13000 virt 12d6e flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .idata at 0x327070000 off 4f000 size 2000 virt 1804 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .reloc at 0x327072000 off 51000 size 1000 virt 23c flags 42000040 0028:002c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=3 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ole32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" 0028:002c:trace:module:get_load_order_value got environment b for L"rpcrt4" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0x231ae0000-0x231b62000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .text at 0x231ae1000 off 1000 size 47000 virt 46400 flags 60000060 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .data at 0x231b28000 off 48000 size 1000 virt 710 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rodata at 0x231b29000 off 49000 size 2000 virt 1b44 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rdata at 0x231b2b000 off 4b000 size 15000 virt 14b90 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .pdata at 0x231b40000 off 60000 size 3000 virt 2334 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .xdata at 0x231b43000 off 63000 size 3000 virt 289c flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .bss at 0x231b46000 off 0 size 0 virt 690 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .edata at 0x231b47000 off 66000 size 17000 virt 16730 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .idata at 0x231b5e000 off 7d000 size 2000 virt 19a8 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rsrc at 0x231b60000 off 7f000 size 1000 virt 3a8 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .reloc at 0x231b61000 off 80000 size 1000 virt 504 flags 42000040 0028:002c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rpcrt4.dll" 0000000000440470 0000000231AE0000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"user32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\combase.dll" 0000000000440110 0000000327020000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\combase.dll" at 0000000327020000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\combase.dll" at 0000000327020000 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=4 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=2 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"user32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=3 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ole32.dll" 000000000043E780 00000002E8F10000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ole32.dll" at 00000002E8F10000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ole32.dll" at 00000002E8F10000 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"user32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=4 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shcore.dll" 000000000043E4A0 00000003126F0000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shcore.dll" at 00000003126F0000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shcore.dll" at 00000003126F0000 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"user32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=5 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shlwapi.dll" 000000000043E1A0 00000002E3540000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shlwapi.dll" at 00000002E3540000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shlwapi.dll" at 00000002E3540000 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"user32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=6 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shell32.dll" 000000000043B910 00000001C69E0000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shell32.dll" at 00000001C69E0000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shell32.dll" at 00000001C69E0000 0028:002c:trace:module:process_attach (L"shell32.dll",0000000000000000) - START 0028:002c:trace:module:process_attach (L"gdi32.dll",0000000000000000) - START 0028:002c:trace:module:process_attach (L"user32.dll",0000000000000000) - START 0028:002c:trace:module:process_attach (L"version.dll",0000000000000000) - START 0028:002c:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,0000000000000000) 00000002F1FA2510 - CALL 0028:002c:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:process_attach (L"version.dll",0000000000000000) - END 0028:002c:trace:module:process_attach (L"win32u.dll",0000000000000000) - START 0028:002c:trace:module:MODULE_InitDLL (000000006AD60000 L"win32u.dll",PROCESS_ATTACH,0000000000000000) 000000006AE09460 - CALL 0028:002c:trace:module:MODULE_InitDLL (000000006AD60000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:process_attach (L"win32u.dll",0000000000000000) - END 0028:002c:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,0000000000000000) 000000023D8C5690 - CALL 0028:002c:trace:module:load_dll looking for L"imm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 0028:002c:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=7 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imm32.dll" 0000000000440B10 00000003AFD00000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imm32.dll" at 00000003AFD00000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imm32.dll" at 00000003AFD00000 0028:002c:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 0028:002c:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031DD20, base 000000000031DD18. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E1C0, base 000000000031E1B8. 0028:002c:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031DCD0, base 000000000031DCC8. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 0028:002c:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:process_attach (L"user32.dll",0000000000000000) - END 0028:002c:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,0000000000000000) 000000026B509F00 - CALL 0028:002c:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:process_attach (L"gdi32.dll",0000000000000000) - END 0028:002c:trace:module:process_attach (L"shlwapi.dll",0000000000000000) - START 0028:002c:trace:module:process_attach (L"shcore.dll",0000000000000000) - START 0028:002c:trace:module:process_attach (L"ole32.dll",0000000000000000) - START 0028:002c:trace:module:process_attach (L"combase.dll",0000000000000000) - START 0028:002c:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - START 0028:002c:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_ATTACH,0000000000000000) 0000000231B26040 - CALL 0028:002c:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - END 0028:002c:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_ATTACH,0000000000000000) 00000003270465C0 - CALL 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E0D0, base 000000000031E0C8. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:process_attach (L"combase.dll",0000000000000000) - END 0028:002c:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_ATTACH,0000000000000000) 00000002E8FB74E0 - CALL 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E180, base 000000000031E178. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:process_attach (L"ole32.dll",0000000000000000) - END 0028:002c:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_ATTACH,0000000000000000) 00000003126F8FD0 - CALL 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E210, base 000000000031E208. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:process_attach (L"shcore.dll",0000000000000000) - END 0028:002c:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_ATTACH,0000000000000000) 00000002E355DE00 - CALL 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E2A0, base 000000000031E298. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:process_attach (L"shlwapi.dll",0000000000000000) - END 0028:002c:trace:module:MODULE_InitDLL (00000001C69E0000 L"shell32.dll",PROCESS_ATTACH,0000000000000000) 00000001C6A688D0 - CALL 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E330, base 000000000031E328. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrGetDllFullName module 00000001C69E0000, name 000000000031E850. 0028:002c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\shell32.dll" 0028:002c:trace:module:MODULE_InitDLL (00000001C69E0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:process_attach (L"shell32.dll",0000000000000000) - END 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8ac,0x00000004,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8ac,0x00000004,0x0) 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E410, base 000000000031E408. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dabc,0x00000004,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dabc,0x00000004,0x0) 0028:002c:fixme:shell:create_link flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031D550, base 000000000031D548. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) failed to connect to mount manager 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31cccc,0x00000004,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31cccc,0x00000004,0x0) 0028:002c:fixme:shell:create_link failed to connect to mount manager 0028:002c:trace:module:LdrResolveDelayLoadedAPI (00000001C69E0000, 00000001C6A69B20, 0000000000000000, 000000007B60C498, 00000001C6ABA818, 0x00000000) 0028:002c:trace:module:load_dll looking for L"ole32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 0028:002c:trace:module:LdrResolveDelayLoadedAPI (00000001C69E0000, 00000001C6A69B20, 0000000000000000, 000000007B60C498, 00000001C6ABA830, 0x00000000) 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C870, base 000000000031C868. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (00000001C69E0000, 00000001C6A69B20, 0000000000000000, 000000007B60C498, 00000001C6ABA820, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (00000002E3540000, 00000002E355E990, 0000000000000000, 000000007B60C498, 00000002E3587A1C, 0x00000000) 0028:002c:trace:module:load_dll looking for L"ole32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=3 0028:002c:trace:module:load_dll looking for L"shlwapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=2 0028:002c:trace:module:LdrResolveDelayLoadedAPI (00000001C69E0000, 00000001C6A69B20, 0000000000000000, 000000007B60C498, 00000001C6ABA890, 0x00000000) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8ac,0x00000004,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8ac,0x00000004,0x0) 0028:002c:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 000000000031F5B0 260) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8ac,0x00000004,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8ac,0x00000004,0x0) 0028:002c:trace:process:SetEnvironmentVariableW (L"WINEDLLOVERRIDES" L"shdocvw=b;*iexplore.exe=b;advpack=b;atl=b;oleaut32=b;rpcrt4=b") 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004D20, 0000000000000000, 000000007B60C498, 00000001400158BC, 0x00000000) 0028:002c:trace:module:load_dll looking for L"setupapi.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" at 0x21a7e0000-0x21a856000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .text at 0x21a7e1000 off 1000 size 37000 virt 365e0 flags 60000060 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .data at 0x21a818000 off 38000 size 1000 virt 230 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rodata at 0x21a819000 off 39000 size 3000 virt 244c flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rdata at 0x21a81c000 off 3c000 size e000 virt d010 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .pdata at 0x21a82a000 off 4a000 size 2000 virt 1818 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .xdata at 0x21a82c000 off 4c000 size 2000 virt 1d24 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .bss at 0x21a82e000 off 0 size 0 virt 720 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .edata at 0x21a82f000 off 4e000 size 18000 virt 171c8 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .idata at 0x21a847000 off 66000 size 2000 virt 1f34 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rsrc at 0x21a849000 off 68000 size c000 virt bf00 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .reloc at 0x21a855000 off 74000 size 1000 virt d8 flags 42000040 0028:002c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=3 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"version.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\version.dll" for L"version.dll" at 00000002F1FA0000, count=2 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\setupapi.dll" 0000000000441750 000000021A7E0000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\setupapi.dll" at 000000021A7E0000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\setupapi.dll" at 000000021A7E0000 0028:002c:trace:module:process_attach (L"setupapi.dll",0000000000000000) - START 0028:002c:trace:module:MODULE_InitDLL (000000021A7E0000 L"setupapi.dll",PROCESS_ATTACH,0000000000000000) 000000021A816860 - CALL 0028:002c:trace:module:MODULE_InitDLL (000000021A7E0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:process_attach (L"setupapi.dll",0000000000000000) - END 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EB30, base 000000000031EB28. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E820, base 000000000031E818. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004D20, 0000000000000000, 000000007B60C498, 00000001400158A4, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004D20, 0000000000000000, 000000007B60C498, 00000001400158AC, 0x00000000) 0028:002c:trace:module:EnumResourceNamesExW 0000000000EE0001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000000EE0001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000000EE0001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000000EE0001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000000EE0001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000000EE0001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000000EE0001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000000EE0001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000000EE0001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000001090001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000001090001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000001090001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000001090001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:load_dll looking for L"atl100.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" at 0x1c1ef0000-0x1c1f1c000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .text at 0x1c1ef1000 off 1000 size c000 virt b530 flags 60000020 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .data at 0x1c1efd000 off d000 size 1000 virt 90 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .rodata at 0x1c1efe000 off e000 size 1000 virt 1d0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .rdata at 0x1c1eff000 off f000 size 9000 virt 8890 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .pdata at 0x1c1f08000 off 18000 size 1000 virt 7d4 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .xdata at 0x1c1f09000 off 19000 size 1000 virt 7b4 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .bss at 0x1c1f0a000 off 0 size 0 virt 170 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .edata at 0x1c1f0b000 off 1a000 size d000 virt cf5d flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .idata at 0x1c1f18000 off 27000 size 1000 virt eb8 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .rsrc at 0x1c1f19000 off 28000 size 2000 virt 1f90 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .reloc at 0x1c1f1b000 off 2a000 size 1000 virt 108 flags 42000040 0028:002c:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=5 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=4 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"oleaut32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" 0028:002c:trace:module:get_load_order_value got environment b for L"oleaut32" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" at 0x2739c0000-0x273af6000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .text at 0x2739c1000 off 1000 size ab000 virt aa720 flags 60000060 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .data at 0x273a6c000 off ac000 size 2000 virt 1100 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rodata at 0x273a6e000 off ae000 size 1000 virt 984 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rdata at 0x273a6f000 off af000 size 1f000 virt 1e700 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .pdata at 0x273a8e000 off ce000 size 6000 virt 57e4 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .xdata at 0x273a94000 off d4000 size 6000 virt 50e4 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .bss at 0x273a9a000 off 0 size 0 virt 38230 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .edata at 0x273ad3000 off da000 size 19000 virt 18c59 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .idata at 0x273aec000 off f3000 size 3000 virt 2aa0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rsrc at 0x273aef000 off f6000 size 5000 virt 4ee0 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .reloc at 0x273af4000 off fb000 size 2000 virt 14e4 flags 42000040 0028:002c:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=6 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=5 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"rpcrt4.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=4 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=8 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\oleaut32.dll" 000000000045C0C0 00000002739C0000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\oleaut32.dll" at 00000002739C0000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\oleaut32.dll" at 00000002739C0000 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"shlwapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=3 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=9 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\atl100.dll" 000000000045BF60 00000001C1EF0000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\atl100.dll" at 00000001C1EF0000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\atl100.dll" at 00000001C1EF0000 0028:002c:trace:module:process_attach (L"atl100.dll",0000000000000000) - START 0028:002c:trace:module:process_attach (L"oleaut32.dll",0000000000000000) - START 0028:002c:trace:module:MODULE_InitDLL (00000002739C0000 L"oleaut32.dll",PROCESS_ATTACH,0000000000000000) 0000000273A6A370 - CALL 0028:002c:trace:process:GetEnvironmentVariableW (L"oanocache" 0000000000000000 0) 0028:002c:trace:module:MODULE_InitDLL (00000002739C0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:process_attach (L"oleaut32.dll",0000000000000000) - END 0028:002c:trace:module:MODULE_InitDLL (00000001C1EF0000 L"atl100.dll",PROCESS_ATTACH,0000000000000000) 00000001C1EFB6D0 - CALL 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031BA30, base 000000000031BA28. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:MODULE_InitDLL (00000001C1EF0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:process_attach (L"atl100.dll",0000000000000000) - END 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C630 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c4b4 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/MSXML/MSXML_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013190B0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013190C0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C630 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c4b4 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/MSXML2/MSXML2_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001319090 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:FindResourceExW 0000000001310001 #0018 L"WINE_MANIFEST" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000150B198 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C630 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c4b4 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/MSXML3/MSXML3_V1_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000150B158 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XMLPARSER_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000150B168 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:FindResourceExW 0000000001310001 #0018 L"WINE_MANIFEST" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001319120 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C630 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c4b4 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/MSXML4/MSXML4_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001319100 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:FindResourceExW 0000000001310001 #0018 L"WINE_MANIFEST" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001319120 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C630 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c4b4 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/MSXML6/MSXML6_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001319100 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C630 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c4b4 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/SHDOCVW/SHDOCVW_V1_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013300C8 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C630 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c4b4 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/SAPI/SAPI_TYPELIB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013380D0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"SAPI_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013380E0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013380F0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C630 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c4b4 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/WBEMDISP/WBEMDISP_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132A0B0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"WBEMDISP_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132A0C0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C630 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c4b4 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"WBEMPROX_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000134B048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C630 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c4b4 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"WMIUTILS_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001320048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000021A7E0000, 000000021A817520, 0000000000000000, 000000007B60C498, 000000021A847BF8, 0x00000000) 0028:002c:trace:module:load_dll looking for L"shell32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=2 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c1bc,0x00000004,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c1bc,0x00000004,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c1bc,0x00000004,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c1bc,0x00000004,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c1bc,0x00000004,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c1bc,0x00000004,0x0) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c1bc,0x00000004,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c1bc,0x00000004,0x0) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C630 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c4b4 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/OLEDB32/OLEDB32_TYPELIB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133D810 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"OLEDB32_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133D820 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C630 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c4b4 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MSDAPS_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000136C068 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ROW_SERVER_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000136C078 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C630 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c4b4 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MSDASQL_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001334068 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0002 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001334078 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C630 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c4b4 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/MSADO15/MSADO15_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013340B0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MSADO15_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013340C0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c4e0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ACTIVEDS_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132E048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/ACTIVEDS.TLB/ACTIVEDS_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001311090 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ACTXPRXY_ACTIVSCP_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000014541C8 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ACTXPRXY_COMCAT_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000014541D8 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ACTXPRXY_DOCOBJ_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000014541E8 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ACTXPRXY_HLINK_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000014541F8 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ACTXPRXY_HTIFACE_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001454208 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ACTXPRXY_HTIFRAME_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001454218 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ACTXPRXY_MSHTML_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001454228 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ACTXPRXY_OBJSAFE_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001454238 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ACTXPRXY_OCMM_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001454248 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ACTXPRXY_SERVPROV_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001454258 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ACTXPRXY_SHLDISP_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001454268 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ACTXPRXY_SHOBJIDL_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001454278 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ACTXPRXY_URLHIST_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001454288 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ADSLDP_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001327068 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001327078 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"AMSTREAM_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001349080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ATL_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013390D0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ATL_LIB_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013390E0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/ATL/ATL_LIB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013390F0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ATL_LIB_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013380B0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/ATL100/ATL_LIB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013380C0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ATL_LIB_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013380B0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/ATL110/ATL_LIB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013380C0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:FindResourceExW 0000000001310001 #0018 L"WINE_MANIFEST" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001338108 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ATL_LIB_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013380E8 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/ATL80/ATL_LIB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013380F8 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:FindResourceExW 0000000001310001 #0018 L"WINE_MANIFEST" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001338108 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ATL_LIB_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013380E8 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/ATL90/ATL_LIB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013380F8 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"AVIFIL32_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001352628 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001352638 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"BROWSEUI_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001330368 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:FindResourceExW 0000000001310001 #0018 L"WINE_MANIFEST" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013FE700 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"COMDLG32_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013668C8 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"COMSVCS_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013300B0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/COMSVCS/COMSVCS_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013300C0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"D3DXOF_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001339080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DDRAW_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001380080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DDRAWEX_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133A080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DEVENUM_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133C080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DHTMLED_TLB_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013340D0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/DHTMLED.OCX/DHTMLED_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013340E0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013340F0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DINPUT_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001351458 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DINPUT8_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001351458 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DIRECTMANIP_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001330048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DISP_EX_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001335048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DMBAND_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001338080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DMCOMPOS_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001337080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DMIME_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000134C080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DMLOADER_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133D080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DMSCRIPT_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013370A0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013370B0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DMSTYLE_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001342080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DMSYNTH_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133A080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DMUSIC_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133F080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DPLAYX_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000134E080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DPNET_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013370A0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0002 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013370B0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DPVOICE_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132E080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DSDMO_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001336080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DSOUND_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001368080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DSQUERY_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132C048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000131C048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DSUIEXT_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132D048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DSWAVE_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001333080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DX8VB_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132F080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DXDIAGN_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133C1C0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"EVR_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001366048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"EXPLORERFRAME_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001331080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/GAMEUX/GAMEUX_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013340C8 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:FindResourceExW 0000000001310001 #0018 L"WINE_MANIFEST" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013920B0 0028:002c:trace:module:FindResourceExW 0000000001310001 #0018 L"WINE_MANIFEST11" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013920C0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/HHCTRL.OCX/HHCTRL_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133D7E0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"HLINK_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001333048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/HNETCFG/HNETCFG_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132E100 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/HNETCFG/HNETCFG_TLB_T.RES\\2" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132E110 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"HNETCFG_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132E120 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/IEFRAME/IEFRAME_V1_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000136D860 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"IEFRAME_V1_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000136D870 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0002 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000136D880 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"IEPROXY_IEAUTOMATION_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132D068 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"IEPROXY_PERHIST_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132D078 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"INETCOMM_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000134B068 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000134B078 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"INFOSOFT_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132C048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"INSENG_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132D048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"ITSS_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001336068 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001336078 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/JSCRIPT/JSGLOBAL_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000139BF70 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"JSCRIPT_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000139BF80 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0002 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000139BF90 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013E4368 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MF_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001378068 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001378078 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MEDIAENGINE_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133E068 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MEDIAENGINE_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133E078 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MF_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133C048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MLANG_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001339068 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0002 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001339078 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/MMCNDMGR/MMCNDMGR_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132C090 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MMDEVAPI_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001338048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MP3DMOD_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001368048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MSCOREE_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001347048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MSCTF_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001343080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MSCTFP_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000136A048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MSHTML_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000014D36B0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/MSHTML.TLB/MSHTML_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001311090 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/MSI/MSISERVER_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000140EE78 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MSISERVER_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000140EE88 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000140EE98 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MSIDENT_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000131D048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MSIMTF_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132D048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/MSSCRIPT.OCX/MSSCRIPT_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132A0B0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0002 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132A0C0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"MSTASK_LOCAL_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001327048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:FindResourceExW 0000000001310001 #0018 L"WINE_MANIFEST" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013AC048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:FindResourceExW 0000000001310001 #0018 L"WINE_MANIFEST" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013AC048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"NETCFGX_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132D048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"NETPROFM_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001322048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"OBJSEL_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132C080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DCOM_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001403490 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"OLE32_OBJIDL_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000014034A0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"OLE32_OLEIDL_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000014034B0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"OLE32_UNKNWN_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000014034C0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/OLEACC/OLEACC_CLASSES_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133D870 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"OLEACC_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133D880 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"OLEAUT32_OAIDL_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001406230 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"OLEAUT32_OCIDL_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001406240 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001406250 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/OLEPRO32/OLEPRO_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013190C8 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"OPCSERVICES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132E048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"PACKAGER_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000131D068 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000131D078 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"PROPSYS_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001338048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/PSTOREC/PSTOREC_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000131E090 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"QASF_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001345080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"QCAP_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001351080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"QDVD_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133A080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"QEDIT_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000134E080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001334048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"QMGRPRXY_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133A048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/QUARTZ/CONTROL_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013D5108 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"QUARTZ_STRMIF_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013D5118 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013D5128 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/RICHED20/RICHED_TOM_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013791D8 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133F080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/SCROBJ/SCROBJ_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001335090 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/SCRRUN/SCRRUN_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133E0E8 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133E0F8 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/SHELL32/SHELL32_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013FF0E0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"SHELL32_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013FF0F0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013FF100 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/STDOLE2.TLB/STDOLE2_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013110C8 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/STDOLE32.TLB/STD_OLE_V1_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013110C8 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"STI_WIA_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001335048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/TASKSCHD/TASKSCHD_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000133E090 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"UIANIMATION_REG_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132F090 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"UIRIBBON_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132C048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"URLMON_URLMON_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000139B328 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000139B338 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/VBSCRIPT/VBSGLOBAL_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013619B8 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/VBSCRIPT/VBSREGEXP10_T.RES\\2" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013619C8 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/VBSCRIPT/VBSREGEXP55_T.RES\\3" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013619D8 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"VBSCRIPT_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013619E8 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0002 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013619F8 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"WIASERVC_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132E068 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132E078 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132C048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001330048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132D048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000131D048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000132B048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"WINDOWSCODECS_WINCODEC_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001495080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/WINHTTP/WINHTTP_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013510C8 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000131B048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/WMP/WMP_TYPELIB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013340E8 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0002 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013340F8 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"WMPHOTO_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001375048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"WPC_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000131D048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/WSHOM.OCX/WSHOM_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013350B0 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" #0001 0000 0028:002c:trace:module:LoadResource 0000000001310001 00000000013350C0 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"DLLS/WUAPI/WUAPI_TLB_T.RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001332090 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001364048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001364048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001364048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001364048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001364048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001364048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001364048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001364048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001364048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001364048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001364048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001364048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000135C048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000135C048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000135C048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000135C048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000135C048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000135C048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000135C048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 000000000135C048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001360048 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C2C0 260) 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 L"WINE_REGISTRY" 000000021A7F68A0 31c144 0028:002c:trace:module:FindResourceExW 0000000001310001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 0028:002c:trace:module:LoadResource 0000000001310001 0000000001360080 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:EnumResourceNamesExW 0000000001310001 #0018 000000021A7F88B0 31c170 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004D20, 0000000000000000, 000000007B60C498, 00000001400158C4, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004D20, 0000000000000000, 000000007B60C498, 00000001400158B4, 0x00000000) 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031A5A0, base 000000000031A598. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726624, 0x00000000) 0028:002c:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=5 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031A1C0, base 000000000031A1B8. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726704, 0x00000000) 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031A3C0, base 000000000031A3B8. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266EC, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726714, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266A4, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726684, 0x00000000) 0030:003c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:003c:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:003c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:003c:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:003c:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:003c:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266AC, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266BC, 0x00000000) 0030:0040:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:0040:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:0040:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:0040:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:0040:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:0040:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72661C, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72667C, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266DC, 0x00000000) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31aa58,0x00000008,0x0) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72660C, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72665C, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726614, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726664, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266B4, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72662C, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726634, 0x00000000) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31aa58,0x00000008,0x0) 0030:0040:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\svchost.exe -k LocalServiceNetworkRestricted" 0000000000000000 0) 0030:0040:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\svchost.exe -k LocalServiceNetworkRestricted" 000000000043E8A0 65) 0030:0040:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 00000000014AE8B0, base 00000000014AE8A8. 0030:0040:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0030:0040:trace:process:GetEnvironmentVariableW (L"SystemRoot" 00000000014AF170 32767) 0030:0040:trace:process:GetEnvironmentVariableW (L"SystemDrive" 00000000014AF170 32767) 0030:0040:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x14aedc8,0x00000008,0x0) 0030:0040:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 00000000014AE850, base 00000000014AE848. 0030:0040:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0030:0040:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 00000000014AEA70, base 00000000014AEA68. 0030:0040:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0030:0040:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 00000000014AE790, base 00000000014AE788. 0030:0040:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0030:0040:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 00000000004472A0 257) 0030:0040:trace:process:GetEnvironmentVariableW (L"WINEBOOTSTRAPMODE" 00000000014BF260 16) 0030:0040:trace:process:CreateProcessInternalW app (null) cmdline L"C:\\windows\\system32\\svchost.exe -k LocalServiceNetworkRestricted" 0030:0040:trace:process:find_exe_file looking for L"C:\\windows\\system32\\svchost.exe" in L"C:\\windows\\system32;.;C:\\windows\\system32;C:\\windows\\system;C:\\windows;" 0030:0040:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\svchost.exe" image L"C:\\windows\\system32\\svchost.exe" cmdline L"C:\\windows\\system32\\svchost.exe -k LocalServiceNetworkRestricted" parent 0x0 0030:0040:trace:process:send_to_cx_loader loader (null) wineserversocket 20 stdin_fd -1 stdout_fd -1 unixdir (null) winedebug (null) wineloader (null) 0030:0040:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0044:0048:trace:module:get_load_order looking for L"C:\\windows\\system32\\svchost.exe" 0044:0048:trace:module:get_load_order got hardcoded default for L"svchost.exe" 0044:0048:trace:module:get_load_order looking for L"C:\\windows\\system32\\svchost.exe" 0044:0048:trace:module:get_load_order got hardcoded default for L"svchost.exe" 0044:0048:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\svchost.exe" at 0x140000000-0x14000a000 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\svchost.exe" section .text at 0x140001000 off 1000 size 2000 virt 1c60 flags 60000020 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\svchost.exe" section .data at 0x140003000 off 3000 size 1000 virt 40 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\svchost.exe" section .rdata at 0x140004000 off 4000 size 1000 virt 580 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\svchost.exe" section .pdata at 0x140005000 off 5000 size 1000 virt cc flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\svchost.exe" section .xdata at 0x140006000 off 6000 size 1000 virt e4 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\svchost.exe" section .bss at 0x140007000 off 0 size 0 virt 140 flags c0000080 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\svchost.exe" section .idata at 0x140008000 off 7000 size 1000 virt 610 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\svchost.exe" section .reloc at 0x140009000 off 8000 size 1000 virt 10 flags 42000040 0044:0048:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0044:0048:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0030:0040:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\svchost.exe" pid 0044 tid 0048 handles 0x80/0x84 0030:0040:trace:process:CreateProcessInternalW started process pid 0044 tid 0048 0044:0048:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 0044:0048:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\svchost.exe" 0000000000431610 0000000140000000 0044:0048:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\svchost.exe" at 0000000140000000: builtin 0044:0048:trace:module:load_dll looking for L"kernel32.dll" in (null) 0044:0048:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernel32.dll" 0044:0048:trace:module:get_load_order got hardcoded default for L"kernel32.dll" 0044:0048:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0044:0048:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0044:0048:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernelbase.dll" 0044:0048:trace:module:get_load_order got hardcoded default for L"kernelbase.dll" 0044:0048:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0044:0048:trace:module:load_dll looking for L"ntdll.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 0000000000431E80 000000007B000000 0044:0048:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 0044:0048:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"ntdll.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000431B60 000000007B600000 0044:0048:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 0044:0048:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 0044:0048:trace:module:load_dll looking for L"advapi32.dll" in (null) 0044:0048:trace:module:get_load_order looking for L"C:\\windows\\system32\\advapi32.dll" 0044:0048:trace:module:get_load_order got hardcoded default for L"advapi32.dll" 0044:0048:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0044:0048:trace:module:load_dll looking for L"kernel32.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0044:0048:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvcrt.dll" 0044:0048:trace:module:get_load_order got hardcoded default for L"msvcrt.dll" 0044:0048:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0044:0048:trace:module:load_dll looking for L"kernel32.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"ntdll.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 0000000000432330 00000001C8DB0000 0044:0048:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 0044:0048:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"ntdll.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"sechost.dll" in (null) 0044:0048:trace:module:get_load_order looking for L"C:\\windows\\system32\\sechost.dll" 0044:0048:trace:module:get_load_order got hardcoded default for L"sechost.dll" 0044:0048:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0044:0048:trace:module:load_dll looking for L"kernel32.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"ntdll.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0044:0048:trace:module:get_load_order looking for L"C:\\windows\\system32\\ucrtbase.dll" 0044:0048:trace:module:get_load_order got hardcoded default for L"ucrtbase.dll" 0044:0048:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0044:0048:trace:module:load_dll looking for L"kernel32.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"ntdll.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 00000000004328C0 00000003AF670000 0044:0048:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 0044:0048:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 00000000004325D0 000000032A700000 0044:0048:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 0044:0048:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 0000000000432050 0000000330260000 0044:0048:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 0044:0048:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"kernel32.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"ntdll.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 0044:0048:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 0044:0048:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0044:0048:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 0044:0048:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 0044:0048:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 0044:0048:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 0044:0048:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 0044:0048:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 0044:0048:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0044:0048:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 0044:0048:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 0044:0048:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0044:0048:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 0044:0048:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 0044:0048:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 0044:0048:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 0044:0048:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F3B0. 0044:0048:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\svchost.exe" 0044:0048:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F400. 0044:0048:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\svchost.exe" 0044:0048:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0044:0048:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0044:0048:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 0044:0048:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 0044:0048:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 0044:0048:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 0044:0048:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 0044:0048:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\svchost.exe" 0044:0048:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 0044:0048:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\svchost.exe" 0044:0048:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0044:0048:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 0044:0048:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 0044:0048:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0044:0048:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 0044:0048:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 0044:0048:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0044:0048:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 0044:0048:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 0044:0048:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F7A0, base 000000000031F798. 0044:0048:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0044:0048:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\wevtsvc.dll" 0000000000000000 0) 0044:0048:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\wevtsvc.dll" 000000000043A2C0 32) 0044:0048:trace:module:load_dll looking for L"C:\\windows\\system32\\wevtsvc.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0044:0048:trace:module:get_load_order looking for L"C:\\windows\\system32\\wevtsvc.dll" 0044:0048:trace:module:get_load_order got hardcoded default for L"wevtsvc.dll" 0044:0048:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\wevtsvc.dll" at 0x2eba70000-0x2eba7b000 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wevtsvc.dll" section .text at 0x2eba71000 off 1000 size 1000 virt de0 flags 60000020 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wevtsvc.dll" section .data at 0x2eba72000 off 2000 size 1000 virt 70 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wevtsvc.dll" section .rodata at 0x2eba73000 off 3000 size 1000 virt 8 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wevtsvc.dll" section .rdata at 0x2eba74000 off 4000 size 1000 virt 200 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wevtsvc.dll" section .pdata at 0x2eba75000 off 5000 size 1000 virt c0 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wevtsvc.dll" section .xdata at 0x2eba76000 off 6000 size 1000 virt b8 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wevtsvc.dll" section .bss at 0x2eba77000 off 0 size 0 virt 160 flags c0000080 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wevtsvc.dll" section .edata at 0x2eba78000 off 7000 size 1000 virt 119 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wevtsvc.dll" section .idata at 0x2eba79000 off 8000 size 1000 virt 46c flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wevtsvc.dll" section .reloc at 0x2eba7a000 off 9000 size 1000 virt 20 flags 42000040 0044:0048:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wevtsvc.dll" 000000000043A450 00000002EBA70000 0044:0048:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wevtsvc.dll" at 00000002EBA70000: builtin 0044:0048:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wevtsvc.dll" at 00000002EBA70000 0044:0048:trace:module:process_attach (L"wevtsvc.dll",0000000000000000) - START 0044:0048:trace:module:MODULE_InitDLL (00000002EBA70000 L"wevtsvc.dll",PROCESS_ATTACH,0000000000000000) 00000002EBA71340 - CALL 0044:0048:trace:module:MODULE_InitDLL (00000002EBA70000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0044:0048:trace:module:process_attach (L"wevtsvc.dll",0000000000000000) - END 0044:0048:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F720, base 000000000031F718. 0044:0048:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0044:0048:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726624, 0x00000000) 0044:0048:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0044:0048:trace:module:get_load_order looking for L"C:\\windows\\system32\\rpcrt4.dll" 0044:0048:trace:module:get_load_order_value got environment b for L"rpcrt4" 0044:0048:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0x231ae0000-0x231b62000 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .text at 0x231ae1000 off 1000 size 47000 virt 46400 flags 60000060 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .data at 0x231b28000 off 48000 size 1000 virt 710 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rodata at 0x231b29000 off 49000 size 2000 virt 1b44 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rdata at 0x231b2b000 off 4b000 size 15000 virt 14b90 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .pdata at 0x231b40000 off 60000 size 3000 virt 2334 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .xdata at 0x231b43000 off 63000 size 3000 virt 289c flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .bss at 0x231b46000 off 0 size 0 virt 690 flags c0000080 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .edata at 0x231b47000 off 66000 size 17000 virt 16730 flags 40000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .idata at 0x231b5e000 off 7d000 size 2000 virt 19a8 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rsrc at 0x231b60000 off 7f000 size 1000 virt 3a8 flags c0000040 0044:0048:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .reloc at 0x231b61000 off 80000 size 1000 virt 504 flags 42000040 0044:0048:trace:module:load_dll looking for L"advapi32.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"kernel32.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"ntdll.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0044:0048:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0044:0048:trace:module:import_dll is not hybrid module 0044:0048:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rpcrt4.dll" 0000000000438CB0 0000000231AE0000 0044:0048:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000: builtin 0044:0048:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000 0044:0048:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - START 0044:0048:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_ATTACH,0000000000000000) 0000000231B26040 - CALL 0044:0048:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0044:0048:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - END 0044:0048:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EE20, base 000000000031EE18. 0044:0048:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0044:0048:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726704, 0x00000000) 0044:0048:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F020, base 000000000031F018. 0044:0048:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0044:0048:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266EC, 0x00000000) 0044:0048:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726714, 0x00000000) 0044:0048:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266A4, 0x00000000) 0044:0048:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726684, 0x00000000) 0030:004c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:004c:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:004c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:004c:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:004c:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:004c:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0044:0048:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266AC, 0x00000000) 0044:0048:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266BC, 0x00000000) 0030:0050:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:0050:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:0050:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:0050:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:0050:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:0050:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0044:0048:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72661C, 0x00000000) 0044:0048:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72667C, 0x00000000) 0044:0048:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266DC, 0x00000000) 0044:0054:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0044:0054:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0044:0054:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0044:0054:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0044:0054:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0044:0054:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0044:0054:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72660C, 0x00000000) 0044:0054:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72665C, 0x00000000) 0044:0054:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726614, 0x00000000) 0044:0054:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726664, 0x00000000) 0044:0058:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0044:0058:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0044:0058:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0044:0058:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0044:0058:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0044:0058:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0044:0058:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 00000000011BF7D0, base 00000000011BF7C8. 0044:0058:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0044:0058:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266C4, 0x00000000) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31aa58,0x00000008,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31aa58,0x00000008,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31aa58,0x00000008,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31aa58,0x00000008,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31aa58,0x00000008,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31aa58,0x00000008,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31aa58,0x00000008,0x0) 0030:0040:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\plugplay.exe" 0000000000000000 0) 0030:0040:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\plugplay.exe" 000000000044D760 33) 0030:0040:trace:process:CreateProcessInternalW app (null) cmdline L"C:\\windows\\system32\\plugplay.exe" 0030:0040:trace:process:find_exe_file looking for L"C:\\windows\\system32\\plugplay.exe" in L"C:\\windows\\system32;.;C:\\windows\\system32;C:\\windows\\system;C:\\windows;" 0030:0040:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\plugplay.exe" image L"C:\\windows\\system32\\plugplay.exe" cmdline L"C:\\windows\\system32\\plugplay.exe" parent 0x0 0030:0040:trace:process:send_to_cx_loader loader (null) wineserversocket 28 stdin_fd -1 stdout_fd -1 unixdir (null) winedebug (null) wineloader (null) 0030:0040:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 005c:0060:trace:module:get_load_order looking for L"C:\\windows\\system32\\plugplay.exe" 005c:0060:trace:module:get_load_order got hardcoded default for L"plugplay.exe" 005c:0060:trace:module:get_load_order looking for L"C:\\windows\\system32\\plugplay.exe" 005c:0060:trace:module:get_load_order got hardcoded default for L"plugplay.exe" 005c:0060:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\plugplay.exe" at 0x140000000-0x14000b000 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\plugplay.exe" section .text at 0x140001000 off 1000 size 3000 virt 2190 flags 60000020 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\plugplay.exe" section .data at 0x140004000 off 4000 size 1000 virt 150 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\plugplay.exe" section .rdata at 0x140005000 off 5000 size 1000 virt 540 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\plugplay.exe" section .pdata at 0x140006000 off 6000 size 1000 virt 228 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\plugplay.exe" section .xdata at 0x140007000 off 7000 size 1000 virt 1e0 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\plugplay.exe" section .bss at 0x140008000 off 0 size 0 virt 160 flags c0000080 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\plugplay.exe" section .idata at 0x140009000 off 8000 size 1000 virt a6c flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\plugplay.exe" section .reloc at 0x14000a000 off 9000 size 1000 virt 64 flags 42000040 005c:0060:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 005c:0060:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0030:0040:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\plugplay.exe" pid 005c tid 0060 handles 0xb8/0xbc 0030:0040:trace:process:CreateProcessInternalW started process pid 005c tid 0060 005c:0060:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 005c:0060:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\plugplay.exe" 00000000004315F0 0000000140000000 005c:0060:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\plugplay.exe" at 0000000140000000: builtin 005c:0060:trace:module:load_dll looking for L"kernel32.dll" in (null) 005c:0060:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernel32.dll" 005c:0060:trace:module:get_load_order got hardcoded default for L"kernel32.dll" 005c:0060:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 005c:0060:trace:module:load_dll looking for L"kernelbase.dll" in (null) 005c:0060:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernelbase.dll" 005c:0060:trace:module:get_load_order got hardcoded default for L"kernelbase.dll" 005c:0060:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 005c:0060:trace:module:load_dll looking for L"ntdll.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 0000000000431E70 000000007B000000 005c:0060:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 005c:0060:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ntdll.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000431B50 000000007B600000 005c:0060:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 005c:0060:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 005c:0060:trace:module:load_dll looking for L"advapi32.dll" in (null) 005c:0060:trace:module:get_load_order looking for L"C:\\windows\\system32\\advapi32.dll" 005c:0060:trace:module:get_load_order got hardcoded default for L"advapi32.dll" 005c:0060:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 005c:0060:trace:module:load_dll looking for L"kernel32.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"kernelbase.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"msvcrt.dll" in (null) 005c:0060:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvcrt.dll" 005c:0060:trace:module:get_load_order got hardcoded default for L"msvcrt.dll" 005c:0060:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 005c:0060:trace:module:load_dll looking for L"kernel32.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ntdll.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 0000000000432320 00000001C8DB0000 005c:0060:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 005c:0060:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ntdll.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"sechost.dll" in (null) 005c:0060:trace:module:get_load_order looking for L"C:\\windows\\system32\\sechost.dll" 005c:0060:trace:module:get_load_order got hardcoded default for L"sechost.dll" 005c:0060:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 005c:0060:trace:module:load_dll looking for L"kernel32.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"kernelbase.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ntdll.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 005c:0060:trace:module:get_load_order looking for L"C:\\windows\\system32\\ucrtbase.dll" 005c:0060:trace:module:get_load_order got hardcoded default for L"ucrtbase.dll" 005c:0060:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 005c:0060:trace:module:load_dll looking for L"kernel32.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ntdll.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 00000000004328B0 00000003AF670000 005c:0060:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 005c:0060:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 00000000004325C0 000000032A700000 005c:0060:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 005c:0060:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 0000000000432040 0000000330260000 005c:0060:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 005c:0060:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"kernel32.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ntdll.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 005c:0060:trace:module:get_load_order looking for L"C:\\windows\\system32\\rpcrt4.dll" 005c:0060:trace:module:get_load_order_value got environment b for L"rpcrt4" 005c:0060:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0x231ae0000-0x231b62000 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .text at 0x231ae1000 off 1000 size 47000 virt 46400 flags 60000060 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .data at 0x231b28000 off 48000 size 1000 virt 710 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rodata at 0x231b29000 off 49000 size 2000 virt 1b44 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rdata at 0x231b2b000 off 4b000 size 15000 virt 14b90 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .pdata at 0x231b40000 off 60000 size 3000 virt 2334 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .xdata at 0x231b43000 off 63000 size 3000 virt 289c flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .bss at 0x231b46000 off 0 size 0 virt 690 flags c0000080 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .edata at 0x231b47000 off 66000 size 17000 virt 16730 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .idata at 0x231b5e000 off 7d000 size 2000 virt 19a8 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rsrc at 0x231b60000 off 7f000 size 1000 virt 3a8 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .reloc at 0x231b61000 off 80000 size 1000 virt 504 flags 42000040 005c:0060:trace:module:load_dll looking for L"advapi32.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"kernel32.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ntdll.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rpcrt4.dll" 0000000000432A80 0000000231AE0000 005c:0060:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000: builtin 005c:0060:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"user32.dll" in (null) 005c:0060:trace:module:get_load_order looking for L"C:\\windows\\system32\\user32.dll" 005c:0060:trace:module:get_load_order got hardcoded default for L"user32.dll" 005c:0060:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 005c:0060:trace:module:load_dll looking for L"advapi32.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"gdi32.dll" in (null) 005c:0060:trace:module:get_load_order looking for L"C:\\windows\\system32\\gdi32.dll" 005c:0060:trace:module:get_load_order got hardcoded default for L"gdi32.dll" 005c:0060:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 005c:0060:trace:module:load_dll looking for L"advapi32.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=4 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"kernel32.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ntdll.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"user32.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"win32u.dll" in (null) 005c:0060:trace:module:get_load_order looking for L"C:\\windows\\system32\\win32u.dll" 005c:0060:trace:module:get_load_order got hardcoded default for L"win32u.dll" 005c:0060:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\win32u.dll" is a fake Wine dll 005c:0060:trace:module:load_dll looking for L"kernel32.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ntdll.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\win32u.dll" 0000000000433470 000000006AC60000 005c:0060:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\win32u.dll" at 000000006AC60000: builtin 005c:0060:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\win32u.dll" at 000000006AC60000 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\gdi32.dll" 0000000000433110 000000026B4C0000 005c:0060:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000: builtin 005c:0060:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"kernel32.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"kernelbase.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ntdll.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"sechost.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"version.dll" in (null) 005c:0060:trace:module:get_load_order looking for L"C:\\windows\\system32\\version.dll" 005c:0060:trace:module:get_load_order got hardcoded default for L"version.dll" 005c:0060:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 005c:0060:trace:module:load_dll looking for L"kernel32.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=11 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"kernelbase.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ntdll.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=13 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=6 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 00000000004337D0 00000002F1FA0000 005c:0060:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 00000002F1FA0000: builtin 005c:0060:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 00000002F1FA0000 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"win32u.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AC60000, count=2 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\user32.dll" 0000000000432E30 000000023D820000 005c:0060:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\user32.dll" at 000000023D820000: builtin 005c:0060:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\user32.dll" at 000000023D820000 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 005c:0060:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 005c:0060:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 005c:0060:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 005c:0060:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 005c:0060:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 005c:0060:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 005c:0060:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 005c:0060:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 005c:0060:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 005c:0060:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 005c:0060:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 005c:0060:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 005c:0060:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 005c:0060:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 005c:0060:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 005c:0060:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 005c:0060:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F3B0. 005c:0060:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\plugplay.exe" 005c:0060:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F400. 005c:0060:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\plugplay.exe" 005c:0060:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 005c:0060:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 005c:0060:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 005c:0060:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 005c:0060:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 005c:0060:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 005c:0060:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 005c:0060:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\plugplay.exe" 005c:0060:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 005c:0060:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\plugplay.exe" 005c:0060:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 005c:0060:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 005c:0060:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 005c:0060:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 005c:0060:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 005c:0060:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 005c:0060:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 005c:0060:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 005c:0060:trace:module:process_attach (L"rpcrt4.dll",000000000031FB00) - START 005c:0060:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_ATTACH,000000000031FB00) 0000000231B26040 - CALL 005c:0060:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 005c:0060:trace:module:process_attach (L"rpcrt4.dll",000000000031FB00) - END 005c:0060:trace:module:process_attach (L"user32.dll",000000000031FB00) - START 005c:0060:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - START 005c:0060:trace:module:process_attach (L"win32u.dll",000000000031FB00) - START 005c:0060:trace:module:MODULE_InitDLL (000000006AC60000 L"win32u.dll",PROCESS_ATTACH,000000000031FB00) 000000006AD09460 - CALL 005c:0060:trace:module:MODULE_InitDLL (000000006AC60000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 005c:0060:trace:module:process_attach (L"win32u.dll",000000000031FB00) - END 005c:0060:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000031FB00) 000000026B509F00 - CALL 005c:0060:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 005c:0060:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - END 005c:0060:trace:module:process_attach (L"version.dll",000000000031FB00) - START 005c:0060:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000031FB00) 00000002F1FA2510 - CALL 005c:0060:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 005c:0060:trace:module:process_attach (L"version.dll",000000000031FB00) - END 005c:0060:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000031FB00) 000000023D8C5690 - CALL 005c:0060:trace:module:load_dll looking for L"imm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 005c:0060:trace:module:get_load_order looking for L"C:\\windows\\system32\\imm32.dll" 005c:0060:trace:module:get_load_order got hardcoded default for L"imm32.dll" 005c:0060:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 005c:0060:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 005c:0060:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 005c:0060:trace:module:import_dll is not hybrid module 005c:0060:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imm32.dll" 000000000043B110 00000003AFD00000 005c:0060:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imm32.dll" at 00000003AFD00000: builtin 005c:0060:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imm32.dll" at 00000003AFD00000 005c:0060:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 005c:0060:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 005c:0060:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EC40, base 000000000031EC38. 005c:0060:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 005c:0060:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F0E0, base 000000000031F0D8. 005c:0060:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 005c:0060:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EBF0, base 000000000031EBE8. 005c:0060:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 005c:0060:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 005c:0060:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 005c:0060:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 005c:0060:trace:module:process_attach (L"user32.dll",000000000031FB00) - END 005c:0060:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 005c:0060:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F7F0, base 000000000031F7E8. 005c:0060:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 005c:0060:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726624, 0x00000000) 005c:0060:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 005c:0060:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=-1 005c:0060:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EEF0, base 000000000031EEE8. 005c:0060:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 005c:0060:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726704, 0x00000000) 005c:0060:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F0F0, base 000000000031F0E8. 005c:0060:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 005c:0060:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266EC, 0x00000000) 005c:0060:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726714, 0x00000000) 005c:0060:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266A4, 0x00000000) 005c:0060:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726684, 0x00000000) 0030:0064:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:0064:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:0064:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:0064:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:0064:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:0064:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0060:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266AC, 0x00000000) 005c:0060:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266BC, 0x00000000) 005c:0060:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72661C, 0x00000000) 005c:0060:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72667C, 0x00000000) 005c:0060:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266DC, 0x00000000) 005c:0068:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 005c:0068:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0068:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 005c:0068:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0068:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 005c:0068:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0068:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",THREAD_ATTACH,0000000000000000) 000000023D8C5690 - CALL 005c:0068:trace:module:MODULE_InitDLL (000000023D820000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0068:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",THREAD_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 005c:0068:trace:module:MODULE_InitDLL (00000003AFD00000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0068:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72660C, 0x00000000) 005c:0068:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72665C, 0x00000000) 005c:0068:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726614, 0x00000000) 005c:0068:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726664, 0x00000000) 005c:006c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 005c:006c:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:006c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 005c:006c:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:006c:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 005c:006c:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:006c:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",THREAD_ATTACH,0000000000000000) 000000023D8C5690 - CALL 005c:006c:trace:module:MODULE_InitDLL (000000023D820000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:006c:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",THREAD_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 005c:006c:trace:module:MODULE_InitDLL (00000003AFD00000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:006c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 00000000013DF7A0, base 00000000013DF798. 005c:006c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 005c:0070:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 005c:0070:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0070:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 005c:0070:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0070:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 005c:0070:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0070:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",THREAD_ATTACH,0000000000000000) 000000023D8C5690 - CALL 005c:0070:trace:module:MODULE_InitDLL (000000023D820000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0070:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",THREAD_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 005c:0070:trace:module:MODULE_InitDLL (00000003AFD00000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:006c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266C4, 0x00000000) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31aa58,0x00000008,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31aa58,0x00000008,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31aa58,0x00000008,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31aa58,0x00000008,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31aa58,0x00000008,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31aa58,0x00000008,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31aa58,0x00000008,0x0) 0030:0040:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\ndis.sys" 0000000000000000 0) 0030:0040:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\ndis.sys" 00000000004519B0 37) 0030:0040:trace:module:GetBinaryTypeW L"C:\\windows\\system32\\drivers\\ndis.sys" 0030:0040:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\winedevice.exe" 0000000000000000 0) 0030:0040:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\winedevice.exe" 0000000000451C20 35) 0030:0040:trace:process:CreateProcessInternalW app (null) cmdline L"C:\\windows\\system32\\winedevice.exe" 0030:0040:trace:process:find_exe_file looking for L"C:\\windows\\system32\\winedevice.exe" in L"C:\\windows\\system32;.;C:\\windows\\system32;C:\\windows\\system;C:\\windows;" 0030:0040:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\winedevice.exe" image L"C:\\windows\\system32\\winedevice.exe" cmdline L"C:\\windows\\system32\\winedevice.exe" parent 0x0 0030:0040:trace:process:send_to_cx_loader loader (null) wineserversocket 32 stdin_fd -1 stdout_fd -1 unixdir (null) winedebug (null) wineloader (null) 0030:0040:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0074:0078:trace:module:get_load_order looking for L"C:\\windows\\system32\\winedevice.exe" 0074:0078:trace:module:get_load_order got hardcoded default for L"winedevice.exe" 0074:0078:trace:module:get_load_order looking for L"C:\\windows\\system32\\winedevice.exe" 0074:0078:trace:module:get_load_order got hardcoded default for L"winedevice.exe" 0074:0078:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\winedevice.exe" at 0x140000000-0x14000a000 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winedevice.exe" section .text at 0x140001000 off 1000 size 2000 virt 13f0 flags 60000020 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winedevice.exe" section .data at 0x140003000 off 3000 size 1000 virt 60 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winedevice.exe" section .rdata at 0x140004000 off 4000 size 1000 virt 2a0 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winedevice.exe" section .pdata at 0x140005000 off 5000 size 1000 virt d8 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winedevice.exe" section .xdata at 0x140006000 off 6000 size 1000 virt e0 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winedevice.exe" section .bss at 0x140007000 off 0 size 0 virt 160 flags c0000080 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winedevice.exe" section .idata at 0x140008000 off 7000 size 1000 virt 7a4 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winedevice.exe" section .reloc at 0x140009000 off 8000 size 1000 virt 10 flags 42000040 0074:0078:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0074:0078:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0030:0040:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\winedevice.exe" pid 0074 tid 0078 handles 0xf4/0xf8 0030:0040:trace:process:CreateProcessInternalW started process pid 0074 tid 0078 0074:0078:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 0074:0078:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\winedevice.exe" 00000000004315F0 0000000140000000 0074:0078:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\winedevice.exe" at 0000000140000000: builtin 0074:0078:trace:module:load_dll looking for L"kernel32.dll" in (null) 0074:0078:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernel32.dll" 0074:0078:trace:module:get_load_order got hardcoded default for L"kernel32.dll" 0074:0078:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0074:0078:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0074:0078:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernelbase.dll" 0074:0078:trace:module:get_load_order got hardcoded default for L"kernelbase.dll" 0074:0078:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0074:0078:trace:module:load_dll looking for L"ntdll.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 0000000000431E70 000000007B000000 0074:0078:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 0074:0078:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"ntdll.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000431B50 000000007B600000 0074:0078:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 0074:0078:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 0074:0078:trace:module:load_dll looking for L"advapi32.dll" in (null) 0074:0078:trace:module:get_load_order looking for L"C:\\windows\\system32\\advapi32.dll" 0074:0078:trace:module:get_load_order got hardcoded default for L"advapi32.dll" 0074:0078:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0074:0078:trace:module:load_dll looking for L"kernel32.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0074:0078:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvcrt.dll" 0074:0078:trace:module:get_load_order got hardcoded default for L"msvcrt.dll" 0074:0078:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0074:0078:trace:module:load_dll looking for L"kernel32.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"ntdll.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 0000000000432320 00000001C8DB0000 0074:0078:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 0074:0078:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"ntdll.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"sechost.dll" in (null) 0074:0078:trace:module:get_load_order looking for L"C:\\windows\\system32\\sechost.dll" 0074:0078:trace:module:get_load_order got hardcoded default for L"sechost.dll" 0074:0078:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0074:0078:trace:module:load_dll looking for L"kernel32.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"ntdll.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0074:0078:trace:module:get_load_order looking for L"C:\\windows\\system32\\ucrtbase.dll" 0074:0078:trace:module:get_load_order got hardcoded default for L"ucrtbase.dll" 0074:0078:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0074:0078:trace:module:load_dll looking for L"kernel32.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"ntdll.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 00000000004328B0 00000003AF670000 0074:0078:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 0074:0078:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 00000000004325C0 000000032A700000 0074:0078:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 0074:0078:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 0000000000432040 0000000330260000 0074:0078:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 0074:0078:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"kernel32.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"ntdll.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"ntoskrnl.exe" in (null) 0074:0078:trace:module:get_load_order looking for L"C:\\windows\\system32\\ntoskrnl.exe" 0074:0078:trace:module:get_load_order got hardcoded default for L"ntoskrnl.exe" 0074:0078:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" at 0x2279a0000-0x2279f9000 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .text at 0x2279a1000 off 1000 size 25000 virt 24e20 flags 60000060 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .data at 0x2279c6000 off 26000 size 1000 virt 530 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .rodata at 0x2279c7000 off 27000 size 6000 virt 5e74 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .rdata at 0x2279cd000 off 2d000 size 6000 virt 5050 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .pdata at 0x2279d3000 off 33000 size 2000 virt 11c4 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .xdata at 0x2279d5000 off 35000 size 2000 virt 10b4 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .bss at 0x2279d7000 off 0 size 0 virt 620 flags c0000080 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .edata at 0x2279d8000 off 37000 size 18000 virt 1777e flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .idata at 0x2279f0000 off 4f000 size 7000 virt 68bc flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .rsrc at 0x2279f7000 off 56000 size 1000 virt 3b8 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .reloc at 0x2279f8000 off 57000 size 1000 virt 144 flags 42000040 0074:0078:trace:module:load_dll looking for L"advapi32.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"kernel32.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\msvcrt.dll" for L"msvcrt.dll" at 00000001C8DB0000, count=2 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"ntdll.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" 0000000000432A80 00000002279A0000 0074:0078:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ntoskrnl.exe" at 00000002279A0000: builtin 0074:0078:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" at 00000002279A0000 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 0074:0078:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 0074:0078:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0074:0078:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 0074:0078:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 0074:0078:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 0074:0078:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 0074:0078:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 0074:0078:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 0074:0078:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0074:0078:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 0074:0078:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 0074:0078:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0074:0078:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 0074:0078:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 0074:0078:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 0074:0078:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 0074:0078:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F3B0. 0074:0078:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\winedevice.exe" 0074:0078:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F400. 0074:0078:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\winedevice.exe" 0074:0078:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0074:0078:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0074:0078:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 0074:0078:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 0074:0078:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 0074:0078:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 0074:0078:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 0074:0078:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\winedevice.exe" 0074:0078:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 0074:0078:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\winedevice.exe" 0074:0078:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0074:0078:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 0074:0078:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 0074:0078:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0074:0078:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 0074:0078:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 0074:0078:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0074:0078:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 0074:0078:trace:module:process_attach (L"ntoskrnl.exe",000000000031FB00) - START 0074:0078:trace:module:MODULE_InitDLL (00000002279A0000 L"ntoskrnl.exe",PROCESS_ATTACH,000000000031FB00) 00000002279C3D50 - CALL 0074:0078:trace:module:LdrRegisterDllNotification (0, 00000002279AEE00, 0000000000000000, 00000002279D7420) 0074:0078:trace:module:MODULE_InitDLL (00000002279A0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0074:0078:trace:module:process_attach (L"ntoskrnl.exe",000000000031FB00) - END 0074:0078:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 0074:0078:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F7D0, base 000000000031F7C8. 0074:0078:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0078:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726624, 0x00000000) 0074:0078:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0074:0078:trace:module:get_load_order looking for L"C:\\windows\\system32\\rpcrt4.dll" 0074:0078:trace:module:get_load_order_value got environment b for L"rpcrt4" 0074:0078:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0x231ae0000-0x231b62000 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .text at 0x231ae1000 off 1000 size 47000 virt 46400 flags 60000060 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .data at 0x231b28000 off 48000 size 1000 virt 710 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rodata at 0x231b29000 off 49000 size 2000 virt 1b44 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rdata at 0x231b2b000 off 4b000 size 15000 virt 14b90 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .pdata at 0x231b40000 off 60000 size 3000 virt 2334 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .xdata at 0x231b43000 off 63000 size 3000 virt 289c flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .bss at 0x231b46000 off 0 size 0 virt 690 flags c0000080 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .edata at 0x231b47000 off 66000 size 17000 virt 16730 flags 40000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .idata at 0x231b5e000 off 7d000 size 2000 virt 19a8 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rsrc at 0x231b60000 off 7f000 size 1000 virt 3a8 flags c0000040 0074:0078:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .reloc at 0x231b61000 off 80000 size 1000 virt 504 flags 42000040 0074:0078:trace:module:load_dll looking for L"advapi32.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"kernel32.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"ntdll.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0074:0078:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0074:0078:trace:module:import_dll is not hybrid module 0074:0078:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rpcrt4.dll" 000000000043A560 0000000231AE0000 0074:0078:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000: builtin 0074:0078:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000 0074:0078:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - START 0074:0078:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EDE0, base 000000000031EDD8. 0074:0078:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0078:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EAE0, base 000000000031EAD8. 0074:0078:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0078:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_ATTACH,0000000000000000) 0000000231B26040 - CALL 0074:0078:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0074:0078:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - END 0074:0078:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EED0, base 000000000031EEC8. 0074:0078:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0078:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726704, 0x00000000) 0074:0078:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F0D0, base 000000000031F0C8. 0074:0078:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0078:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266EC, 0x00000000) 0074:0078:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726714, 0x00000000) 0074:0078:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266A4, 0x00000000) 0074:0078:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726684, 0x00000000) 0030:007c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:007c:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:007c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:007c:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:007c:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:007c:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0074:0078:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266AC, 0x00000000) 0074:0078:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266BC, 0x00000000) 0074:0078:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72661C, 0x00000000) 0074:0078:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72667C, 0x00000000) 0074:0078:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266DC, 0x00000000) 0074:0080:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0074:0080:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0074:0080:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0074:0080:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0074:0080:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0074:0080:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0074:0080:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72660C, 0x00000000) 0074:0080:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72665C, 0x00000000) 0074:0080:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726614, 0x00000000) 0074:0080:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726664, 0x00000000) 0074:0084:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0074:0084:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0074:0084:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0074:0084:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0074:0084:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0074:0084:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0074:0084:trace:module:LdrAddDllDirectory L"\\??\\C:\\windows\\system32\\drivers" 0074:0084:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 00000000012CF8D0, base 00000000012CF8C8. 0074:0084:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0084:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 00000000012CF5C0, base 00000000012CF5B8. 0074:0084:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0084:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266C4, 0x00000000) 0074:0084:trace:process:NtQueryInformationProcess (0x54,0x00000000,0x440028,0x00000030,0x0) 0074:0084:trace:process:NtQueryInformationProcess (0x54,0x0000001a,0x12cf2b8,0x00000008,0x0) 0074:0084:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DA0, 0000000000000000, 000000007B60C498, 00000002279F2944, 0x00000000) 0074:0084:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0074:0084:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=2 0074:0084:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DA0, 0000000000000000, 000000007B60C498, 00000002279F2934, 0x00000000) 0074:0084:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DA0, 0000000000000000, 000000007B60C498, 00000002279F294C, 0x00000000) 0074:0080:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72663C, 0x00000000) 0074:0080:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\ndis.sys" 0000000000000000 0) 0074:0080:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\ndis.sys" 000000000043FDB0 37) 0074:0080:trace:module:load_dll looking for L"C:\\windows\\system32\\drivers\\ndis.sys" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:get_load_order looking for L"C:\\windows\\system32\\drivers\\ndis.sys" 0074:0080:trace:module:get_load_order got hardcoded default for L"C:\\windows\\system32\\drivers\\ndis.sys" 0074:0080:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\drivers\\ndis.sys" at 0x1dc4b0000-0x1dc4c3000 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\ndis.sys" section .text at 0x1dc4b1000 off 1000 size 3000 virt 3000 flags 60000020 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\ndis.sys" section .data at 0x1dc4b4000 off 4000 size 1000 virt 70 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\ndis.sys" section .rodata at 0x1dc4b5000 off 5000 size 2000 virt 1d98 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\ndis.sys" section .rdata at 0x1dc4b7000 off 7000 size 1000 virt 440 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\ndis.sys" section .pdata at 0x1dc4b8000 off 8000 size 1000 virt 114 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\ndis.sys" section .xdata at 0x1dc4b9000 off 9000 size 1000 virt 110 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\ndis.sys" section .bss at 0x1dc4ba000 off 0 size 0 virt 140 flags c0000080 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\ndis.sys" section .edata at 0x1dc4bb000 off a000 size 6000 virt 56b2 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\ndis.sys" section .idata at 0x1dc4c1000 off 10000 size 1000 virt 608 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\ndis.sys" section .reloc at 0x1dc4c2000 off 11000 size 1000 virt 20 flags 42000040 0074:0080:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"iphlpapi.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:get_load_order looking for L"C:\\windows\\system32\\iphlpapi.dll" 0074:0080:trace:module:get_load_order got hardcoded default for L"iphlpapi.dll" 0074:0080:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\iphlpapi.dll" at 0x240030000-0x24005d000 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iphlpapi.dll" section .text at 0x240031000 off 1000 size d000 virt cd00 flags 60000020 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iphlpapi.dll" section .data at 0x24003e000 off e000 size 1000 virt 70 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iphlpapi.dll" section .rodata at 0x24003f000 off f000 size 1000 virt 854 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iphlpapi.dll" section .rdata at 0x240040000 off 10000 size 8000 virt 77d0 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iphlpapi.dll" section .pdata at 0x240048000 off 18000 size 1000 virt 768 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iphlpapi.dll" section .xdata at 0x240049000 off 19000 size 1000 virt 7c4 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iphlpapi.dll" section .bss at 0x24004a000 off 0 size 0 virt 160 flags c0000080 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iphlpapi.dll" section .edata at 0x24004b000 off 1a000 size f000 virt ec66 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iphlpapi.dll" section .idata at 0x24005a000 off 29000 size 1000 virt 998 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iphlpapi.dll" section .rsrc at 0x24005b000 off 2a000 size 1000 virt 3b0 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iphlpapi.dll" section .reloc at 0x24005c000 off 2b000 size 1000 virt 48 flags 42000040 0074:0080:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"dnsapi.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:get_load_order looking for L"C:\\windows\\system32\\dnsapi.dll" 0074:0080:trace:module:get_load_order got hardcoded default for L"dnsapi.dll" 0074:0080:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\dnsapi.dll" at 0x29cfc0000-0x29cfd6000 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dnsapi.dll" section .text at 0x29cfc1000 off 1000 size 8000 virt 7110 flags 60000060 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dnsapi.dll" section .data at 0x29cfc9000 off 9000 size 1000 virt b0 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dnsapi.dll" section .rodata at 0x29cfca000 off a000 size 1000 virt b48 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dnsapi.dll" section .rdata at 0x29cfcb000 off b000 size 2000 virt 1340 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dnsapi.dll" section .pdata at 0x29cfcd000 off d000 size 1000 virt 390 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dnsapi.dll" section .xdata at 0x29cfce000 off e000 size 1000 virt 3d8 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dnsapi.dll" section .bss at 0x29cfcf000 off 0 size 0 virt 170 flags c0000080 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dnsapi.dll" section .edata at 0x29cfd0000 off f000 size 3000 virt 2898 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dnsapi.dll" section .idata at 0x29cfd3000 off 12000 size 1000 virt 638 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dnsapi.dll" section .rsrc at 0x29cfd4000 off 13000 size 1000 virt 398 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dnsapi.dll" section .reloc at 0x29cfd5000 off 14000 size 1000 virt 30 flags 42000040 0074:0080:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\dnsapi.dll" 00000000004426D0 000000029CFC0000 0074:0080:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\dnsapi.dll" at 000000029CFC0000: builtin 0074:0080:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\dnsapi.dll" at 000000029CFC0000 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"nsi.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:get_load_order looking for L"C:\\windows\\system32\\nsi.dll" 0074:0080:trace:module:get_load_order got hardcoded default for L"nsi.dll" 0074:0080:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\nsi.dll" at 0x28dfa0000-0x28dfac000 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\nsi.dll" section .text at 0x28dfa1000 off 1000 size 2000 virt 1d70 flags 60000020 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\nsi.dll" section .data at 0x28dfa3000 off 3000 size 1000 virt 70 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\nsi.dll" section .rodata at 0x28dfa4000 off 4000 size 1000 virt 29c flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\nsi.dll" section .rdata at 0x28dfa5000 off 5000 size 1000 virt 2e0 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\nsi.dll" section .pdata at 0x28dfa6000 off 6000 size 1000 virt 114 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\nsi.dll" section .xdata at 0x28dfa7000 off 7000 size 1000 virt 15c flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\nsi.dll" section .bss at 0x28dfa8000 off 0 size 0 virt 140 flags c0000080 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\nsi.dll" section .edata at 0x28dfa9000 off 8000 size 1000 virt 98a flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\nsi.dll" section .idata at 0x28dfaa000 off 9000 size 1000 virt 41c flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\nsi.dll" section .reloc at 0x28dfab000 off a000 size 1000 virt 20 flags 42000040 0074:0080:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\nsi.dll" 00000000004429E0 000000028DFA0000 0074:0080:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\nsi.dll" at 000000028DFA0000: builtin 0074:0080:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\nsi.dll" at 000000028DFA0000 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\iphlpapi.dll" 00000000004423C0 0000000240030000 0074:0080:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\iphlpapi.dll" at 0000000240030000: builtin 0074:0080:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\iphlpapi.dll" at 0000000240030000 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ntoskrnl.exe" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ntoskrnl.exe" for L"ntoskrnl.exe" at 00000002279A0000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\drivers\\ndis.sys" 0000000000442070 00000001DC4B0000 0074:0080:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\drivers\\ndis.sys" at 00000001DC4B0000: builtin 0074:0080:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\drivers\\ndis.sys" at 00000001DC4B0000 0074:0080:trace:module:process_attach (L"ndis.sys",0000000000000000) - START 0074:0080:trace:module:process_attach (L"iphlpapi.dll",0000000000000000) - START 0074:0080:trace:module:process_attach (L"dnsapi.dll",0000000000000000) - START 0074:0080:trace:module:MODULE_InitDLL (000000029CFC0000 L"dnsapi.dll",PROCESS_ATTACH,0000000000000000) 000000029CFC74F0 - CALL 0074:0080:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCED40, base 0000000000FCED38. 0074:0080:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0080:trace:module:MODULE_InitDLL (000000029CFC0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0074:0080:trace:module:process_attach (L"dnsapi.dll",0000000000000000) - END 0074:0080:trace:module:process_attach (L"nsi.dll",0000000000000000) - START 0074:0080:trace:module:MODULE_InitDLL (000000028DFA0000 L"nsi.dll",PROCESS_ATTACH,0000000000000000) 000000028DFA2280 - CALL 0074:0080:trace:module:MODULE_InitDLL (000000028DFA0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0074:0080:trace:module:process_attach (L"nsi.dll",0000000000000000) - END 0074:0080:trace:module:MODULE_InitDLL (0000000240030000 L"iphlpapi.dll",PROCESS_ATTACH,0000000000000000) 000000024003D160 - CALL 0074:0080:trace:module:MODULE_InitDLL (0000000240030000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0074:0080:trace:module:process_attach (L"iphlpapi.dll",0000000000000000) - END 0074:0080:trace:module:process_attach (L"ndis.sys",0000000000000000) - END 0074:0080:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCF8A0, base 0000000000FCF898. 0074:0080:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0080:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCF590, base 0000000000FCF588. 0074:0080:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0080:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCF2D0, base 0000000000FCF2C8. 0074:0080:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0080:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCF0E0, base 0000000000FCF0D8. 0074:0080:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0080:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F299C, 0x00000000) 0074:0080:trace:module:load_dll looking for L"setupapi.dll" in (null) 0074:0080:trace:module:get_load_order looking for L"C:\\windows\\system32\\setupapi.dll" 0074:0080:trace:module:get_load_order got hardcoded default for L"setupapi.dll" 0074:0080:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" at 0x21a7e0000-0x21a856000 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .text at 0x21a7e1000 off 1000 size 37000 virt 365e0 flags 60000060 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .data at 0x21a818000 off 38000 size 1000 virt 230 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rodata at 0x21a819000 off 39000 size 3000 virt 244c flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rdata at 0x21a81c000 off 3c000 size e000 virt d010 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .pdata at 0x21a82a000 off 4a000 size 2000 virt 1818 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .xdata at 0x21a82c000 off 4c000 size 2000 virt 1d24 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .bss at 0x21a82e000 off 0 size 0 virt 720 flags c0000080 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .edata at 0x21a82f000 off 4e000 size 18000 virt 171c8 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .idata at 0x21a847000 off 66000 size 2000 virt 1f34 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rsrc at 0x21a849000 off 68000 size c000 virt bf00 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .reloc at 0x21a855000 off 74000 size 1000 virt d8 flags 42000040 0074:0080:trace:module:load_dll looking for L"advapi32.dll" in (null) 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"kernel32.dll" in (null) 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ntdll.dll" in (null) 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=3 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"version.dll" in (null) 0074:0080:trace:module:get_load_order looking for L"C:\\windows\\system32\\version.dll" 0074:0080:trace:module:get_load_order got hardcoded default for L"version.dll" 0074:0080:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 0074:0080:trace:module:load_dll looking for L"kernel32.dll" in (null) 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ntdll.dll" in (null) 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 0000000000442F60 00000002F1FA0000 0074:0080:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 00000002F1FA0000: builtin 0074:0080:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 00000002F1FA0000 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\setupapi.dll" 0000000000442C00 000000021A7E0000 0074:0080:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\setupapi.dll" at 000000021A7E0000: builtin 0074:0080:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\setupapi.dll" at 000000021A7E0000 0074:0080:trace:module:process_attach (L"setupapi.dll",0000000000000000) - START 0074:0080:trace:module:process_attach (L"version.dll",0000000000000000) - START 0074:0080:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,0000000000000000) 00000002F1FA2510 - CALL 0074:0080:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0074:0080:trace:module:process_attach (L"version.dll",0000000000000000) - END 0074:0080:trace:module:MODULE_InitDLL (000000021A7E0000 L"setupapi.dll",PROCESS_ATTACH,0000000000000000) 000000021A816860 - CALL 0074:0080:trace:module:MODULE_InitDLL (000000021A7E0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0074:0080:trace:module:process_attach (L"setupapi.dll",0000000000000000) - END 0074:0080:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCF2B0, base 0000000000FCF2A8. 0074:0080:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0080:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCEFA0, base 0000000000FCEF98. 0074:0080:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0080:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F2994, 0x00000000) 0074:0080:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F298C, 0x00000000) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31aa58,0x00000008,0x0) 0030:0040:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\nsiproxy.sys" 0000000000000000 0) 0030:0040:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\nsiproxy.sys" 00000000004546E0 41) 0030:0040:trace:module:GetBinaryTypeW L"C:\\windows\\system32\\drivers\\nsiproxy.sys" 0074:0080:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\nsiproxy.sys" 0000000000000000 0) 0074:0080:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\nsiproxy.sys" 00000000004436C0 41) 0074:0080:trace:module:load_dll looking for L"C:\\windows\\system32\\drivers\\nsiproxy.sys" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:get_load_order looking for L"C:\\windows\\system32\\drivers\\nsiproxy.sys" 0074:0080:trace:module:get_load_order got hardcoded default for L"C:\\windows\\system32\\drivers\\nsiproxy.sys" 0074:0080:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\drivers\\nsiproxy.sys" at 0x229880000-0x22988b000 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\nsiproxy.sys" section .text at 0x229881000 off 1000 size 2000 virt 19a0 flags 60000020 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\nsiproxy.sys" section .data at 0x229883000 off 3000 size 1000 virt d0 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\nsiproxy.sys" section .rdata at 0x229884000 off 4000 size 1000 virt 380 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\nsiproxy.sys" section .pdata at 0x229885000 off 5000 size 1000 virt fc flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\nsiproxy.sys" section .xdata at 0x229886000 off 6000 size 1000 virt 118 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\nsiproxy.sys" section .bss at 0x229887000 off 0 size 0 virt 170 flags c0000080 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\nsiproxy.sys" section .edata at 0x229888000 off 7000 size 1000 virt 11d flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\nsiproxy.sys" section .idata at 0x229889000 off 8000 size 1000 virt 5d4 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\nsiproxy.sys" section .reloc at 0x22988a000 off 9000 size 1000 virt 28 flags 42000040 0074:0080:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ntoskrnl.exe" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ntoskrnl.exe" for L"ntoskrnl.exe" at 00000002279A0000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\drivers\\nsiproxy.sys" 00000000004438C0 0000000229880000 0074:0080:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\drivers\\nsiproxy.sys" at 0000000229880000: builtin 0074:0080:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\drivers\\nsiproxy.sys" at 0000000229880000 0074:0080:trace:module:process_attach (L"nsiproxy.sys",0000000000000000) - START 0074:0080:trace:module:process_attach (L"nsiproxy.sys",0000000000000000) - END 0074:0080:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCF830, base 0000000000FCF828. 0074:0080:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0080:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCF520, base 0000000000FCF518. 0074:0080:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0088:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0074:0088:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0074:0088:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0074:0088:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0074:0088:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0074:0088:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004D20, 0000000000000000, 000000007B60C498, 000000014001586C, 0x00000000) 0030:003c:trace:module:LdrShutdownThread () 0030:003c:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_DETACH,0000000000000000) 0000000231B26040 - CALL 0030:003c:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:003c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_DETACH,0000000000000000) 00000003AF6F1C30 - CALL 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004D00, 0000000000000000, 000000007B60C498, 0000000140015A64, 0x00000000) 0030:003c:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_DETACH,0000000000000000) - RETURN 1 0028:002c:trace:module:load_dll looking for L"user32.dll" in (null) 0030:003c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_DETACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:003c:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_DETACH,0000000000000000) - RETURN 1 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=10 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004D00, 0000000000000000, 000000007B60C498, 0000000140015AE4, 0x00000000) 0028:002c:trace:process:CreateProcessInternalW app L"C:\\windows\\system32\\rundll32.exe" cmdline L"C:\\windows\\system32\\rundll32.exe setupapi,InstallHinfSection PreInstall 128 \\\\?\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\wine.inf" 0028:002c:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\rundll32.exe" image L"C:\\windows\\system32\\rundll32.exe" cmdline L"C:\\windows\\system32\\rundll32.exe setupapi,InstallHinfSection PreInstall 128 \\\\?\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\wine.inf" parent 0x0 0028:002c:trace:process:send_to_cx_loader loader (null) wineserversocket 12 stdin_fd -1 stdout_fd -1 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 0028:002c:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\rundll32.exe" 008c:0090:trace:module:get_load_order got hardcoded default for L"rundll32.exe" 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\rundll32.exe" 008c:0090:trace:module:get_load_order got hardcoded default for L"rundll32.exe" 008c:0090:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\rundll32.exe" at 0x140000000-0x14000a000 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rundll32.exe" section .text at 0x140001000 off 1000 size 2000 virt 1bb0 flags 60000020 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rundll32.exe" section .data at 0x140003000 off 3000 size 1000 virt 40 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rundll32.exe" section .rdata at 0x140004000 off 4000 size 1000 virt 250 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rundll32.exe" section .pdata at 0x140005000 off 5000 size 1000 virt d8 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rundll32.exe" section .xdata at 0x140006000 off 6000 size 1000 virt e8 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rundll32.exe" section .bss at 0x140007000 off 0 size 0 virt 140 flags c0000080 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rundll32.exe" section .idata at 0x140008000 off 7000 size 1000 virt 764 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rundll32.exe" section .reloc at 0x140009000 off 8000 size 1000 virt 14 flags 42000040 008c:0090:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 008c:0090:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0028:002c:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\rundll32.exe" pid 008c tid 0090 handles 0x8c/0x90 0028:002c:trace:process:CreateProcessInternalW started process pid 008c tid 0090 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004D00, 0000000000000000, 000000007B60C498, 0000000140015AC4, 0x00000000) 008c:0090:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rundll32.exe" 00000000004321E0 0000000140000000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rundll32.exe" at 0000000140000000: builtin 008c:0090:trace:module:load_dll looking for L"kernel32.dll" in (null) 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernel32.dll" 008c:0090:trace:module:get_load_order got hardcoded default for L"kernel32.dll" 008c:0090:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 008c:0090:trace:module:load_dll looking for L"kernelbase.dll" in (null) 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernelbase.dll" 008c:0090:trace:module:get_load_order got hardcoded default for L"kernelbase.dll" 008c:0090:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 0000000000432A60 000000007B000000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 008c:0090:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000432740 000000007B600000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 008c:0090:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 008c:0090:trace:module:load_dll looking for L"kernel32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\ucrtbase.dll" 008c:0090:trace:module:get_load_order got hardcoded default for L"ucrtbase.dll" 008c:0090:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 008c:0090:trace:module:load_dll looking for L"kernel32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 0000000000432C30 00000003AF670000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 008c:0090:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"user32.dll" in (null) 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\user32.dll" 008c:0090:trace:module:get_load_order got hardcoded default for L"user32.dll" 008c:0090:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 008c:0090:trace:module:load_dll looking for L"advapi32.dll" in (null) 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\advapi32.dll" 008c:0090:trace:module:get_load_order got hardcoded default for L"advapi32.dll" 008c:0090:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 008c:0090:trace:module:load_dll looking for L"kernel32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"kernelbase.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"msvcrt.dll" in (null) 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvcrt.dll" 008c:0090:trace:module:get_load_order got hardcoded default for L"msvcrt.dll" 008c:0090:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 008c:0090:trace:module:load_dll looking for L"kernel32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 0000000000433490 00000001C8DB0000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 008c:0090:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"sechost.dll" in (null) 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\sechost.dll" 008c:0090:trace:module:get_load_order got hardcoded default for L"sechost.dll" 008c:0090:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 008c:0090:trace:module:load_dll looking for L"kernel32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"kernelbase.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 00000000004335F0 000000032A700000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 008c:0090:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 0000000000433180 0000000330260000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 008c:0090:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"gdi32.dll" in (null) 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\gdi32.dll" 008c:0090:trace:module:get_load_order got hardcoded default for L"gdi32.dll" 008c:0090:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 008c:0090:trace:module:load_dll looking for L"advapi32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"kernel32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"user32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"win32u.dll" in (null) 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\win32u.dll" 008c:0090:trace:module:get_load_order got hardcoded default for L"win32u.dll" 008c:0090:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\win32u.dll" is a fake Wine dll 008c:0090:trace:module:load_dll looking for L"kernel32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\win32u.dll" 0000000000433CD0 000000006AC60000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\win32u.dll" at 000000006AC60000: builtin 008c:0090:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\win32u.dll" at 000000006AC60000 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\gdi32.dll" 00000000004338A0 000000026B4C0000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000: builtin 008c:0090:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"kernel32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"kernelbase.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"sechost.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"version.dll" in (null) 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\version.dll" 008c:0090:trace:module:get_load_order got hardcoded default for L"version.dll" 008c:0090:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 008c:0090:trace:module:load_dll looking for L"kernel32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"kernelbase.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 0000000000433FF0 00000002F1FA0000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 00000002F1FA0000: builtin 008c:0090:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 00000002F1FA0000 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"win32u.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AC60000, count=2 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\user32.dll" 0000000000432ED0 000000023D820000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\user32.dll" at 000000023D820000: builtin 008c:0090:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\user32.dll" at 000000023D820000 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 008c:0090:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 008c:0090:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 008c:0090:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 008c:0090:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 008c:0090:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 008c:0090:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 008c:0090:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 008c:0090:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 008c:0090:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 008c:0090:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 008c:0090:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 008c:0090:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 008c:0090:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 008c:0090:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 008c:0090:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 008c:0090:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F440. 008c:0090:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\rundll32.exe" 008c:0090:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F490. 008c:0090:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\rundll32.exe" 008c:0090:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 008c:0090:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 008c:0090:trace:module:process_attach (L"user32.dll",000000000031FB00) - START 008c:0090:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 008c:0090:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 008c:0090:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 008c:0090:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 008c:0090:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\rundll32.exe" 008c:0090:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 008c:0090:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\rundll32.exe" 008c:0090:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 008c:0090:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 008c:0090:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 008c:0090:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 008c:0090:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 008c:0090:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 008c:0090:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 008c:0090:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 008c:0090:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 008c:0090:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 008c:0090:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - START 008c:0090:trace:module:process_attach (L"win32u.dll",000000000031FB00) - START 008c:0090:trace:module:MODULE_InitDLL (000000006AC60000 L"win32u.dll",PROCESS_ATTACH,000000000031FB00) 000000006AD09460 - CALL 008c:0090:trace:module:MODULE_InitDLL (000000006AC60000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 008c:0090:trace:module:process_attach (L"win32u.dll",000000000031FB00) - END 008c:0090:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000031FB00) 000000026B509F00 - CALL 008c:0090:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 008c:0090:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - END 008c:0090:trace:module:process_attach (L"version.dll",000000000031FB00) - START 008c:0090:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000031FB00) 00000002F1FA2510 - CALL 008c:0090:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 008c:0090:trace:module:process_attach (L"version.dll",000000000031FB00) - END 008c:0090:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000031FB00) 000000023D8C5690 - CALL 008c:0090:trace:module:load_dll looking for L"imm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\imm32.dll" 008c:0090:trace:module:get_load_order got hardcoded default for L"imm32.dll" 008c:0090:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 008c:0090:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imm32.dll" 000000000043B250 00000003AFD00000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imm32.dll" at 00000003AFD00000: builtin 008c:0090:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imm32.dll" at 00000003AFD00000 008c:0090:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 008c:0090:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 008c:0090:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EC40, base 000000000031EC38. 008c:0090:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 008c:0090:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F0E0, base 000000000031F0D8. 008c:0090:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 008c:0090:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EBF0, base 000000000031EBE8. 008c:0090:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 008c:0090:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 008c:0090:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 008c:0090:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 008c:0090:trace:module:process_attach (L"user32.dll",000000000031FB00) - END 008c:0090:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 008c:0090:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F620, base 000000000031F618. 008c:0090:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 008c:0090:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\explorer.exe" image L"C:\\windows\\system32\\explorer.exe" cmdline L"\"C:\\windows\\system32\\explorer.exe\" /desktop" parent 0x0 008c:0090:trace:process:send_to_cx_loader loader (null) wineserversocket 10 stdin_fd -1 stdout_fd -1 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 008c:0090:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\explorer.exe" 0094:0098:trace:module:get_load_order got hardcoded default for L"explorer.exe" 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\explorer.exe" 0094:0098:trace:module:get_load_order got hardcoded default for L"explorer.exe" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\explorer.exe" at 0x140000000-0x140020000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\explorer.exe" section .text at 0x140001000 off 1000 size f000 virt e390 flags 60000060 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\explorer.exe" section .data at 0x140010000 off 10000 size 1000 virt 170 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\explorer.exe" section .rdata at 0x140011000 off 11000 size 7000 virt 62b0 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\explorer.exe" section .pdata at 0x140018000 off 18000 size 1000 virt 9b4 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\explorer.exe" section .xdata at 0x140019000 off 19000 size 1000 virt 8f0 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\explorer.exe" section .bss at 0x14001a000 off 0 size 0 virt 660 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\explorer.exe" section .idata at 0x14001b000 off 1a000 size 2000 virt 1dec flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\explorer.exe" section .rsrc at 0x14001d000 off 1c000 size 2000 virt 1840 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\explorer.exe" section .reloc at 0x14001f000 off 1e000 size 1000 virt 264 flags 42000040 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0094:0098:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 008c:0090:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\explorer.exe" pid 0094 tid 0098 handles 0x58/0x5c 0094:0098:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\explorer.exe" 00000000004320F0 0000000140000000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\explorer.exe" at 0000000140000000: builtin 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in (null) 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernel32.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"kernel32.dll" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0094:0098:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernelbase.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"kernelbase.dll" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 0000000000432970 000000007B000000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000432650 000000007B600000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 0094:0098:trace:module:load_dll looking for L"advapi32.dll" in (null) 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\advapi32.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"advapi32.dll" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvcrt.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"msvcrt.dll" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 0000000000434BD0 00000001C8DB0000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"sechost.dll" in (null) 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\sechost.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"sechost.dll" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\ucrtbase.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"ucrtbase.dll" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 0000000000433D10 00000003AF670000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 0000000000433950 000000032A700000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 0000000000433500 0000000330260000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"gdi32.dll" in (null) 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\gdi32.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"gdi32.dll" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 0094:0098:trace:module:load_dll looking for L"advapi32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"user32.dll" in (null) 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\user32.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"user32.dll" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 0094:0098:trace:module:load_dll looking for L"advapi32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"gdi32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"sechost.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"version.dll" in (null) 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\version.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"version.dll" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 0000000000435AC0 00000002F1FA0000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 00000002F1FA0000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 00000002F1FA0000 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"win32u.dll" in (null) 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\win32u.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"win32u.dll" 0094:0098:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\win32u.dll" is a fake Wine dll 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\win32u.dll" 0000000000435EB0 000000006AB60000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\win32u.dll" at 000000006AB60000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\win32u.dll" at 000000006AB60000 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\user32.dll" 0000000000434290 000000023D820000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\user32.dll" at 000000023D820000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\user32.dll" at 000000023D820000 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"win32u.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AB60000, count=2 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\gdi32.dll" 0000000000433EE0 000000026B4C0000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\rpcrt4.dll" 0094:0098:trace:module:get_load_order_value got environment b for L"rpcrt4" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0x231ae0000-0x231b62000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .text at 0x231ae1000 off 1000 size 47000 virt 46400 flags 60000060 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .data at 0x231b28000 off 48000 size 1000 virt 710 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rodata at 0x231b29000 off 49000 size 2000 virt 1b44 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rdata at 0x231b2b000 off 4b000 size 15000 virt 14b90 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .pdata at 0x231b40000 off 60000 size 3000 virt 2334 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .xdata at 0x231b43000 off 63000 size 3000 virt 289c flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .bss at 0x231b46000 off 0 size 0 virt 690 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .edata at 0x231b47000 off 66000 size 17000 virt 16730 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .idata at 0x231b5e000 off 7d000 size 2000 virt 19a8 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rsrc at 0x231b60000 off 7f000 size 1000 virt 3a8 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .reloc at 0x231b61000 off 80000 size 1000 virt 504 flags 42000040 0094:0098:trace:module:load_dll looking for L"advapi32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=4 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=11 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=13 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rpcrt4.dll" 0000000000436010 0000000231AE0000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=6 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"user32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 0094:0098:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 0094:0098:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0094:0098:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 0094:0098:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 0094:0098:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 0094:0098:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 0094:0098:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 0094:0098:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 0094:0098:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0094:0098:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 0094:0098:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 0094:0098:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0094:0098:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 0094:0098:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 0094:0098:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 0094:0098:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 0094:0098:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F3B0. 0094:0098:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\explorer.exe" 0094:0098:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F400. 0094:0098:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\explorer.exe" 0094:0098:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0094:0098:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0094:0098:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 0094:0098:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 0094:0098:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 0094:0098:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 0094:0098:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 0094:0098:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\explorer.exe" 0094:0098:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 0094:0098:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\explorer.exe" 0094:0098:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0094:0098:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 0094:0098:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 0094:0098:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0094:0098:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 0094:0098:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 0094:0098:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0094:0098:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 0094:0098:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - START 0094:0098:trace:module:process_attach (L"user32.dll",000000000031FB00) - START 0094:0098:trace:module:process_attach (L"version.dll",000000000031FB00) - START 0094:0098:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000031FB00) 00000002F1FA2510 - CALL 0094:0098:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0094:0098:trace:module:process_attach (L"version.dll",000000000031FB00) - END 0094:0098:trace:module:process_attach (L"win32u.dll",000000000031FB00) - START 0094:0098:trace:module:MODULE_InitDLL (000000006AB60000 L"win32u.dll",PROCESS_ATTACH,000000000031FB00) 000000006AC09460 - CALL 0094:0098:trace:module:MODULE_InitDLL (000000006AB60000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0094:0098:trace:module:process_attach (L"win32u.dll",000000000031FB00) - END 0094:0098:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000031FB00) 000000023D8C5690 - CALL 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F130, base 000000000031F128. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EE20, base 000000000031EE18. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:0098:trace:module:load_dll looking for L"imm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\imm32.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"imm32.dll" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 0094:0098:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imm32.dll" 000000000043E1C0 00000003AFD00000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imm32.dll" at 00000003AFD00000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imm32.dll" at 00000003AFD00000 0094:0098:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 0094:0098:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EBB0, base 000000000031EBA8. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031F048. 0094:0098:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 0094:0098:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0094:0098:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 0094:0098:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0094:0098:trace:module:process_attach (L"user32.dll",000000000031FB00) - END 0094:0098:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000031FB00) 000000026B509F00 - CALL 0094:0098:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0094:0098:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - END 0094:0098:trace:module:process_attach (L"rpcrt4.dll",000000000031FB00) - START 0094:0098:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_ATTACH,000000000031FB00) 0000000231B26040 - CALL 0094:0098:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0094:0098:trace:module:process_attach (L"rpcrt4.dll",000000000031FB00) - END 0094:0098:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EC20, base 000000000031EC18. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E8D0, base 000000000031E8C8. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EC20, base 000000000031EC18. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E940, base 000000000031E938. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:0098:trace:module:load_dll looking for L"winemac.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\winemac.drv" 0094:0098:trace:module:get_load_order got hardcoded default for L"winemac.drv" 0094:0098:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\winemac.drv" is a fake Wine dll 0094:0098:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"win32u.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AB60000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\winemac.drv" 000000000043E3E0 000000006DD10000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\winemac.drv" at 000000006DD10000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\winemac.drv" at 000000006DD10000 0094:0098:trace:module:process_attach (L"winemac.drv",0000000000000000) - START 0094:0098:trace:module:MODULE_InitDLL (000000006DD10000 L"winemac.drv",PROCESS_ATTACH,0000000000000000) 000000006DD28C10 - CALL 0094:0098:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031E630. 0094:0098:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\explorer.exe" 0094:0098:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 0094:0098:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 0094:0098:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 0094:0098:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 0094:0098:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 0094:0098:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 0094:0098:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 0094:0098:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 0094:0098:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 0094:0098:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 0094:0098:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 0094:0098:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 0094:0098:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 0094:0098:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 0094:0098:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 0094:0098:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 0094:0098:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 0094:0098:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 0094:0098:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 0094:0098:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 0094:0098:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 0094:0098:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 0094:0098:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 0094:0098:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 0094:0098:trace:module:MODULE_InitDLL (000000006DD10000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0094:0098:trace:module:process_attach (L"winemac.drv",0000000000000000) - END 0094:0098:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0094:0098:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0094:0098:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031DF70. 0094:0098:trace:module:LoadResource 000000023D820000 000000023D908880 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031D760, base 000000000031D758. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031DBB0. 0094:0098:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0094:0098:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0094:0098:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031DF70. 0094:0098:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0094:0098:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0094:0098:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031DF70. 0094:0098:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0094:0098:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0094:0098:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031DF70. 0094:0098:trace:module:FindResourceExW 000000023D820000 #000c #7f01 0000 0094:0098:trace:module:LoadResource 000000023D820000 000000023D90A4C0 0094:0098:trace:module:FindResourceExW 000000023D820000 #0001 #0009 0000 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031DF70. 0094:0098:trace:module:LoadResource 000000023D820000 000000023D9088E0 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031DBB0. 0094:0098:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0094:0098:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0094:0098:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031DF70. 0094:0098:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0094:0098:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0094:0098:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031DF70. 0094:0098:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0094:0098:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0094:0098:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031DF70. 0094:0098:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0094:0098:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0094:0098:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031DF70. 0094:0098:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0094:0098:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0094:0098:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031DF70. 0094:0098:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0094:0098:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0094:0098:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031DF70. 0094:0098:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0094:0098:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0094:0098:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031DF70. 0094:0098:trace:module:load_dll looking for L"uxtheme.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\uxtheme.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"uxtheme.dll" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 0x2f7230000-0x2f7265000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .text at 0x2f7231000 off 1000 size 13000 virt 123c0 flags 60000060 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .data at 0x2f7244000 off 14000 size 1000 virt 110 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rodata at 0x2f7245000 off 15000 size 1000 virt 430 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rdata at 0x2f7246000 off 16000 size 16000 virt 15a30 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .pdata at 0x2f725c000 off 2c000 size 1000 virt 87c flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .xdata at 0x2f725d000 off 2d000 size 1000 virt 97c flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .bss at 0x2f725e000 off 0 size 0 virt 4a0 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .edata at 0x2f725f000 off 2e000 size 2000 virt 1de0 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .idata at 0x2f7261000 off 30000 size 2000 virt 14ac flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rsrc at 0x2f7263000 off 32000 size 1000 virt 5f8 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .reloc at 0x2f7264000 off 33000 size 1000 virt bc flags 42000040 0094:0098:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\uxtheme.dll" 0000000000440100 00000002F7230000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\uxtheme.dll" at 00000002F7230000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 00000002F7230000 0094:0098:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - START 0094:0098:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_ATTACH,0000000000000000) 00000002F72424B0 - CALL 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031DDA0, base 000000000031DD98. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:0098:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0094:0098:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - END 0094:0098:trace:module:LdrUnloadDll (00000002F7230000) 0094:0098:trace:module:LdrUnloadDll (L"uxtheme.dll") - START 0094:0098:trace:module:MODULE_DecRefCount (L"uxtheme.dll") ldr.LoadCount: 0 0094:0098:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_DETACH,0000000000000000) 00000002F72424B0 - CALL 0094:0098:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_DETACH,0000000000000000) - RETURN 1 0094:0098:trace:module:free_modref unloading L"C:\\windows\\system32\\uxtheme.dll" 0094:0098:trace:module:LdrUnloadDll END 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E010, base 000000000031E008. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:009c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0094:009c:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0094:009c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0094:009c:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0094:009c:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",THREAD_ATTACH,0000000000000000) 000000023D8C5690 - CALL 0094:009c:trace:module:MODULE_InitDLL (000000023D820000,THREAD_ATTACH,0000000000000000) - RETURN 1 0094:009c:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",THREAD_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 0094:009c:trace:module:MODULE_InitDLL (00000003AFD00000,THREAD_ATTACH,0000000000000000) - RETURN 1 0094:009c:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0094:009c:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0094:0098:trace:module:FindResourceExW 000000023D820000 #000e #7f05 0000 0094:0098:trace:module:LoadResource 000000023D820000 000000023D90A6C0 0094:0098:trace:module:FindResourceExW 000000023D820000 #0003 #003b 0000 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E8A0. 0094:0098:trace:module:LoadResource 000000023D820000 000000023D909520 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E4E0. 0094:009c:trace:module:EnumResourceNamesExW 0000000000000000 #000e 000000006DD1FB00 110e968 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000023D820000, 000000023D8C6780, 0000000000000000, 000000007B60C498, 000000023D902488, 0x00000000) 0094:0098:trace:module:load_dll looking for L"imm32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\imm32.dll" for L"imm32.dll" at 00000003AFD00000, count=2 0094:0098:trace:module:FindResourceExW 000000023D820000 #000e #7f05 0000 0094:0098:trace:module:LoadResource 000000023D820000 000000023D90A6C0 0094:0098:trace:module:FindResourceExW 000000023D820000 #0003 #003b 0000 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E7C0. 0094:0098:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0094:0098:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0094:0098:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E7C0. 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E1E0, base 000000000031E1D8. 0094:0098:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\user32.dll" -> 000000023D820000 (load path (null)) 0094:0098:trace:module:FindResourceExW 000000023D820000 #000e #7f05 0000 0094:0098:trace:module:LoadResource 000000023D820000 000000023D90A6C0 0094:0098:trace:module:FindResourceExW 000000023D820000 #0003 #003c 0000 0094:0098:trace:module:LoadResource 000000023D820000 000000023D909530 0094:0098:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031DC10. 0094:0098:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031E780. 0094:0098:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\explorer.exe" 0094:0098:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000445380, dll_characteristics 0000000000000000, name 000000000031E6E0, base 000000000031E678. 0094:0098:trace:module:LdrAddRefDll (L"explorer.exe") ldr.LoadCount: -1 0094:0098:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\explorer.exe" -> 0000000140000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 0094:0098:trace:module:FindResourceExW 0000000140000000 #0010 #0001 0000 0094:0098:trace:module:LdrUnloadDll (0000000140000000) 0094:0098:trace:module:LdrUnloadDll (L"explorer.exe") - START 0094:0098:trace:module:LdrUnloadDll END 0094:0098:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000446230, dll_characteristics 0000000000000000, name 000000000031E6B0, base 000000000031E648. 0094:0098:trace:module:LdrAddRefDll (L"explorer.exe") ldr.LoadCount: -1 0094:0098:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\explorer.exe" -> 0000000140000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 0094:0098:trace:module:FindResourceExW 0000000140000000 #0010 #0001 0000 0094:0098:trace:module:LoadResource 0000000140000000 000000014001D3C8 0094:0098:trace:module:LdrUnloadDll (0000000140000000) 0094:0098:trace:module:LdrUnloadDll (L"explorer.exe") - START 0094:0098:trace:module:LdrUnloadDll END 0094:0098:trace:module:FindResourceExW 0000000000000000 #0006 #0001 0000 0094:0098:trace:module:LoadResource 0000000000000000 000000014001D2A8 0094:0098:trace:module:load_dll looking for L"shell32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\shell32.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"shell32.dll" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" at 0x1c69e0000-0x1c72fe000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .text at 0x1c69e1000 off 1000 size 89000 virt 88c60 flags 60000060 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .data at 0x1c6a6a000 off 8a000 size 2000 virt 13e0 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rodata at 0x1c6a6c000 off 8c000 size 2000 virt 18ec flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rdata at 0x1c6a6e000 off 8e000 size 29000 virt 28e90 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .pdata at 0x1c6a97000 off b7000 size 6000 virt 5748 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .xdata at 0x1c6a9d000 off bd000 size 6000 virt 5c20 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .bss at 0x1c6aa3000 off 0 size 0 virt 570 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .edata at 0x1c6aa4000 off c3000 size 15000 virt 14070 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .idata at 0x1c6ab9000 off d8000 size 5000 virt 4aa0 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rsrc at 0x1c6abe000 off dd000 size 83e000 virt 83d918 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .reloc at 0x1c72fc000 off 91b000 size 2000 virt 1264 flags 42000040 0094:0098:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"shlwapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\shlwapi.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"shlwapi.dll" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" at 0x2e3540000-0x2e3591000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .text at 0x2e3541000 off 1000 size 1e000 virt 1dac0 flags 60000060 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .data at 0x2e355f000 off 1f000 size 1000 virt 210 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rodata at 0x2e3560000 off 20000 size 2000 virt 18fc flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rdata at 0x2e3562000 off 22000 size b000 virt a290 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .pdata at 0x2e356d000 off 2d000 size 2000 virt 11b8 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .xdata at 0x2e356f000 off 2f000 size 2000 virt 13a8 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .bss at 0x2e3571000 off 0 size 0 virt 1c0 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .edata at 0x2e3572000 off 31000 size 14000 virt 13ab5 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .idata at 0x2e3586000 off 45000 size 5000 virt 442c flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rsrc at 0x2e358b000 off 4a000 size 5000 virt 4ed0 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .reloc at 0x2e3590000 off 4f000 size 1000 virt e0 flags 42000040 0094:0098:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernelbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"shcore.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\shcore.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"shcore.dll" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" at 0x3126f0000-0x312709000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .text at 0x3126f1000 off 1000 size 9000 virt 8b70 flags 60000020 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .data at 0x3126fa000 off a000 size 1000 virt b0 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rodata at 0x3126fb000 off b000 size 1000 virt fb4 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rdata at 0x3126fc000 off c000 size 3000 virt 2360 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .pdata at 0x3126ff000 off f000 size 1000 virt 57c flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .xdata at 0x312700000 off 10000 size 1000 virt 61c flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .bss at 0x312701000 off 0 size 0 virt 160 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .edata at 0x312702000 off 11000 size 5000 virt 480e flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .idata at 0x312707000 off 16000 size 1000 virt c74 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .reloc at 0x312708000 off 17000 size 1000 virt a8 flags 42000040 0094:0098:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\ole32.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"ole32.dll" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" at 0x2e8f10000-0x2e902b000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .text at 0x2e8f11000 off 1000 size a8000 virt a76a0 flags 60000060 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .data at 0x2e8fb9000 off a9000 size 1000 virt 480 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rodata at 0x2e8fba000 off aa000 size 1000 virt 778 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rdata at 0x2e8fbb000 off ab000 size 1e000 virt 1d750 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .pdata at 0x2e8fd9000 off c9000 size 7000 virt 6b10 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .xdata at 0x2e8fe0000 off d0000 size 7000 virt 67c4 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .bss at 0x2e8fe7000 off 0 size 0 virt 210 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .edata at 0x2e8fe8000 off d7000 size 18000 virt 17412 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .idata at 0x2e9000000 off ef000 size 4000 virt 367c flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rsrc at 0x2e9004000 off f3000 size 25000 virt 24bc0 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .reloc at 0x2e9029000 off 118000 size 2000 virt 1804 flags 42000040 0094:0098:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"combase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\combase.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"combase.dll" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" at 0x327020000-0x327073000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .text at 0x327021000 off 1000 size 27000 virt 26590 flags 60000060 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .data at 0x327048000 off 28000 size 1000 virt 580 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rodata at 0x327049000 off 29000 size 2000 virt 16c0 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rdata at 0x32704b000 off 2b000 size d000 virt cf90 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .pdata at 0x327058000 off 38000 size 2000 virt 17a0 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .xdata at 0x32705a000 off 3a000 size 2000 virt 18e4 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .bss at 0x32705c000 off 0 size 0 virt 1a0 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .edata at 0x32705d000 off 3c000 size 13000 virt 12d6e flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .idata at 0x327070000 off 4f000 size 2000 virt 1804 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .reloc at 0x327072000 off 51000 size 1000 virt 23c flags 42000040 0094:0098:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"rpcrt4.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\combase.dll" 0000000000446D30 0000000327020000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\combase.dll" at 0000000327020000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\combase.dll" at 0000000327020000 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernelbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"rpcrt4.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ole32.dll" 0000000000446A50 00000002E8F10000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ole32.dll" at 00000002E8F10000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ole32.dll" at 00000002E8F10000 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shcore.dll" 0000000000446770 00000003126F0000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shcore.dll" at 00000003126F0000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shcore.dll" at 00000003126F0000 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shlwapi.dll" 0000000000446340 00000002E3540000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shlwapi.dll" at 00000002E3540000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shlwapi.dll" at 00000002E3540000 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shell32.dll" 00000000004457B0 00000001C69E0000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shell32.dll" at 00000001C69E0000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shell32.dll" at 00000001C69E0000 0094:0098:trace:module:process_attach (L"shell32.dll",0000000000000000) - START 0094:0098:trace:module:process_attach (L"shlwapi.dll",0000000000000000) - START 0094:0098:trace:module:process_attach (L"shcore.dll",0000000000000000) - START 0094:0098:trace:module:process_attach (L"ole32.dll",0000000000000000) - START 0094:0098:trace:module:process_attach (L"combase.dll",0000000000000000) - START 0094:0098:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_ATTACH,0000000000000000) 00000003270465C0 - CALL 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E1F0, base 000000000031E1E8. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:0098:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0094:0098:trace:module:process_attach (L"combase.dll",0000000000000000) - END 0094:0098:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_ATTACH,0000000000000000) 00000002E8FB74E0 - CALL 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E2A0, base 000000000031E298. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:0098:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0094:0098:trace:module:process_attach (L"ole32.dll",0000000000000000) - END 0094:0098:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_ATTACH,0000000000000000) 00000003126F8FD0 - CALL 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E330, base 000000000031E328. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:0098:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0094:0098:trace:module:process_attach (L"shcore.dll",0000000000000000) - END 0094:0098:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_ATTACH,0000000000000000) 00000002E355DE00 - CALL 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E3C0, base 000000000031E3B8. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:0098:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0094:0098:trace:module:process_attach (L"shlwapi.dll",0000000000000000) - END 0094:0098:trace:module:MODULE_InitDLL (00000001C69E0000 L"shell32.dll",PROCESS_ATTACH,0000000000000000) 00000001C6A688D0 - CALL 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E450, base 000000000031E448. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:0098:trace:module:LdrGetDllFullName module 00000001C69E0000, name 000000000031E970. 0094:0098:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\shell32.dll" 0094:0098:trace:module:MODULE_InitDLL (00000001C69E0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0094:0098:trace:module:process_attach (L"shell32.dll",0000000000000000) - END 0094:0098:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 000000014000F2F0, 0000000000000000, 000000007B60C498, 000000014001BA50, 0x00000000) 0094:0098:trace:module:load_dll looking for L"shell32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=2 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E8D0, base 000000000031E8C8. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:0098:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e64c,0x00000004,0x0) 0094:0098:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e64c,0x00000004,0x0) 0094:0098:trace:module:LdrResolveDelayLoadedAPI (00000001C69E0000, 00000001C6A69B20, 0000000000000000, 000000007B60C498, 00000001C6ABA818, 0x00000000) 0094:0098:trace:module:load_dll looking for L"ole32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 0094:0098:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 000000014000F330, 0000000000000000, 000000007B60C498, 000000014001B970, 0x00000000) 0094:0098:trace:module:load_dll looking for L"ole32.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=3 0094:0098:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 000000014000F330, 0000000000000000, 000000007B60C498, 000000014001B978, 0x00000000) 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EA30, base 000000000031EA28. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:0098:trace:module:load_dll looking for L"C:\\windows\\system32\\ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"C:\\windows\\system32\\ole32.dll" at 00000002E8F10000, count=4 0094:00a0:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0094:00a0:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0094:00a0:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0094:00a0:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0094:00a0:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",THREAD_ATTACH,0000000000000000) 000000023D8C5690 - CALL 0094:00a0:trace:module:MODULE_InitDLL (000000023D820000,THREAD_ATTACH,0000000000000000) - RETURN 1 0094:00a0:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",THREAD_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 0094:00a0:trace:module:MODULE_InitDLL (00000003AFD00000,THREAD_ATTACH,0000000000000000) - RETURN 1 0094:00a0:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0094:00a0:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0094:00a0:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",THREAD_ATTACH,0000000000000000) 00000003270465C0 - CALL 0094:00a0:trace:module:MODULE_InitDLL (0000000327020000,THREAD_ATTACH,0000000000000000) - RETURN 1 0094:00a0:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",THREAD_ATTACH,0000000000000000) 00000002E8FB74E0 - CALL 0094:00a0:trace:module:MODULE_InitDLL (00000002E8F10000,THREAD_ATTACH,0000000000000000) - RETURN 1 0094:0098:trace:module:load_dll looking for L"C:\\windows\\system32\\actxprxy.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\actxprxy.dll" 0094:0098:trace:module:get_load_order got hardcoded default for L"actxprxy.dll" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\actxprxy.dll" at 0x1d0830000-0x1d0980000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .text at 0x1d0831000 off 1000 size f6000 virt f5510 flags 60000020 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .data at 0x1d0927000 off f7000 size 1000 virt cd0 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .rodata at 0x1d0928000 off f8000 size 1000 virt 1c flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .rdata at 0x1d0929000 off f9000 size 1b000 virt 1a730 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .pdata at 0x1d0944000 off 114000 size 9000 virt 89a0 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .xdata at 0x1d094d000 off 11d000 size 8000 virt 78c4 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .bss at 0x1d0955000 off 0 size 0 virt 190 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .edata at 0x1d0956000 off 125000 size 1d000 virt 1c918 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .idata at 0x1d0973000 off 142000 size 2000 virt 1738 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .rsrc at 0x1d0975000 off 144000 size 8000 virt 7310 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .reloc at 0x1d097d000 off 14c000 size 3000 virt 2754 flags 42000040 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=5 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"oleaut32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:get_load_order looking for L"C:\\windows\\system32\\oleaut32.dll" 0094:0098:trace:module:get_load_order_value got environment b for L"oleaut32" 0094:0098:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" at 0x2739c0000-0x273af6000 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .text at 0x2739c1000 off 1000 size ab000 virt aa720 flags 60000060 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .data at 0x273a6c000 off ac000 size 2000 virt 1100 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rodata at 0x273a6e000 off ae000 size 1000 virt 984 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rdata at 0x273a6f000 off af000 size 1f000 virt 1e700 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .pdata at 0x273a8e000 off ce000 size 6000 virt 57e4 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .xdata at 0x273a94000 off d4000 size 6000 virt 50e4 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .bss at 0x273a9a000 off 0 size 0 virt 38230 flags c0000080 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .edata at 0x273ad3000 off da000 size 19000 virt 18c59 flags 40000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .idata at 0x273aec000 off f3000 size 3000 virt 2aa0 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rsrc at 0x273aef000 off f6000 size 5000 virt 4ee0 flags c0000040 0094:0098:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .reloc at 0x273af4000 off fb000 size 2000 virt 14e4 flags 42000040 0094:0098:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=6 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"rpcrt4.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\oleaut32.dll" 000000000044B1F0 00000002739C0000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\oleaut32.dll" at 00000002739C0000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\oleaut32.dll" at 00000002739C0000 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"rpcrt4.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0094:0098:trace:module:import_dll is not hybrid module 0094:0098:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\actxprxy.dll" 000000000044AE20 00000001D0830000 0094:0098:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\actxprxy.dll" at 00000001D0830000: builtin 0094:0098:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\actxprxy.dll" at 00000001D0830000 0094:0098:trace:module:process_attach (L"actxprxy.dll",0000000000000000) - START 0094:0098:trace:module:process_attach (L"oleaut32.dll",0000000000000000) - START 0094:0098:trace:module:MODULE_InitDLL (00000002739C0000 L"oleaut32.dll",PROCESS_ATTACH,0000000000000000) 0000000273A6A370 - CALL 0094:0098:trace:process:GetEnvironmentVariableW (L"oanocache" 0000000000000000 0) 0094:0098:trace:module:MODULE_InitDLL (00000002739C0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0094:0098:trace:module:process_attach (L"oleaut32.dll",0000000000000000) - END 0094:0098:trace:module:MODULE_InitDLL (00000001D0830000 L"actxprxy.dll",PROCESS_ATTACH,0000000000000000) 00000001D09254B0 - CALL 0094:0098:trace:module:MODULE_InitDLL (00000001D0830000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0094:0098:trace:module:process_attach (L"actxprxy.dll",0000000000000000) - END 0094:0098:trace:seh:dispatch_exception code=6ba flags=0 addr=000000007B01354E ip=000000007B01354E tid=0098 0094:0098:warn:seh:dispatch_exception unknown exception (code=6ba) raised 0094:0098:trace:seh:dispatch_exception rax=000000007b013500 rbx=000000000031e9c8 rcx=000000000031e6e0 rdx=0000000000000000 0094:0098:trace:seh:dispatch_exception rsi=000000000000006c rdi=000000000044b8f0 rbp=0000000140010028 rsp=000000000031e6c0 0094:0098:trace:seh:dispatch_exception r8=0000000000000000 r9=0000000000000000 r10=0000000000540000 r11=000000000044b888 0094:0098:trace:seh:dispatch_exception r12=000000000031e9c8 r13=0000000000448210 r14=000000000044b790 r15=0000000000000005 0094:0098:trace:seh:call_stack_handlers found wine frame 000000000031E8A0 rsp 000000000031EBA0 handler 0000000327044AC0 0094:0098:trace:seh:call_teb_handler calling TEB handler 0000000327044AC0 (rec=000000000031E6E0, frame=000000000031E8A0 context=000000000031DC10, dispatch=000000000031DAE0) 0094:0098:trace:seh:call_teb_handler handler at 0000000327044AC0 returned 1 0094:0098:trace:seh:call_stack_handlers found wine frame 000000000031EBE0 rsp 000000000031ED30 handler 0000000327046FF0 0094:0098:trace:seh:call_teb_handler calling TEB handler 0000000327046FF0 (rec=000000000031E6E0, frame=000000000031EBE0 context=000000000031DC10, dispatch=000000000031DAE0) 0094:0098:trace:seh:RtlRestoreContext returning to 0000000327046F8A stack 000000000031EBA0 0094:0098:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E3E0, base 000000000031E3D8. 0094:0098:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726624, 0x00000000) 0094:0098:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0094:0098:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=-1 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726704, 0x00000000) 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266EC, 0x00000000) 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726714, 0x00000000) 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266A4, 0x00000000) 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726684, 0x00000000) 0030:00a4:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:00a4:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:00a4:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:00a4:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:00a4:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:00a4:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266AC, 0x00000000) 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266BC, 0x00000000) 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72661C, 0x00000000) 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72667C, 0x00000000) 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266DC, 0x00000000) 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72660C, 0x00000000) 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72665C, 0x00000000) 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726614, 0x00000000) 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726664, 0x00000000) 0030:0050:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\rpcss.exe" 0000000000000000 0) 0030:0050:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\rpcss.exe" 000000000044FCC0 30) 0030:0050:trace:process:CreateProcessInternalW app (null) cmdline L"C:\\windows\\system32\\rpcss.exe" 0030:0050:trace:process:find_exe_file looking for L"C:\\windows\\system32\\rpcss.exe" in L"C:\\windows\\system32;.;C:\\windows\\system32;C:\\windows\\system;C:\\windows;" 0030:0050:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\rpcss.exe" image L"C:\\windows\\system32\\rpcss.exe" cmdline L"C:\\windows\\system32\\rpcss.exe" parent 0x0 0030:0050:trace:process:send_to_cx_loader loader (null) wineserversocket 17 stdin_fd -1 stdout_fd -1 unixdir (null) winedebug (null) wineloader (null) 0030:0050:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 00a8:00ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\rpcss.exe" 00a8:00ac:trace:module:get_load_order got hardcoded default for L"rpcss.exe" 00a8:00ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\rpcss.exe" 00a8:00ac:trace:module:get_load_order got hardcoded default for L"rpcss.exe" 00a8:00ac:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\rpcss.exe" at 0x140000000-0x140010000 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rpcss.exe" section .text at 0x140001000 off 1000 size 8000 virt 7450 flags 60000020 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rpcss.exe" section .data at 0x140009000 off 9000 size 1000 virt 410 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rpcss.exe" section .rdata at 0x14000a000 off a000 size 1000 virt f30 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rpcss.exe" section .pdata at 0x14000b000 off b000 size 1000 virt 4a4 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rpcss.exe" section .xdata at 0x14000c000 off c000 size 1000 virt 464 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rpcss.exe" section .bss at 0x14000d000 off 0 size 0 virt 160 flags c0000080 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rpcss.exe" section .idata at 0x14000e000 off d000 size 1000 virt b58 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rpcss.exe" section .reloc at 0x14000f000 off e000 size 1000 virt f0 flags 42000040 00a8:00ac:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 00a8:00ac:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0030:0050:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\rpcss.exe" pid 00a8 tid 00ac handles 0x114/0x118 0030:0050:trace:process:CreateProcessInternalW started process pid 00a8 tid 00ac 00a8:00ac:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 00a8:00ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rpcss.exe" 00000000004315D0 0000000140000000 00a8:00ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rpcss.exe" at 0000000140000000: builtin 00a8:00ac:trace:module:load_dll looking for L"kernel32.dll" in (null) 00a8:00ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernel32.dll" 00a8:00ac:trace:module:get_load_order got hardcoded default for L"kernel32.dll" 00a8:00ac:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 00a8:00ac:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00a8:00ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernelbase.dll" 00a8:00ac:trace:module:get_load_order got hardcoded default for L"kernelbase.dll" 00a8:00ac:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 00a8:00ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 0000000000431E40 000000007B000000 00a8:00ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 00a8:00ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000431B20 000000007B600000 00a8:00ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 00a8:00ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 00a8:00ac:trace:module:load_dll looking for L"advapi32.dll" in (null) 00a8:00ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\advapi32.dll" 00a8:00ac:trace:module:get_load_order got hardcoded default for L"advapi32.dll" 00a8:00ac:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 00a8:00ac:trace:module:load_dll looking for L"kernel32.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:load_dll looking for L"msvcrt.dll" in (null) 00a8:00ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvcrt.dll" 00a8:00ac:trace:module:get_load_order got hardcoded default for L"msvcrt.dll" 00a8:00ac:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 00a8:00ac:trace:module:load_dll looking for L"kernel32.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 00000000004322F0 00000001C8DB0000 00a8:00ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 00a8:00ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:load_dll looking for L"sechost.dll" in (null) 00a8:00ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\sechost.dll" 00a8:00ac:trace:module:get_load_order got hardcoded default for L"sechost.dll" 00a8:00ac:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 00a8:00ac:trace:module:load_dll looking for L"kernel32.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00a8:00ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\ucrtbase.dll" 00a8:00ac:trace:module:get_load_order got hardcoded default for L"ucrtbase.dll" 00a8:00ac:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 00a8:00ac:trace:module:load_dll looking for L"kernel32.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 0000000000432880 00000003AF670000 00a8:00ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 00a8:00ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 0000000000432590 000000032A700000 00a8:00ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 00a8:00ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 0000000000432010 0000000330260000 00a8:00ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 00a8:00ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:load_dll looking for L"kernel32.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 00a8:00ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\rpcrt4.dll" 00a8:00ac:trace:module:get_load_order_value got environment b for L"rpcrt4" 00a8:00ac:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0x231ae0000-0x231b62000 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .text at 0x231ae1000 off 1000 size 47000 virt 46400 flags 60000060 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .data at 0x231b28000 off 48000 size 1000 virt 710 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rodata at 0x231b29000 off 49000 size 2000 virt 1b44 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rdata at 0x231b2b000 off 4b000 size 15000 virt 14b90 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .pdata at 0x231b40000 off 60000 size 3000 virt 2334 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .xdata at 0x231b43000 off 63000 size 3000 virt 289c flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .bss at 0x231b46000 off 0 size 0 virt 690 flags c0000080 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .edata at 0x231b47000 off 66000 size 17000 virt 16730 flags 40000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .idata at 0x231b5e000 off 7d000 size 2000 virt 19a8 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rsrc at 0x231b60000 off 7f000 size 1000 virt 3a8 flags c0000040 00a8:00ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .reloc at 0x231b61000 off 80000 size 1000 virt 504 flags 42000040 00a8:00ac:trace:module:load_dll looking for L"advapi32.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:load_dll looking for L"kernel32.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rpcrt4.dll" 0000000000432A50 0000000231AE0000 00a8:00ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000: builtin 00a8:00ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 00a8:00ac:trace:module:import_dll is not hybrid module 00a8:00ac:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 00a8:00ac:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 00a8:00ac:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00a8:00ac:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 00a8:00ac:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 00a8:00ac:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 00a8:00ac:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 00a8:00ac:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 00a8:00ac:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 00a8:00ac:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00a8:00ac:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 00a8:00ac:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 00a8:00ac:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00a8:00ac:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 00a8:00ac:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 00a8:00ac:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 00a8:00ac:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 00a8:00ac:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F3B0. 00a8:00ac:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\rpcss.exe" 00a8:00ac:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F400. 00a8:00ac:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\rpcss.exe" 00a8:00ac:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 00a8:00ac:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00a8:00ac:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 00a8:00ac:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 00a8:00ac:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 00a8:00ac:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 00a8:00ac:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 00a8:00ac:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\rpcss.exe" 00a8:00ac:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 00a8:00ac:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\rpcss.exe" 00a8:00ac:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00a8:00ac:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 00a8:00ac:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 00a8:00ac:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00a8:00ac:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 00a8:00ac:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 00a8:00ac:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00a8:00ac:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 00a8:00ac:trace:module:process_attach (L"rpcrt4.dll",000000000031FB00) - START 00a8:00ac:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_ATTACH,000000000031FB00) 0000000231B26040 - CALL 00a8:00ac:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00a8:00ac:trace:module:process_attach (L"rpcrt4.dll",000000000031FB00) - END 00a8:00ac:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 00a8:00ac:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F7F0, base 000000000031F7E8. 00a8:00ac:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00a8:00ac:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726624, 0x00000000) 00a8:00ac:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 00a8:00ac:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=-1 00a8:00ac:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EEF0, base 000000000031EEE8. 00a8:00ac:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00a8:00ac:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726704, 0x00000000) 00a8:00ac:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F0F0, base 000000000031F0E8. 00a8:00ac:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00a8:00ac:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266EC, 0x00000000) 00a8:00ac:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726714, 0x00000000) 00a8:00ac:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266A4, 0x00000000) 00a8:00ac:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726684, 0x00000000) 0030:00b0:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:00b0:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:00b0:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:00b0:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:00b0:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:00b0:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00ac:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266AC, 0x00000000) 00a8:00ac:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266BC, 0x00000000) 00a8:00ac:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72661C, 0x00000000) 00a8:00ac:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72667C, 0x00000000) 00a8:00ac:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266DC, 0x00000000) 00a8:00b4:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 00a8:00b4:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00b4:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 00a8:00b4:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00b4:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 00a8:00b4:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00b4:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72660C, 0x00000000) 00a8:00b4:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72665C, 0x00000000) 00a8:00b4:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726614, 0x00000000) 00a8:00b4:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726664, 0x00000000) 00a8:00b8:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 00a8:00b8:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00b8:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 00a8:00b8:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00b8:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 00a8:00b8:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00b8:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 00000000011BF7C0, base 00000000011BF7B8. 00a8:00b8:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00a8:00bc:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 00a8:00bc:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00bc:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 00a8:00bc:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00bc:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 00a8:00bc:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00c0:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 00a8:00c0:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00c0:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 00a8:00c0:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00c0:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 00a8:00c0:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00b8:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266C4, 0x00000000) 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266D4, 0x00000000) 0094:0098:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726654, 0x00000000) 0030:00a4:trace:module:LdrShutdownThread () 0030:00a4:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_DETACH,0000000000000000) 0000000231B26040 - CALL 0030:00a4:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:00a4:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_DETACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:00a4:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:00a4:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_DETACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:00a4:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_DETACH,0000000000000000) - RETURN 1 00a8:00c4:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 00a8:00c4:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00c4:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 00a8:00c4:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00c4:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 00a8:00c4:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00c8:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 00a8:00c8:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00c8:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 00a8:00c8:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:00c8:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 00a8:00c8:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 008c:0090:trace:module:load_dll looking for L"winemac.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\winemac.drv" 008c:0090:trace:module:get_load_order got hardcoded default for L"winemac.drv" 008c:0090:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\winemac.drv" is a fake Wine dll 008c:0090:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"win32u.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AC60000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\winemac.drv" 000000000043B470 000000006DD10000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\winemac.drv" at 000000006DD10000: builtin 008c:0090:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\winemac.drv" at 000000006DD10000 008c:0090:trace:module:process_attach (L"winemac.drv",0000000000000000) - START 008c:0090:trace:module:MODULE_InitDLL (000000006DD10000 L"winemac.drv",PROCESS_ATTACH,0000000000000000) 000000006DD28C10 - CALL 008c:0090:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031BA60. 008c:0090:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\rundll32.exe" 008c:0090:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 008c:0090:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 008c:0090:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 008c:0090:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 008c:0090:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 008c:0090:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 008c:0090:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 008c:0090:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 008c:0090:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 008c:0090:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 008c:0090:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 008c:0090:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 008c:0090:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 008c:0090:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 008c:0090:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 008c:0090:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 008c:0090:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 008c:0090:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 008c:0090:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 008c:0090:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 008c:0090:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 008c:0090:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 008c:0090:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 008c:0090:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 008c:0090:trace:module:MODULE_InitDLL (000000006DD10000,PROCESS_ATTACH,0000000000000000) - RETURN 1 008c:0090:trace:module:process_attach (L"winemac.drv",0000000000000000) - END 008c:0090:trace:module:EnumResourceNamesExW 0000000000000000 #000e 000000006DD1FB00 31d2f8 008c:0090:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 008c:0090:trace:module:LoadResource 000000023D820000 000000023D90A4B0 008c:0090:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 008c:0090:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 008c:0090:trace:module:LoadResource 000000023D820000 000000023D908880 008c:0090:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C310, base 000000000031C308. 008c:0090:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 008c:0090:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C760. 008c:0090:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 008c:0090:trace:module:LoadResource 000000023D820000 000000023D90A4B0 008c:0090:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 008c:0090:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 008c:0090:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 008c:0090:trace:module:LoadResource 000000023D820000 000000023D90A4B0 008c:0090:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 008c:0090:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 008c:0090:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 008c:0090:trace:module:LoadResource 000000023D820000 000000023D90A4B0 008c:0090:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 008c:0090:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 008c:0090:trace:module:FindResourceExW 000000023D820000 #000c #7f01 0000 008c:0090:trace:module:LoadResource 000000023D820000 000000023D90A4C0 008c:0090:trace:module:FindResourceExW 000000023D820000 #0001 #0009 0000 008c:0090:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 008c:0090:trace:module:LoadResource 000000023D820000 000000023D9088E0 008c:0090:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C760. 008c:0090:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 008c:0090:trace:module:LoadResource 000000023D820000 000000023D90A4B0 008c:0090:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 008c:0090:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 008c:0090:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 008c:0090:trace:module:LoadResource 000000023D820000 000000023D90A4B0 008c:0090:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 008c:0090:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 008c:0090:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 008c:0090:trace:module:LoadResource 000000023D820000 000000023D90A4B0 008c:0090:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 008c:0090:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 008c:0090:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 008c:0090:trace:module:LoadResource 000000023D820000 000000023D90A4B0 008c:0090:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 008c:0090:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 008c:0090:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 008c:0090:trace:module:LoadResource 000000023D820000 000000023D90A4B0 008c:0090:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 008c:0090:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 008c:0090:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 008c:0090:trace:module:LoadResource 000000023D820000 000000023D90A4B0 008c:0090:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 008c:0090:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 008c:0090:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 008c:0090:trace:module:LoadResource 000000023D820000 000000023D90A4B0 008c:0090:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 008c:0090:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 008c:0090:trace:module:load_dll looking for L"uxtheme.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\uxtheme.dll" 008c:0090:trace:module:get_load_order got hardcoded default for L"uxtheme.dll" 008c:0090:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 0x2f7230000-0x2f7265000 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .text at 0x2f7231000 off 1000 size 13000 virt 123c0 flags 60000060 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .data at 0x2f7244000 off 14000 size 1000 virt 110 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rodata at 0x2f7245000 off 15000 size 1000 virt 430 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rdata at 0x2f7246000 off 16000 size 16000 virt 15a30 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .pdata at 0x2f725c000 off 2c000 size 1000 virt 87c flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .xdata at 0x2f725d000 off 2d000 size 1000 virt 97c flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .bss at 0x2f725e000 off 0 size 0 virt 4a0 flags c0000080 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .edata at 0x2f725f000 off 2e000 size 2000 virt 1de0 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .idata at 0x2f7261000 off 30000 size 2000 virt 14ac flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rsrc at 0x2f7263000 off 32000 size 1000 virt 5f8 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .reloc at 0x2f7264000 off 33000 size 1000 virt bc flags 42000040 008c:0090:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\uxtheme.dll" 000000000043B8E0 00000002F7230000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\uxtheme.dll" at 00000002F7230000: builtin 008c:0090:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 00000002F7230000 008c:0090:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - START 008c:0090:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_ATTACH,0000000000000000) 00000002F72424B0 - CALL 008c:0090:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C950, base 000000000031C948. 008c:0090:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 008c:0090:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_ATTACH,0000000000000000) - RETURN 1 008c:0090:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - END 008c:0090:trace:module:LdrUnloadDll (00000002F7230000) 008c:0090:trace:module:LdrUnloadDll (L"uxtheme.dll") - START 008c:0090:trace:module:MODULE_DecRefCount (L"uxtheme.dll") ldr.LoadCount: 0 008c:0090:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_DETACH,0000000000000000) 00000002F72424B0 - CALL 008c:0090:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_DETACH,0000000000000000) - RETURN 1 008c:0090:trace:module:free_modref unloading L"C:\\windows\\system32\\uxtheme.dll" 008c:0090:trace:module:LdrUnloadDll END 008c:0090:trace:module:load_dll looking for L"winemac.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\winemac.drv" for L"winemac.drv" at 000000006DD10000, count=2 008c:0090:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 008c:0090:trace:module:LoadResource 000000023D820000 000000023D90A4B0 008c:0090:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 008c:0090:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031F280. 008c:0090:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F240. 008c:0090:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\rundll32.exe" 008c:0090:trace:module:LdrGetDllHandleEx flags 0, load_path 000000000043B060, dll_characteristics 0000000000000000, name 000000000031F1A0, base 000000000031F138. 008c:0090:trace:module:LdrAddRefDll (L"rundll32.exe") ldr.LoadCount: -1 008c:0090:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\rundll32.exe" -> 0000000140000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 008c:0090:trace:module:FindResourceExW 0000000140000000 #0010 #0001 0000 008c:0090:trace:module:LdrUnloadDll (0000000140000000) 008c:0090:trace:module:LdrUnloadDll (L"rundll32.exe") - START 008c:0090:trace:module:LdrUnloadDll END 008c:0090:trace:module:FindResourceExW 000000023D820000 #0004 L"SYSMENU" 0000 008c:0090:trace:module:LoadResource 000000023D820000 000000023D909940 008c:0090:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EAA0, base 000000000031EA98. 008c:0090:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 008c:0090:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F630, base 000000000031F628. 008c:0090:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 008c:0090:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F320, base 000000000031F318. 008c:0090:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 008c:0090:trace:module:load_dll looking for L"setupapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\setupapi.dll" 008c:0090:trace:module:get_load_order got hardcoded default for L"setupapi.dll" 008c:0090:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" at 0x21a7e0000-0x21a856000 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .text at 0x21a7e1000 off 1000 size 37000 virt 365e0 flags 60000060 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .data at 0x21a818000 off 38000 size 1000 virt 230 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rodata at 0x21a819000 off 39000 size 3000 virt 244c flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rdata at 0x21a81c000 off 3c000 size e000 virt d010 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .pdata at 0x21a82a000 off 4a000 size 2000 virt 1818 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .xdata at 0x21a82c000 off 4c000 size 2000 virt 1d24 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .bss at 0x21a82e000 off 0 size 0 virt 720 flags c0000080 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .edata at 0x21a82f000 off 4e000 size 18000 virt 171c8 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .idata at 0x21a847000 off 66000 size 2000 virt 1f34 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rsrc at 0x21a849000 off 68000 size c000 virt bf00 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .reloc at 0x21a855000 off 74000 size 1000 virt d8 flags 42000040 008c:0090:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"kernelbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"rpcrt4.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\rpcrt4.dll" 008c:0090:trace:module:get_load_order_value got environment b for L"rpcrt4" 008c:0090:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0x231ae0000-0x231b62000 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .text at 0x231ae1000 off 1000 size 47000 virt 46400 flags 60000060 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .data at 0x231b28000 off 48000 size 1000 virt 710 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rodata at 0x231b29000 off 49000 size 2000 virt 1b44 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rdata at 0x231b2b000 off 4b000 size 15000 virt 14b90 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .pdata at 0x231b40000 off 60000 size 3000 virt 2334 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .xdata at 0x231b43000 off 63000 size 3000 virt 289c flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .bss at 0x231b46000 off 0 size 0 virt 690 flags c0000080 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .edata at 0x231b47000 off 66000 size 17000 virt 16730 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .idata at 0x231b5e000 off 7d000 size 2000 virt 19a8 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rsrc at 0x231b60000 off 7f000 size 1000 virt 3a8 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .reloc at 0x231b61000 off 80000 size 1000 virt 504 flags 42000040 008c:0090:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rpcrt4.dll" 000000000043F730 0000000231AE0000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000: builtin 008c:0090:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"version.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\version.dll" for L"version.dll" at 00000002F1FA0000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\setupapi.dll" 000000000043F010 000000021A7E0000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\setupapi.dll" at 000000021A7E0000: builtin 008c:0090:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\setupapi.dll" at 000000021A7E0000 008c:0090:trace:module:process_attach (L"setupapi.dll",0000000000000000) - START 008c:0090:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - START 008c:0090:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_ATTACH,0000000000000000) 0000000231B26040 - CALL 008c:0090:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 008c:0090:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - END 008c:0090:trace:module:MODULE_InitDLL (000000021A7E0000 L"setupapi.dll",PROCESS_ATTACH,0000000000000000) 000000021A816860 - CALL 008c:0090:trace:module:MODULE_InitDLL (000000021A7E0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 008c:0090:trace:module:process_attach (L"setupapi.dll",0000000000000000) - END 008c:0090:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F340, base 000000000031F338. 008c:0090:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 008c:0090:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F030, base 000000000031F028. 008c:0090:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 008c:0090:trace:module:EnumResourceNamesExW 0000000000F10001 #0018 000000021A7F88B0 31ccd0 008c:0090:trace:module:EnumResourceNamesExW 0000000000F10001 #0018 000000021A7F88B0 31ccd0 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000021A7E0000, 000000021A817560, 0000000000000000, 000000007B60C498, 000000021A847BB8, 0x00000000) 008c:0090:trace:module:load_dll looking for L"ole32.dll" in (null) 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\ole32.dll" 008c:0090:trace:module:get_load_order got hardcoded default for L"ole32.dll" 008c:0090:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" at 0x2e8f10000-0x2e902b000 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .text at 0x2e8f11000 off 1000 size a8000 virt a76a0 flags 60000060 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .data at 0x2e8fb9000 off a9000 size 1000 virt 480 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rodata at 0x2e8fba000 off aa000 size 1000 virt 778 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rdata at 0x2e8fbb000 off ab000 size 1e000 virt 1d750 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .pdata at 0x2e8fd9000 off c9000 size 7000 virt 6b10 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .xdata at 0x2e8fe0000 off d0000 size 7000 virt 67c4 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .bss at 0x2e8fe7000 off 0 size 0 virt 210 flags c0000080 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .edata at 0x2e8fe8000 off d7000 size 18000 virt 17412 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .idata at 0x2e9000000 off ef000 size 4000 virt 367c flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rsrc at 0x2e9004000 off f3000 size 25000 virt 24bc0 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .reloc at 0x2e9029000 off 118000 size 2000 virt 1804 flags 42000040 008c:0090:trace:module:load_dll looking for L"advapi32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"combase.dll" in (null) 008c:0090:trace:module:get_load_order looking for L"C:\\windows\\system32\\combase.dll" 008c:0090:trace:module:get_load_order got hardcoded default for L"combase.dll" 008c:0090:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" at 0x327020000-0x327073000 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .text at 0x327021000 off 1000 size 27000 virt 26590 flags 60000060 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .data at 0x327048000 off 28000 size 1000 virt 580 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rodata at 0x327049000 off 29000 size 2000 virt 16c0 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rdata at 0x32704b000 off 2b000 size d000 virt cf90 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .pdata at 0x327058000 off 38000 size 2000 virt 17a0 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .xdata at 0x32705a000 off 3a000 size 2000 virt 18e4 flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .bss at 0x32705c000 off 0 size 0 virt 1a0 flags c0000080 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .edata at 0x32705d000 off 3c000 size 13000 virt 12d6e flags 40000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .idata at 0x327070000 off 4f000 size 2000 virt 1804 flags c0000040 008c:0090:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .reloc at 0x327072000 off 51000 size 1000 virt 23c flags 42000040 008c:0090:trace:module:load_dll looking for L"advapi32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"gdi32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"kernel32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ole32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=2 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"user32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\combase.dll" 000000000045CB40 0000000327020000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\combase.dll" at 0000000327020000: builtin 008c:0090:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\combase.dll" at 0000000327020000 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"gdi32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"kernel32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"kernelbase.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ntdll.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=3 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:load_dll looking for L"user32.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 008c:0090:trace:module:import_dll is not hybrid module 008c:0090:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ole32.dll" 000000000045C9E0 00000002E8F10000 008c:0090:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ole32.dll" at 00000002E8F10000: builtin 008c:0090:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ole32.dll" at 00000002E8F10000 008c:0090:trace:module:process_attach (L"ole32.dll",0000000000000000) - START 008c:0090:trace:module:process_attach (L"combase.dll",0000000000000000) - START 008c:0090:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_ATTACH,0000000000000000) 00000003270465C0 - CALL 008c:0090:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E930, base 000000000031E928. 008c:0090:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 008c:0090:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_ATTACH,0000000000000000) - RETURN 1 008c:0090:trace:module:process_attach (L"combase.dll",0000000000000000) - END 008c:0090:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_ATTACH,0000000000000000) 00000002E8FB74E0 - CALL 008c:0090:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E9E0, base 000000000031E9D8. 008c:0090:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 008c:0090:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_ATTACH,0000000000000000) - RETURN 1 008c:0090:trace:module:process_attach (L"ole32.dll",0000000000000000) - END 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000021A7E0000, 000000021A817560, 0000000000000000, 000000007B60C498, 000000021A847BC0, 0x00000000) 008c:0090:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031AD00, base 000000000031ACF8. 008c:0090:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726624, 0x00000000) 008c:0090:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 008c:0090:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=4 008c:0090:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031A920, base 000000000031A918. 008c:0090:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726704, 0x00000000) 008c:0090:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031AB20, base 000000000031AB18. 008c:0090:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266EC, 0x00000000) 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726714, 0x00000000) 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266A4, 0x00000000) 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726684, 0x00000000) 0030:00cc:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:00cc:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:00cc:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:00cc:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:00cc:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:00cc:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266AC, 0x00000000) 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266BC, 0x00000000) 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72661C, 0x00000000) 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72667C, 0x00000000) 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266DC, 0x00000000) 008c:0090:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72660C, 0x00000000) 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72665C, 0x00000000) 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726614, 0x00000000) 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726664, 0x00000000) 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266B4, 0x00000000) 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72662C, 0x00000000) 008c:0090:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726634, 0x00000000) 0030:0040:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\mountmgr.sys" 0000000000000000 0) 0030:0040:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\mountmgr.sys" 0000000000454AB0 41) 0030:0040:trace:module:GetBinaryTypeW L"C:\\windows\\system32\\drivers\\mountmgr.sys" 0074:0080:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\mountmgr.sys" 0000000000000000 0) 0074:0080:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\mountmgr.sys" 00000000004460D0 41) 0074:0080:trace:module:load_dll looking for L"C:\\windows\\system32\\drivers\\mountmgr.sys" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:get_load_order looking for L"C:\\windows\\system32\\drivers\\mountmgr.sys" 0074:0080:trace:module:get_load_order got hardcoded default for L"C:\\windows\\system32\\drivers\\mountmgr.sys" 0074:0080:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\drivers\\mountmgr.sys" at 0x1fbac0000-0x1fbad2000 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\mountmgr.sys" section .text at 0x1fbac1000 off 1000 size 8000 virt 7770 flags 60000060 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\mountmgr.sys" section .data at 0x1fbac9000 off 9000 size 1000 virt 100 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\mountmgr.sys" section .rdata at 0x1fbaca000 off a000 size 2000 virt 1350 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\mountmgr.sys" section .pdata at 0x1fbacc000 off c000 size 1000 virt 360 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\mountmgr.sys" section .xdata at 0x1fbacd000 off d000 size 1000 virt 43c flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\mountmgr.sys" section .bss at 0x1fbace000 off 0 size 0 virt 190 flags c0000080 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\mountmgr.sys" section .edata at 0x1fbacf000 off e000 size 1000 virt 321 flags 40000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\mountmgr.sys" section .idata at 0x1fbad0000 off f000 size 1000 virt bd0 flags c0000040 0074:0080:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\mountmgr.sys" section .reloc at 0x1fbad1000 off 10000 size 1000 virt 48 flags 42000040 0074:0080:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ntoskrnl.exe" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ntoskrnl.exe" for L"ntoskrnl.exe" at 00000002279A0000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 0074:0080:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0074:0080:trace:module:import_dll is not hybrid module 0074:0080:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\drivers\\mountmgr.sys" 00000000004462D0 00000001FBAC0000 0074:0080:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\drivers\\mountmgr.sys" at 00000001FBAC0000: builtin 0074:0080:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\drivers\\mountmgr.sys" at 00000001FBAC0000 0074:0080:trace:module:process_attach (L"mountmgr.sys",0000000000000000) - START 0074:0080:trace:module:process_attach (L"mountmgr.sys",0000000000000000) - END 0074:0080:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCF810, base 0000000000FCF808. 0074:0080:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0080:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCF500, base 0000000000FCF4F8. 0074:0080:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:0080:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCD7A0, base 0000000000FCD798. 0074:0080:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0074:00d0:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0074:00d0:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0074:00d0:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0074:00d0:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0074:00d0:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0074:00d0:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0074:00d4:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0074:00d4:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0074:00d4:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0074:00d4:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0074:00d4:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0074:00d4:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:00cc:trace:module:LdrShutdownThread () 0030:00cc:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_DETACH,0000000000000000) 0000000231B26040 - CALL 0030:00cc:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:00cc:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_DETACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:00cc:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:00cc:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_DETACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:00cc:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_DETACH,0000000000000000) - RETURN 1 008c:0090:trace:module:LdrUnloadDll (000000021A7E0000) 008c:0090:trace:module:LdrUnloadDll (L"setupapi.dll") - START 008c:0090:trace:module:MODULE_DecRefCount (L"setupapi.dll") ldr.LoadCount: 0 008c:0090:trace:module:MODULE_DecRefCount (L"rpcrt4.dll") ldr.LoadCount: 3 008c:0090:trace:module:MODULE_InitDLL (000000021A7E0000 L"setupapi.dll",PROCESS_DETACH,0000000000000000) 000000021A816860 - CALL 008c:0090:trace:module:MODULE_InitDLL (000000021A7E0000,PROCESS_DETACH,0000000000000000) - RETURN 1 008c:0090:trace:module:free_modref unloading L"C:\\windows\\system32\\setupapi.dll" 008c:0090:trace:module:LdrUnloadDll END 008c:0090:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FD50, base 000000000031FD48. 008c:0090:trace:module:LdrGetDllHandleEx L"mscoree" -> 0000000000000000 (load path (null)) 008c:0090:trace:module:LdrShutdownProcess () 008c:0090:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_DETACH,0000000000000001) 00000002E8FB74E0 - CALL 008c:0090:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_DETACH,0000000000000001) - RETURN 1 008c:0090:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_DETACH,0000000000000001) 00000003270465C0 - CALL 008c:0090:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_DETACH,0000000000000001) - RETURN 1 008c:0090:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_DETACH,0000000000000001) 0000000231B26040 - CALL 008c:0090:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_DETACH,0000000000000001) - RETURN 1 008c:0090:trace:module:MODULE_InitDLL (000000006DD10000 L"winemac.drv",PROCESS_DETACH,0000000000000001) 000000006DD28C10 - CALL 008c:0090:trace:module:MODULE_InitDLL (000000006DD10000,PROCESS_DETACH,0000000000000001) - RETURN 1 008c:0090:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 008c:0090:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 008c:0090:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 008c:0090:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 008c:0090:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 008c:0090:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 008c:0090:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 008c:0090:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 008c:0090:trace:module:MODULE_InitDLL (000000006AC60000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006AD09460 - CALL 008c:0090:trace:module:MODULE_InitDLL (000000006AC60000,PROCESS_DETACH,0000000000000001) - RETURN 1 008c:0090:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 008c:0090:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 008c:0090:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 008c:0090:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 008c:0090:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 008c:0090:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 008c:0090:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 008c:0090:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 008c:0090:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 008c:0090:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 008c:0090:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 008c:0090:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 008c:0090:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 008c:0090:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:process:CreateProcessInternalW app L"C:\\windows\\system32\\rundll32.exe" cmdline L"C:\\windows\\system32\\rundll32.exe setupapi,InstallHinfSection DefaultInstall 128 \\\\?\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\wine.inf" 0028:002c:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\rundll32.exe" image L"C:\\windows\\system32\\rundll32.exe" cmdline L"C:\\windows\\system32\\rundll32.exe setupapi,InstallHinfSection DefaultInstall 128 \\\\?\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\wine.inf" parent 0x0 0028:002c:trace:process:send_to_cx_loader loader (null) wineserversocket 12 stdin_fd -1 stdout_fd -1 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 0028:002c:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\rundll32.exe" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"rundll32.exe" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\rundll32.exe" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"rundll32.exe" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\rundll32.exe" at 0x140000000-0x14000a000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rundll32.exe" section .text at 0x140001000 off 1000 size 2000 virt 1bb0 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rundll32.exe" section .data at 0x140003000 off 3000 size 1000 virt 40 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rundll32.exe" section .rdata at 0x140004000 off 4000 size 1000 virt 250 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rundll32.exe" section .pdata at 0x140005000 off 5000 size 1000 virt d8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rundll32.exe" section .xdata at 0x140006000 off 6000 size 1000 virt e8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rundll32.exe" section .bss at 0x140007000 off 0 size 0 virt 140 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rundll32.exe" section .idata at 0x140008000 off 7000 size 1000 virt 764 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rundll32.exe" section .reloc at 0x140009000 off 8000 size 1000 virt 14 flags 42000040 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 00d8:00dc:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0028:002c:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\rundll32.exe" pid 00d8 tid 00dc handles 0x94/0x98 0028:002c:trace:process:CreateProcessInternalW started process pid 00d8 tid 00dc 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rundll32.exe" 00000000004321F0 0000000140000000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rundll32.exe" at 0000000140000000: builtin 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernel32.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"kernel32.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernelbase.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"kernelbase.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 0000000000432A70 000000007B000000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000432750 000000007B600000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\ucrtbase.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"ucrtbase.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 0000000000432C40 00000003AF670000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in (null) 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\user32.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"user32.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in (null) 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\advapi32.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"advapi32.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"msvcrt.dll" in (null) 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvcrt.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"msvcrt.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 00000000004334A0 00000001C8DB0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"sechost.dll" in (null) 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\sechost.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"sechost.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 0000000000433600 000000032A700000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 0000000000433190 0000000330260000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in (null) 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\gdi32.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"gdi32.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"win32u.dll" in (null) 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\win32u.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"win32u.dll" 00d8:00dc:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\win32u.dll" is a fake Wine dll 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\win32u.dll" 0000000000433CE0 000000006AC60000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\win32u.dll" at 000000006AC60000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\win32u.dll" at 000000006AC60000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\gdi32.dll" 00000000004338B0 000000026B4C0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"sechost.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"version.dll" in (null) 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\version.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"version.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 0000000000434000 00000002F1FA0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 00000002F1FA0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 00000002F1FA0000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"win32u.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AC60000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\user32.dll" 0000000000432EE0 000000023D820000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\user32.dll" at 000000023D820000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\user32.dll" at 000000023D820000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 00d8:00dc:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00d8:00dc:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 00d8:00dc:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 00d8:00dc:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 00d8:00dc:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 00d8:00dc:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 00d8:00dc:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00d8:00dc:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 00d8:00dc:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00d8:00dc:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 00d8:00dc:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 00d8:00dc:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F440. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\rundll32.exe" 00d8:00dc:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F490. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\rundll32.exe" 00d8:00dc:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00d8:00dc:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 00d8:00dc:trace:module:process_attach (L"user32.dll",000000000031FB00) - START 00d8:00dc:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 00d8:00dc:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 00d8:00dc:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\rundll32.exe" 00d8:00dc:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\rundll32.exe" 00d8:00dc:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 00d8:00dc:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00d8:00dc:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 00d8:00dc:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 00d8:00dc:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00d8:00dc:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 00d8:00dc:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00d8:00dc:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 00d8:00dc:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - START 00d8:00dc:trace:module:process_attach (L"win32u.dll",000000000031FB00) - START 00d8:00dc:trace:module:MODULE_InitDLL (000000006AC60000 L"win32u.dll",PROCESS_ATTACH,000000000031FB00) 000000006AD09460 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000006AC60000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00d8:00dc:trace:module:process_attach (L"win32u.dll",000000000031FB00) - END 00d8:00dc:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000031FB00) 000000026B509F00 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00d8:00dc:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - END 00d8:00dc:trace:module:process_attach (L"version.dll",000000000031FB00) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000031FB00) 00000002F1FA2510 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00d8:00dc:trace:module:process_attach (L"version.dll",000000000031FB00) - END 00d8:00dc:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000031FB00) 000000023D8C5690 - CALL 00d8:00dc:trace:module:load_dll looking for L"imm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\imm32.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"imm32.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imm32.dll" 000000000043B280 00000003AFD00000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imm32.dll" at 00000003AFD00000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imm32.dll" at 00000003AFD00000 00d8:00dc:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EC40, base 000000000031EC38. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F0E0, base 000000000031F0D8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EBF0, base 000000000031EBE8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00d8:00dc:trace:module:process_attach (L"user32.dll",000000000031FB00) - END 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F620, base 000000000031F618. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:load_dll looking for L"winemac.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\winemac.drv" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"winemac.drv" 00d8:00dc:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\winemac.drv" is a fake Wine dll 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"win32u.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AC60000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\winemac.drv" 000000000043B4A0 000000006E5B0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\winemac.drv" at 000000006E5B0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\winemac.drv" at 000000006E5B0000 00d8:00dc:trace:module:process_attach (L"winemac.drv",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (000000006E5B0000 L"winemac.drv",PROCESS_ATTACH,0000000000000000) 000000006E5D3C10 - CALL 00d8:00dc:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031BA60. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\rundll32.exe" 00d8:00dc:trace:module:FindResourceExW 000000006E5B0000 #0006 #0011 0000 00d8:00dc:trace:module:LoadResource 000000006E5B0000 000000006E6399D8 00d8:00dc:trace:module:FindResourceExW 000000006E5B0000 #0006 #0011 0000 00d8:00dc:trace:module:LoadResource 000000006E5B0000 000000006E6399D8 00d8:00dc:trace:module:FindResourceExW 000000006E5B0000 #0006 #0011 0000 00d8:00dc:trace:module:LoadResource 000000006E5B0000 000000006E6399D8 00d8:00dc:trace:module:FindResourceExW 000000006E5B0000 #0006 #0011 0000 00d8:00dc:trace:module:LoadResource 000000006E5B0000 000000006E6399D8 00d8:00dc:trace:module:FindResourceExW 000000006E5B0000 #0006 #0011 0000 00d8:00dc:trace:module:LoadResource 000000006E5B0000 000000006E6399D8 00d8:00dc:trace:module:FindResourceExW 000000006E5B0000 #0006 #0011 0000 00d8:00dc:trace:module:LoadResource 000000006E5B0000 000000006E6399D8 00d8:00dc:trace:module:FindResourceExW 000000006E5B0000 #0006 #0011 0000 00d8:00dc:trace:module:LoadResource 000000006E5B0000 000000006E6399D8 00d8:00dc:trace:module:FindResourceExW 000000006E5B0000 #0006 #0012 0000 00d8:00dc:trace:module:LoadResource 000000006E5B0000 000000006E639BC8 00d8:00dc:trace:module:FindResourceExW 000000006E5B0000 #0006 #0012 0000 00d8:00dc:trace:module:LoadResource 000000006E5B0000 000000006E639BC8 00d8:00dc:trace:module:FindResourceExW 000000006E5B0000 #0006 #0012 0000 00d8:00dc:trace:module:LoadResource 000000006E5B0000 000000006E639BC8 00d8:00dc:trace:module:FindResourceExW 000000006E5B0000 #0006 #0012 0000 00d8:00dc:trace:module:LoadResource 000000006E5B0000 000000006E639BC8 00d8:00dc:trace:module:FindResourceExW 000000006E5B0000 #0006 #0012 0000 00d8:00dc:trace:module:LoadResource 000000006E5B0000 000000006E639BC8 00d8:00dc:trace:module:MODULE_InitDLL (000000006E5B0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"winemac.drv",0000000000000000) - END 00d8:00dc:trace:module:EnumResourceNamesExW 0000000000000000 #000e 000000006E5CAB00 31d2f8 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D908880 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C310, base 000000000031C308. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C760. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f01 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4C0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0009 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D9088E0 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C760. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 00d8:00dc:trace:module:load_dll looking for L"uxtheme.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\uxtheme.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"uxtheme.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 0x2f7230000-0x2f7265000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .text at 0x2f7231000 off 1000 size 13000 virt 123c0 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .data at 0x2f7244000 off 14000 size 1000 virt 110 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rodata at 0x2f7245000 off 15000 size 1000 virt 430 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rdata at 0x2f7246000 off 16000 size 16000 virt 15a30 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .pdata at 0x2f725c000 off 2c000 size 1000 virt 87c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .xdata at 0x2f725d000 off 2d000 size 1000 virt 97c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .bss at 0x2f725e000 off 0 size 0 virt 4a0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .edata at 0x2f725f000 off 2e000 size 2000 virt 1de0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .idata at 0x2f7261000 off 30000 size 2000 virt 14ac flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rsrc at 0x2f7263000 off 32000 size 1000 virt 5f8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .reloc at 0x2f7264000 off 33000 size 1000 virt bc flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\uxtheme.dll" 000000000043B910 00000002F7230000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\uxtheme.dll" at 00000002F7230000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 00000002F7230000 00d8:00dc:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_ATTACH,0000000000000000) 00000002F72424B0 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C950, base 000000000031C948. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - END 00d8:00dc:trace:module:LdrUnloadDll (00000002F7230000) 00d8:00dc:trace:module:LdrUnloadDll (L"uxtheme.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"uxtheme.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_DETACH,0000000000000000) 00000002F72424B0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\uxtheme.dll" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:load_dll looking for L"winemac.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\winemac.drv" for L"winemac.drv" at 000000006E5B0000, count=2 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031F280. 00d8:00dc:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F240. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\rundll32.exe" 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0, load_path 000000000043B090, dll_characteristics 0000000000000000, name 000000000031F1A0, base 000000000031F138. 00d8:00dc:trace:module:LdrAddRefDll (L"rundll32.exe") ldr.LoadCount: -1 00d8:00dc:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\rundll32.exe" -> 0000000140000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 00d8:00dc:trace:module:FindResourceExW 0000000140000000 #0010 #0001 0000 00d8:00dc:trace:module:LdrUnloadDll (0000000140000000) 00d8:00dc:trace:module:LdrUnloadDll (L"rundll32.exe") - START 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0004 L"SYSMENU" 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D909940 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EAA0, base 000000000031EA98. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F630, base 000000000031F628. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F320, base 000000000031F318. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:load_dll looking for L"setupapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\setupapi.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"setupapi.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" at 0x21a7e0000-0x21a856000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .text at 0x21a7e1000 off 1000 size 37000 virt 365e0 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .data at 0x21a818000 off 38000 size 1000 virt 230 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rodata at 0x21a819000 off 39000 size 3000 virt 244c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rdata at 0x21a81c000 off 3c000 size e000 virt d010 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .pdata at 0x21a82a000 off 4a000 size 2000 virt 1818 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .xdata at 0x21a82c000 off 4c000 size 2000 virt 1d24 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .bss at 0x21a82e000 off 0 size 0 virt 720 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .edata at 0x21a82f000 off 4e000 size 18000 virt 171c8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .idata at 0x21a847000 off 66000 size 2000 virt 1f34 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rsrc at 0x21a849000 off 68000 size c000 virt bf00 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .reloc at 0x21a855000 off 74000 size 1000 virt d8 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernelbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"rpcrt4.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\rpcrt4.dll" 00d8:00dc:trace:module:get_load_order_value got environment b for L"rpcrt4" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0x231ae0000-0x231b62000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .text at 0x231ae1000 off 1000 size 47000 virt 46400 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .data at 0x231b28000 off 48000 size 1000 virt 710 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rodata at 0x231b29000 off 49000 size 2000 virt 1b44 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rdata at 0x231b2b000 off 4b000 size 15000 virt 14b90 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .pdata at 0x231b40000 off 60000 size 3000 virt 2334 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .xdata at 0x231b43000 off 63000 size 3000 virt 289c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .bss at 0x231b46000 off 0 size 0 virt 690 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .edata at 0x231b47000 off 66000 size 17000 virt 16730 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .idata at 0x231b5e000 off 7d000 size 2000 virt 19a8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rsrc at 0x231b60000 off 7f000 size 1000 virt 3a8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .reloc at 0x231b61000 off 80000 size 1000 virt 504 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rpcrt4.dll" 000000000043F790 0000000231AE0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"version.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\version.dll" for L"version.dll" at 00000002F1FA0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\setupapi.dll" 000000000043F440 000000021A7E0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\setupapi.dll" at 000000021A7E0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\setupapi.dll" at 000000021A7E0000 00d8:00dc:trace:module:process_attach (L"setupapi.dll",0000000000000000) - START 00d8:00dc:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_ATTACH,0000000000000000) 0000000231B26040 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (000000021A7E0000 L"setupapi.dll",PROCESS_ATTACH,0000000000000000) 000000021A816860 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000021A7E0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"setupapi.dll",0000000000000000) - END 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F340, base 000000000031F338. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F030, base 000000000031F028. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000000F10001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000000F10001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000000F10001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:EnumResourceNamesExW 00000000010C0001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:EnumResourceNamesExW 00000000010C0001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:EnumResourceNamesExW 00000000010C0001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:EnumResourceNamesExW 00000000010C0001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:load_dll looking for L"atl100.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\atl100.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"atl100.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" at 0x1c1ef0000-0x1c1f1c000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .text at 0x1c1ef1000 off 1000 size c000 virt b530 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .data at 0x1c1efd000 off d000 size 1000 virt 90 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .rodata at 0x1c1efe000 off e000 size 1000 virt 1d0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .rdata at 0x1c1eff000 off f000 size 9000 virt 8890 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .pdata at 0x1c1f08000 off 18000 size 1000 virt 7d4 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .xdata at 0x1c1f09000 off 19000 size 1000 virt 7b4 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .bss at 0x1c1f0a000 off 0 size 0 virt 170 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .edata at 0x1c1f0b000 off 1a000 size d000 virt cf5d flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .idata at 0x1c1f18000 off 27000 size 1000 virt eb8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .rsrc at 0x1c1f19000 off 28000 size 2000 virt 1f90 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .reloc at 0x1c1f1b000 off 2a000 size 1000 virt 108 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\ole32.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"ole32.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" at 0x2e8f10000-0x2e902b000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .text at 0x2e8f11000 off 1000 size a8000 virt a76a0 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .data at 0x2e8fb9000 off a9000 size 1000 virt 480 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rodata at 0x2e8fba000 off aa000 size 1000 virt 778 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rdata at 0x2e8fbb000 off ab000 size 1e000 virt 1d750 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .pdata at 0x2e8fd9000 off c9000 size 7000 virt 6b10 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .xdata at 0x2e8fe0000 off d0000 size 7000 virt 67c4 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .bss at 0x2e8fe7000 off 0 size 0 virt 210 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .edata at 0x2e8fe8000 off d7000 size 18000 virt 17412 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .idata at 0x2e9000000 off ef000 size 4000 virt 367c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rsrc at 0x2e9004000 off f3000 size 25000 virt 24bc0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .reloc at 0x2e9029000 off 118000 size 2000 virt 1804 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"combase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\combase.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"combase.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" at 0x327020000-0x327073000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .text at 0x327021000 off 1000 size 27000 virt 26590 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .data at 0x327048000 off 28000 size 1000 virt 580 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rodata at 0x327049000 off 29000 size 2000 virt 16c0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rdata at 0x32704b000 off 2b000 size d000 virt cf90 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .pdata at 0x327058000 off 38000 size 2000 virt 17a0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .xdata at 0x32705a000 off 3a000 size 2000 virt 18e4 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .bss at 0x32705c000 off 0 size 0 virt 1a0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .edata at 0x32705d000 off 3c000 size 13000 virt 12d6e flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .idata at 0x327070000 off 4f000 size 2000 virt 1804 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .reloc at 0x327072000 off 51000 size 1000 virt 23c flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"rpcrt4.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\combase.dll" 0000000000459E70 0000000327020000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\combase.dll" at 0000000327020000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\combase.dll" at 0000000327020000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernelbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"rpcrt4.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ole32.dll" 000000000045CCA0 00000002E8F10000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ole32.dll" at 00000002E8F10000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ole32.dll" at 00000002E8F10000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"oleaut32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\oleaut32.dll" 00d8:00dc:trace:module:get_load_order_value got environment b for L"oleaut32" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" at 0x2739c0000-0x273af6000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .text at 0x2739c1000 off 1000 size ab000 virt aa720 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .data at 0x273a6c000 off ac000 size 2000 virt 1100 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rodata at 0x273a6e000 off ae000 size 1000 virt 984 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rdata at 0x273a6f000 off af000 size 1f000 virt 1e700 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .pdata at 0x273a8e000 off ce000 size 6000 virt 57e4 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .xdata at 0x273a94000 off d4000 size 6000 virt 50e4 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .bss at 0x273a9a000 off 0 size 0 virt 38230 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .edata at 0x273ad3000 off da000 size 19000 virt 18c59 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .idata at 0x273aec000 off f3000 size 3000 virt 2aa0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rsrc at 0x273aef000 off f6000 size 5000 virt 4ee0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .reloc at 0x273af4000 off fb000 size 2000 virt 14e4 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"rpcrt4.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=4 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\oleaut32.dll" 000000000045A320 00000002739C0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\oleaut32.dll" at 00000002739C0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\oleaut32.dll" at 00000002739C0000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"shlwapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\shlwapi.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"shlwapi.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" at 0x2e3540000-0x2e3591000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .text at 0x2e3541000 off 1000 size 1e000 virt 1dac0 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .data at 0x2e355f000 off 1f000 size 1000 virt 210 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rodata at 0x2e3560000 off 20000 size 2000 virt 18fc flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rdata at 0x2e3562000 off 22000 size b000 virt a290 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .pdata at 0x2e356d000 off 2d000 size 2000 virt 11b8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .xdata at 0x2e356f000 off 2f000 size 2000 virt 13a8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .bss at 0x2e3571000 off 0 size 0 virt 1c0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .edata at 0x2e3572000 off 31000 size 14000 virt 13ab5 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .idata at 0x2e3586000 off 45000 size 5000 virt 442c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rsrc at 0x2e358b000 off 4a000 size 5000 virt 4ed0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .reloc at 0x2e3590000 off 4f000 size 1000 virt e0 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernelbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"shcore.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\shcore.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"shcore.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" at 0x3126f0000-0x312709000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .text at 0x3126f1000 off 1000 size 9000 virt 8b70 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .data at 0x3126fa000 off a000 size 1000 virt b0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rodata at 0x3126fb000 off b000 size 1000 virt fb4 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rdata at 0x3126fc000 off c000 size 3000 virt 2360 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .pdata at 0x3126ff000 off f000 size 1000 virt 57c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .xdata at 0x312700000 off 10000 size 1000 virt 61c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .bss at 0x312701000 off 0 size 0 virt 160 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .edata at 0x312702000 off 11000 size 5000 virt 480e flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .idata at 0x312707000 off 16000 size 1000 virt c74 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .reloc at 0x312708000 off 17000 size 1000 virt a8 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shcore.dll" 000000000045AA90 00000003126F0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shcore.dll" at 00000003126F0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shcore.dll" at 00000003126F0000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shlwapi.dll" 000000000045A770 00000002E3540000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shlwapi.dll" at 00000002E3540000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shlwapi.dll" at 00000002E3540000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\atl100.dll" 000000000045CA00 00000001C1EF0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\atl100.dll" at 00000001C1EF0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\atl100.dll" at 00000001C1EF0000 00d8:00dc:trace:module:process_attach (L"atl100.dll",0000000000000000) - START 00d8:00dc:trace:module:process_attach (L"ole32.dll",0000000000000000) - START 00d8:00dc:trace:module:process_attach (L"combase.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_ATTACH,0000000000000000) 00000003270465C0 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C0E0, base 000000000031C0D8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"combase.dll",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_ATTACH,0000000000000000) 00000002E8FB74E0 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C190, base 000000000031C188. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"ole32.dll",0000000000000000) - END 00d8:00dc:trace:module:process_attach (L"oleaut32.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000002739C0000 L"oleaut32.dll",PROCESS_ATTACH,0000000000000000) 0000000273A6A370 - CALL 00d8:00dc:trace:process:GetEnvironmentVariableW (L"oanocache" 0000000000000000 0) 00d8:00dc:trace:module:MODULE_InitDLL (00000002739C0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"oleaut32.dll",0000000000000000) - END 00d8:00dc:trace:module:process_attach (L"shlwapi.dll",0000000000000000) - START 00d8:00dc:trace:module:process_attach (L"shcore.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_ATTACH,0000000000000000) 00000003126F8FD0 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C100, base 000000000031C0F8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"shcore.dll",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_ATTACH,0000000000000000) 00000002E355DE00 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C190, base 000000000031C188. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"shlwapi.dll",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (00000001C1EF0000 L"atl100.dll",PROCESS_ATTACH,0000000000000000) 00000001C1EFB6D0 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C220, base 000000000031C218. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (00000001C1EF0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"atl100.dll",0000000000000000) - END 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CE20 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31cca4 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/MSXML/MSXML_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013490B0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013490C0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CE20 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31cca4 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/MSXML2/MSXML2_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001349090 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 #0018 L"WINE_MANIFEST" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000153B198 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CE20 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31cca4 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/MSXML3/MSXML3_V1_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000153B158 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XMLPARSER_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000153B168 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 #0018 L"WINE_MANIFEST" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001349120 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CE20 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31cca4 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/MSXML4/MSXML4_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001349100 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 #0018 L"WINE_MANIFEST" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001349120 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CE20 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31cca4 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/MSXML6/MSXML6_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001349100 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CE20 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31cca4 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/SHDOCVW/SHDOCVW_V1_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013600C8 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CE20 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31cca4 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/SAPI/SAPI_TYPELIB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013680D0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"SAPI_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013680E0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013680F0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CE20 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31cca4 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/WBEMDISP/WBEMDISP_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135A0B0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"WBEMDISP_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135A0C0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CE20 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31cca4 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"WBEMPROX_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000137B048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CE20 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31cca4 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"WMIUTILS_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001350048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000021A7E0000, 000000021A817520, 0000000000000000, 000000007B60C498, 000000021A847BF8, 0x00000000) 00d8:00dc:trace:module:load_dll looking for L"shell32.dll" in (null) 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\shell32.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"shell32.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" at 0x1c69e0000-0x1c72fe000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .text at 0x1c69e1000 off 1000 size 89000 virt 88c60 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .data at 0x1c6a6a000 off 8a000 size 2000 virt 13e0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rodata at 0x1c6a6c000 off 8c000 size 2000 virt 18ec flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rdata at 0x1c6a6e000 off 8e000 size 29000 virt 28e90 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .pdata at 0x1c6a97000 off b7000 size 6000 virt 5748 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .xdata at 0x1c6a9d000 off bd000 size 6000 virt 5c20 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .bss at 0x1c6aa3000 off 0 size 0 virt 570 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .edata at 0x1c6aa4000 off c3000 size 15000 virt 14070 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .idata at 0x1c6ab9000 off d8000 size 5000 virt 4aa0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rsrc at 0x1c6abe000 off dd000 size 83e000 virt 83d918 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .reloc at 0x1c72fc000 off 91b000 size 2000 virt 1264 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"shlwapi.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shell32.dll" 000000000045ADF0 00000001C69E0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shell32.dll" at 00000001C69E0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shell32.dll" at 00000001C69E0000 00d8:00dc:trace:module:process_attach (L"shell32.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000001C69E0000 L"shell32.dll",PROCESS_ATTACH,0000000000000000) 00000001C6A688D0 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C430, base 000000000031C428. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllFullName module 00000001C69E0000, name 000000000031C950. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\shell32.dll" 00d8:00dc:trace:module:MODULE_InitDLL (00000001C69E0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"shell32.dll",0000000000000000) - END 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c9ac,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c9ac,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c9ac,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c9ac,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c9ac,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c9ac,0x00000004,0x0) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c9ac,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c9ac,0x00000004,0x0) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CE20 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31cca4 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/OLEDB32/OLEDB32_TYPELIB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136D810 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"OLEDB32_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136D820 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CE20 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31cca4 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MSDAPS_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000139C068 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ROW_SERVER_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000139C078 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CE20 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31cca4 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MSDASQL_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001364068 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0002 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001364078 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CE20 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31cca4 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/MSADO15/MSADO15_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013640B0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MSADO15_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013640C0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31ccd0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ACTIVEDS_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135E048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/ACTIVEDS.TLB/ACTIVEDS_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001341090 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ACTXPRXY_ACTIVSCP_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000014841C8 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ACTXPRXY_COMCAT_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000014841D8 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ACTXPRXY_DOCOBJ_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000014841E8 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ACTXPRXY_HLINK_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000014841F8 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ACTXPRXY_HTIFACE_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001484208 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ACTXPRXY_HTIFRAME_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001484218 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ACTXPRXY_MSHTML_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001484228 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ACTXPRXY_OBJSAFE_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001484238 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ACTXPRXY_OCMM_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001484248 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ACTXPRXY_SERVPROV_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001484258 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ACTXPRXY_SHLDISP_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001484268 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ACTXPRXY_SHOBJIDL_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001484278 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ACTXPRXY_URLHIST_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001484288 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ADSLDP_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001357068 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001357078 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"AMSTREAM_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001379080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ATL_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013690D0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ATL_LIB_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013690E0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/ATL/ATL_LIB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013690F0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ATL_LIB_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013680B0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/ATL100/ATL_LIB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013680C0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ATL_LIB_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013680B0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/ATL110/ATL_LIB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013680C0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:FindResourceExW 0000000001340001 #0018 L"WINE_MANIFEST" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001368108 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ATL_LIB_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013680E8 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/ATL80/ATL_LIB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013680F8 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:FindResourceExW 0000000001340001 #0018 L"WINE_MANIFEST" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001368108 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ATL_LIB_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013680E8 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/ATL90/ATL_LIB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013680F8 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"AVIFIL32_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001382628 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001382638 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"BROWSEUI_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001360368 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:FindResourceExW 0000000001340001 #0018 L"WINE_MANIFEST" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000142E700 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"COMDLG32_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013968C8 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"COMSVCS_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013600B0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/COMSVCS/COMSVCS_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013600C0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"D3DXOF_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001369080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DDRAW_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013B0080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DDRAWEX_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136A080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DEVENUM_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136C080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DHTMLED_TLB_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013640D0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/DHTMLED.OCX/DHTMLED_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013640E0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013640F0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DINPUT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001381458 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DINPUT8_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001381458 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DIRECTMANIP_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001360048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DISP_EX_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001365048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DMBAND_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001368080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DMCOMPOS_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001367080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DMIME_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000137C080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DMLOADER_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136D080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DMSCRIPT_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013670A0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013670B0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DMSTYLE_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001372080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DMSYNTH_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136A080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DMUSIC_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136F080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DPLAYX_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000137E080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DPNET_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013670A0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0002 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013670B0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DPVOICE_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135E080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DSDMO_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001366080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DSOUND_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001398080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DSQUERY_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135C048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000134C048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DSUIEXT_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135D048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DSWAVE_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001363080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DX8VB_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135F080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DXDIAGN_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136C1C0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"EVR_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001396048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"EXPLORERFRAME_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001361080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/GAMEUX/GAMEUX_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013640C8 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:FindResourceExW 0000000001340001 #0018 L"WINE_MANIFEST" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013C20B0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 #0018 L"WINE_MANIFEST11" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013C20C0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/HHCTRL.OCX/HHCTRL_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136D7E0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"HLINK_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001363048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/HNETCFG/HNETCFG_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135E100 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/HNETCFG/HNETCFG_TLB_T.RES\\2" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135E110 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"HNETCFG_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135E120 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/IEFRAME/IEFRAME_V1_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000139D860 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"IEFRAME_V1_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000139D870 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0002 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000139D880 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"IEPROXY_IEAUTOMATION_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135D068 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"IEPROXY_PERHIST_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135D078 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"INETCOMM_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000137B068 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000137B078 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"INFOSOFT_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135C048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"INSENG_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135D048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"ITSS_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001366068 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001366078 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/JSCRIPT/JSGLOBAL_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013CBF70 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"JSCRIPT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013CBF80 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0002 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013CBF90 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001414368 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MF_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013A8068 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013A8078 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MEDIAENGINE_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136E068 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MEDIAENGINE_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136E078 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MF_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136C048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MLANG_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001369068 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0002 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001369078 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/MMCNDMGR/MMCNDMGR_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135C090 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MMDEVAPI_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001368048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MP3DMOD_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001398048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MSCOREE_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001377048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MSCTF_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001373080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MSCTFP_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000139A048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MSHTML_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000015036B0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/MSHTML.TLB/MSHTML_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001341090 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/MSI/MSISERVER_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000143EE78 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MSISERVER_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000143EE88 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000143EE98 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MSIDENT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000134D048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MSIMTF_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135D048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/MSSCRIPT.OCX/MSSCRIPT_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135A0B0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0002 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135A0C0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"MSTASK_LOCAL_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001357048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:FindResourceExW 0000000001340001 #0018 L"WINE_MANIFEST" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013DC048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:FindResourceExW 0000000001340001 #0018 L"WINE_MANIFEST" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013DC048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"NETCFGX_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135D048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"NETPROFM_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001352048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"OBJSEL_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135C080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DCOM_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001433490 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"OLE32_OBJIDL_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000014334A0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"OLE32_OLEIDL_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000014334B0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"OLE32_UNKNWN_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000014334C0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/OLEACC/OLEACC_CLASSES_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136D870 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"OLEACC_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136D880 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"OLEAUT32_OAIDL_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001436230 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"OLEAUT32_OCIDL_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001436240 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001436250 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/OLEPRO32/OLEPRO_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013490C8 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"OPCSERVICES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135E048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"PACKAGER_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000134D068 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000134D078 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"PROPSYS_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001368048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/PSTOREC/PSTOREC_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000134E090 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"QASF_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001375080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"QCAP_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001381080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"QDVD_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136A080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"QEDIT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000137E080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001364048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"QMGRPRXY_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136A048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/QUARTZ/CONTROL_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001405108 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"QUARTZ_STRMIF_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001405118 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001405128 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/RICHED20/RICHED_TOM_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013A91D8 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136F080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/SCROBJ/SCROBJ_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001365090 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/SCRRUN/SCRRUN_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136E0E8 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136E0F8 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/SHELL32/SHELL32_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000142F0E0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"SHELL32_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000142F0F0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000142F100 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/STDOLE2.TLB/STDOLE2_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013410C8 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/STDOLE32.TLB/STD_OLE_V1_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013410C8 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"STI_WIA_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001365048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/TASKSCHD/TASKSCHD_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000136E090 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"UIANIMATION_REG_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135F090 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"UIRIBBON_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135C048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"URLMON_URLMON_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013CB328 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013CB338 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/VBSCRIPT/VBSGLOBAL_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013919B8 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/VBSCRIPT/VBSREGEXP10_T.RES\\2" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013919C8 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/VBSCRIPT/VBSREGEXP55_T.RES\\3" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013919D8 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"VBSCRIPT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013919E8 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0002 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013919F8 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"WIASERVC_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135E068 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135E078 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135C048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001360048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135D048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000134D048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000135B048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"WINDOWSCODECS_WINCODEC_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000014C5080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/WINHTTP/WINHTTP_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013810C8 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000134B048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/WMP/WMP_TYPELIB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013640E8 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0002 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013640F8 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"WMPHOTO_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013A5048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"WPC_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000134D048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/WSHOM.OCX/WSHOM_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013650B0 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 00000000013650C0 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"DLLS/WUAPI/WUAPI_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001362090 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001394048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001394048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001394048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001394048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001394048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001394048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001394048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001394048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001394048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001394048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001394048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XACT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001394048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000138C048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000138C048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000138C048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000138C048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000138C048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000138C048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000138C048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 000000000138C048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001390048 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CAB0 260) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 L"WINE_REGISTRY" 000000021A7F68A0 31c934 00d8:00dc:trace:module:FindResourceExW 0000000001340001 L"WINE_REGISTRY" L"XAUDIO_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000001340001 0000000001390080 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:EnumResourceNamesExW 0000000001340001 #0018 000000021A7F88B0 31c960 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000464390, dll_characteristics 0000000000000000, name 000000000031E7B0, base 000000000031E748. 00d8:00dc:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\mscms.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 00d8:00dc:trace:module:FindResourceExW 0000000000F10001 L"WINE_DATA_FILE" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000000F10001 0000000000F62080 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000464390, dll_characteristics 0000000000000000, name 000000000031E7B0, base 000000000031E748. 00d8:00dc:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\ws2_32.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 00d8:00dc:trace:module:FindResourceExW 0000000000F70001 L"WINE_DATA_FILE" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000000F70001 0000000000F910E0 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000464390, dll_characteristics 0000000000000000, name 000000000031E7B0, base 000000000031E748. 00d8:00dc:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\ws2_32.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 00d8:00dc:trace:module:FindResourceExW 00000000010C0001 L"WINE_DATA_FILE" #0002 0000 00d8:00dc:trace:module:LoadResource 00000000010C0001 00000000010E10F0 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000464390, dll_characteristics 0000000000000000, name 000000000031E7B0, base 000000000031E748. 00d8:00dc:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\ws2_32.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 00d8:00dc:trace:module:FindResourceExW 00000000010F0001 L"WINE_DATA_FILE" #0003 0000 00d8:00dc:trace:module:LoadResource 00000000010F0001 0000000001111100 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000464390, dll_characteristics 0000000000000000, name 000000000031E7B0, base 000000000031E748. 00d8:00dc:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\ws2_32.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 00d8:00dc:trace:module:FindResourceExW 0000000001120001 L"WINE_DATA_FILE" #0004 0000 00d8:00dc:trace:module:LoadResource 0000000001120001 0000000001141110 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000464410, dll_characteristics 0000000000000000, name 000000000031E7B0, base 000000000031E748. 00d8:00dc:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\drivers\\hidclass.sys" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 00d8:00dc:trace:module:FindResourceExW 0000000001150001 L"WINE_DATA_FILE" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001150001 0000000001161048 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000464410, dll_characteristics 0000000000000000, name 000000000031E7B0, base 000000000031E748. 00d8:00dc:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\drivers\\winebus.sys" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 00d8:00dc:trace:module:FindResourceExW 0000000001170001 L"WINE_DATA_FILE" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001170001 000000000117B048 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000464410, dll_characteristics 0000000000000000, name 000000000031E7B0, base 000000000031E748. 00d8:00dc:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\drivers\\winehid.sys" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 00d8:00dc:trace:module:FindResourceExW 0000000001180001 L"WINE_DATA_FILE" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001180001 0000000001188048 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000464410, dll_characteristics 0000000000000000, name 000000000031E7B0, base 000000000031E748. 00d8:00dc:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\drivers\\wineusb.sys" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 00d8:00dc:err:setupapi:SetupDefaultQueueCallbackW flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EA10, base 000000000031EA08. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) copy error 1812 L"@C:\\windows\\system32\\drivers\\wineusb.sys,-1" -> L"C:\\windows\\inf\\wineusb.inf" 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000464410, dll_characteristics 0000000000000000, name 000000000031E7B0, base 000000000031E748. 00d8:00dc:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\drivers\\winexinput.sys" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 00d8:00dc:trace:module:FindResourceExW 0000000001190001 L"WINE_DATA_FILE" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000001190001 000000000119A048 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000021A7E0000, 000000021A817560, 0000000000000000, 000000007B60C498, 000000021A847BB8, 0x00000000) 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=4 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\shell32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"C:\\windows\\system32\\shell32.dll" at 00000001C69E0000, count=2 00d8:00dc:trace:module:EnumResourceNamesExW 00000001C69E0000 L"WINE_REGISTRY" 00000001C6A69360 31d090 00d8:00dc:trace:module:FindResourceExW 00000001C69E0000 L"WINE_REGISTRY" L"DLLS/SHELL32/SHELL32_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 00000001C69E0000 00000001C6AD00E0 00d8:00dc:trace:module:load_dll looking for L"atl100.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\atl100.dll" for L"atl100.dll" at 00000001C1EF0000, count=2 00d8:00dc:trace:module:LdrGetDllFullName module 00000001C69E0000, name 000000000031C9C0. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\shell32.dll" 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CA20 260) 00d8:00dc:trace:module:FindResourceExW 00000001C69E0000 L"WINE_REGISTRY" L"SHELL32_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 00000001C69E0000 00000001C6AD00F0 00d8:00dc:trace:module:FindResourceExW 00000001C69E0000 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 00000001C69E0000 00000001C6AD0100 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031BDF0, base 000000000031BDE8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31b49c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31b49c,0x00000004,0x0) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (00000001C69E0000, 00000001C6A69B20, 0000000000000000, 000000007B60C498, 00000001C6ABA818, 0x00000000) 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=5 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (00000001C69E0000, 00000001C6A69B20, 0000000000000000, 000000007B60C498, 00000001C6ABA830, 0x00000000) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031B040, base 000000000031B038. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (00000001C69E0000, 00000001C6A69B20, 0000000000000000, 000000007B60C498, 00000001C6ABA820, 0x00000000) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (00000002E3540000, 00000002E355E990, 0000000000000000, 000000007B60C498, 00000002E3587A1C, 0x00000000) 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=6 00d8:00dc:trace:module:load_dll looking for L"shlwapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=3 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 0074:0084:trace:process:NtQueryInformationProcess (0x70,0x00000000,0x4507d8,0x00000030,0x0) 0074:0084:trace:process:NtQueryInformationProcess (0x70,0x0000001a,0x12cf258,0x00000008,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (00000001C69E0000, 00000001C6A69B20, 0000000000000000, 000000007B60C498, 00000001C6ABA890, 0x00000000) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c28c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c70c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c7ac,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c7ac,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c7ac,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c7ac,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c7ac,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c7ac,0x00000004,0x0) 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\quartz.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\quartz.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"quartz.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\quartz.dll" at 0x341d30000-0x341dff000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\quartz.dll" section .text at 0x341d31000 off 1000 size 71000 virt 70080 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\quartz.dll" section .data at 0x341da2000 off 72000 size 1000 virt 4d0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\quartz.dll" section .rodata at 0x341da3000 off 73000 size 1000 virt 48 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\quartz.dll" section .rdata at 0x341da4000 off 74000 size 2d000 virt 2c950 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\quartz.dll" section .pdata at 0x341dd1000 off a1000 size 6000 virt 50b8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\quartz.dll" section .xdata at 0x341dd7000 off a7000 size 5000 virt 4b0c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\quartz.dll" section .bss at 0x341ddc000 off 0 size 0 virt 230 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\quartz.dll" section .edata at 0x341ddd000 off ac000 size 16000 virt 15f65 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\quartz.dll" section .idata at 0x341df3000 off c2000 size 3000 virt 2478 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\quartz.dll" section .rsrc at 0x341df6000 off c5000 size 7000 virt 6f60 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\quartz.dll" section .reloc at 0x341dfd000 off cc000 size 2000 virt 1e90 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"dsound.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\dsound.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"dsound.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\dsound.dll" at 0x236df0000-0x236e4b000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dsound.dll" section .text at 0x236df1000 off 1000 size 1a000 virt 19e30 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dsound.dll" section .data at 0x236e0b000 off 1b000 size 1000 virt 610 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dsound.dll" section .rodata at 0x236e0c000 off 1c000 size 1000 virt 44 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dsound.dll" section .rdata at 0x236e0d000 off 1d000 size 1e000 virt 1d170 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dsound.dll" section .pdata at 0x236e2b000 off 3b000 size 1000 virt d2c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dsound.dll" section .xdata at 0x236e2c000 off 3c000 size 2000 virt 1044 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dsound.dll" section .bss at 0x236e2e000 off 0 size 0 virt 290 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dsound.dll" section .edata at 0x236e2f000 off 3e000 size 19000 virt 18f99 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dsound.dll" section .idata at 0x236e48000 off 57000 size 1000 virt b04 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dsound.dll" section .rsrc at 0x236e49000 off 58000 size 1000 virt 8d8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\dsound.dll" section .reloc at 0x236e4a000 off 59000 size 1000 virt 2a4 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=7 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\dsound.dll" 000000000045F010 0000000236DF0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\dsound.dll" at 0000000236DF0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\dsound.dll" at 0000000236DF0000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"msacm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\msacm32.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"msacm32.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\msacm32.dll" at 0x1c8b40000-0x1c8b60000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msacm32.dll" section .text at 0x1c8b41000 off 1000 size e000 virt d100 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msacm32.dll" section .data at 0x1c8b4f000 off f000 size 1000 virt d0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msacm32.dll" section .rodata at 0x1c8b50000 off 10000 size 1000 virt d8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msacm32.dll" section .rdata at 0x1c8b51000 off 11000 size 3000 virt 25d0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msacm32.dll" section .pdata at 0x1c8b54000 off 14000 size 1000 virt 6fc flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msacm32.dll" section .xdata at 0x1c8b55000 off 15000 size 1000 virt 82c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msacm32.dll" section .bss at 0x1c8b56000 off 0 size 0 virt 1a0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msacm32.dll" section .edata at 0x1c8b57000 off 16000 size 1000 virt d6e flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msacm32.dll" section .idata at 0x1c8b58000 off 17000 size 1000 virt aa8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msacm32.dll" section .rsrc at 0x1c8b59000 off 18000 size 6000 virt 5ba0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msacm32.dll" section .reloc at 0x1c8b5f000 off 1e000 size 1000 virt 88 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"winmm.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\winmm.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"winmm.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\winmm.dll" at 0x3b8f00000-0x3b8fc1000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winmm.dll" section .text at 0x3b8f01000 off 1000 size 22000 virt 21a40 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winmm.dll" section .data at 0x3b8f23000 off 23000 size 1000 virt 660 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winmm.dll" section .rodata at 0x3b8f24000 off 24000 size 1000 virt 344 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winmm.dll" section .rdata at 0x3b8f25000 off 25000 size 9000 virt 8da0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winmm.dll" section .pdata at 0x3b8f2e000 off 2e000 size 1000 virt fe4 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winmm.dll" section .xdata at 0x3b8f2f000 off 2f000 size 2000 virt 12ac flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winmm.dll" section .bss at 0x3b8f31000 off 0 size 0 virt ae20 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winmm.dll" section .edata at 0x3b8f3c000 off 31000 size 8000 virt 7682 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winmm.dll" section .idata at 0x3b8f44000 off 39000 size 2000 virt 14ac flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winmm.dll" section .rsrc at 0x3b8f46000 off 3b000 size 7a000 virt 79f10 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winmm.dll" section .reloc at 0x3b8fc0000 off b5000 size 1000 virt ac flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"msacm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\msacm32.dll" for L"msacm32.dll" at 00000001C8B40000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=8 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\winmm.dll" 000000000045E060 00000003B8F00000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\winmm.dll" at 00000003B8F00000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\winmm.dll" at 00000003B8F00000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msacm32.dll" 000000000045E9D0 00000001C8B40000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msacm32.dll" at 00000001C8B40000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msacm32.dll" at 00000001C8B40000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"msvfw32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvfw32.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"msvfw32.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\msvfw32.dll" at 0x39a620000-0x39a643000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msvfw32.dll" section .text at 0x39a621000 off 1000 size d000 virt cfb0 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msvfw32.dll" section .data at 0x39a62e000 off e000 size 1000 virt c0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msvfw32.dll" section .rodata at 0x39a62f000 off f000 size 1000 virt 100 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msvfw32.dll" section .rdata at 0x39a630000 off 10000 size 3000 virt 29f0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msvfw32.dll" section .pdata at 0x39a633000 off 13000 size 1000 virt 36c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msvfw32.dll" section .xdata at 0x39a634000 off 14000 size 1000 virt 408 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msvfw32.dll" section .bss at 0x39a635000 off 0 size 0 virt 160 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msvfw32.dll" section .edata at 0x39a636000 off 15000 size 1000 virt a5a flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msvfw32.dll" section .idata at 0x39a637000 off 16000 size 2000 virt 1078 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msvfw32.dll" section .rsrc at 0x39a639000 off 18000 size 9000 virt 83a0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msvfw32.dll" section .reloc at 0x39a642000 off 21000 size 1000 virt 28 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"comctl32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\comctl32.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"comctl32.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\comctl32.dll" at 0x2bb750000-0x2bb88f000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .text at 0x2bb751000 off 1000 size ae000 virt ad9d0 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .data at 0x2bb7ff000 off af000 size 1000 virt 300 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .rodata at 0x2bb800000 off b0000 size 1000 virt 734 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .rdata at 0x2bb801000 off b1000 size 1f000 virt 1ef80 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .pdata at 0x2bb820000 off d0000 size 4000 virt 3198 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .xdata at 0x2bb824000 off d4000 size 5000 virt 40a8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .bss at 0x2bb829000 off 0 size 0 virt 1720 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .edata at 0x2bb82b000 off d9000 size f000 virt eff3 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .idata at 0x2bb83a000 off e8000 size 4000 virt 3b2c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .rsrc at 0x2bb83e000 off ec000 size 50000 virt 4fad8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .reloc at 0x2bb88e000 off 13c000 size 1000 virt 1d4 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"imm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\imm32.dll" for L"imm32.dll" at 00000003AFD00000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernelbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\comctl32.dll" 000000000045F530 00000002BB750000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\comctl32.dll" at 00000002BB750000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\comctl32.dll" at 00000002BB750000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"winmm.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\winmm.dll" for L"winmm.dll" at 00000003B8F00000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvfw32.dll" 000000000045F280 000000039A620000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvfw32.dll" at 000000039A620000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvfw32.dll" at 000000039A620000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=9 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"oleaut32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\oleaut32.dll" for L"oleaut32.dll" at 00000002739C0000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"rpcrt4.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=5 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\quartz.dll" 000000000045EDE0 0000000341D30000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\quartz.dll" at 0000000341D30000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\quartz.dll" at 0000000341D30000 00d8:00dc:trace:module:process_attach (L"quartz.dll",0000000000000000) - START 00d8:00dc:trace:module:process_attach (L"dsound.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (0000000236DF0000 L"dsound.dll",PROCESS_ATTACH,0000000000000000) 0000000236E09F90 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C630, base 000000000031C628. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrAddRefDll (L"dsound.dll") ldr.LoadCount: 2 00d8:00dc:trace:module:MODULE_InitDLL (0000000236DF0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"dsound.dll",0000000000000000) - END 00d8:00dc:trace:module:process_attach (L"msacm32.dll",0000000000000000) - START 00d8:00dc:trace:module:process_attach (L"winmm.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000003B8F00000 L"winmm.dll",PROCESS_ATTACH,0000000000000000) 00000003B8F219F0 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C590, base 000000000031C588. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (00000003B8F00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"winmm.dll",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (00000001C8B40000 L"msacm32.dll",PROCESS_ATTACH,0000000000000000) 00000001C8B4D580 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C630, base 000000000031C628. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031B4F0, base 000000000031B4E8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031A8B0, base 000000000031A8A8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:load_dll looking for L"msacm.imaadpcm" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:warn:module:load_dll Failed to load module L"msacm.imaadpcm"; status=c0000135 00d8:00dc:trace:module:load_dll looking for L"imaadp32.acm" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\imaadp32.acm" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"imaadp32.acm" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\imaadp32.acm" at 0x39e730000-0x39e73d000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\imaadp32.acm" section .text at 0x39e731000 off 1000 size 3000 virt 27c0 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\imaadp32.acm" section .data at 0x39e734000 off 4000 size 1000 virt 70 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\imaadp32.acm" section .rodata at 0x39e735000 off 5000 size 1000 virt c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\imaadp32.acm" section .rdata at 0x39e736000 off 6000 size 1000 virt 820 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\imaadp32.acm" section .pdata at 0x39e737000 off 7000 size 1000 virt fc flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\imaadp32.acm" section .xdata at 0x39e738000 off 8000 size 1000 virt 128 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\imaadp32.acm" section .bss at 0x39e739000 off 0 size 0 virt 140 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\imaadp32.acm" section .edata at 0x39e73a000 off 9000 size 1000 virt 11f flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\imaadp32.acm" section .idata at 0x39e73b000 off a000 size 1000 virt 45c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\imaadp32.acm" section .reloc at 0x39e73c000 off b000 size 1000 virt 20 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"winmm.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\winmm.dll" for L"winmm.dll" at 00000003B8F00000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imaadp32.acm" 000000000045FC60 000000039E730000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imaadp32.acm" at 000000039E730000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imaadp32.acm" at 000000039E730000 00d8:00dc:trace:module:process_attach (L"imaadp32.acm",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (000000039E730000 L"imaadp32.acm",PROCESS_ATTACH,0000000000000000) 000000039E732D30 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000039E730000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"imaadp32.acm",0000000000000000) - END 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031A3D0, base 000000000031A3C8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:load_dll looking for L"imaadp32.acm" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\imaadp32.acm" for L"imaadp32.acm" at 000000039E730000, count=2 00d8:00dc:trace:module:LdrUnloadDll (000000039E730000) 00d8:00dc:trace:module:LdrUnloadDll (L"imaadp32.acm") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"imaadp32.acm") ldr.LoadCount: 1 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (000000039E730000) 00d8:00dc:trace:module:LdrUnloadDll (L"imaadp32.acm") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"imaadp32.acm") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"winmm.dll") ldr.LoadCount: 2 00d8:00dc:trace:module:MODULE_InitDLL (000000039E730000 L"imaadp32.acm",PROCESS_DETACH,0000000000000000) 000000039E732D30 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000039E730000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\imaadp32.acm" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:load_dll looking for L"msacm.msadpcm" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:warn:module:load_dll Failed to load module L"msacm.msadpcm"; status=c0000135 00d8:00dc:trace:module:load_dll looking for L"msadp32.acm" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\msadp32.acm" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"msadp32.acm" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\msadp32.acm" at 0x2bae80000-0x2bae8d000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msadp32.acm" section .text at 0x2bae81000 off 1000 size 3000 virt 2270 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msadp32.acm" section .data at 0x2bae84000 off 4000 size 1000 virt 70 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msadp32.acm" section .rodata at 0x2bae85000 off 5000 size 1000 virt c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msadp32.acm" section .rdata at 0x2bae86000 off 6000 size 1000 virt 6e0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msadp32.acm" section .pdata at 0x2bae87000 off 7000 size 1000 virt e4 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msadp32.acm" section .xdata at 0x2bae88000 off 8000 size 1000 virt f8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msadp32.acm" section .bss at 0x2bae89000 off 0 size 0 virt 140 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msadp32.acm" section .edata at 0x2bae8a000 off 9000 size 1000 virt 11e flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msadp32.acm" section .idata at 0x2bae8b000 off a000 size 1000 virt 45c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msadp32.acm" section .reloc at 0x2bae8c000 off b000 size 1000 virt 20 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"winmm.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\winmm.dll" for L"winmm.dll" at 00000003B8F00000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msadp32.acm" 000000000045FC50 00000002BAE80000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msadp32.acm" at 00000002BAE80000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msadp32.acm" at 00000002BAE80000 00d8:00dc:trace:module:process_attach (L"msadp32.acm",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000002BAE80000 L"msadp32.acm",PROCESS_ATTACH,0000000000000000) 00000002BAE827E0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000002BAE80000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"msadp32.acm",0000000000000000) - END 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031A3D0, base 000000000031A3C8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:load_dll looking for L"msadp32.acm" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\msadp32.acm" for L"msadp32.acm" at 00000002BAE80000, count=2 00d8:00dc:trace:module:LdrUnloadDll (00000002BAE80000) 00d8:00dc:trace:module:LdrUnloadDll (L"msadp32.acm") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"msadp32.acm") ldr.LoadCount: 1 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (00000002BAE80000) 00d8:00dc:trace:module:LdrUnloadDll (L"msadp32.acm") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"msadp32.acm") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"winmm.dll") ldr.LoadCount: 2 00d8:00dc:trace:module:MODULE_InitDLL (00000002BAE80000 L"msadp32.acm",PROCESS_DETACH,0000000000000000) 00000002BAE827E0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000002BAE80000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\msadp32.acm" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:load_dll looking for L"msacm.msg711" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:warn:module:load_dll Failed to load module L"msacm.msg711"; status=c0000135 00d8:00dc:trace:module:load_dll looking for L"msg711.acm" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\msg711.acm" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"msg711.acm" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\msg711.acm" at 0x3a52a0000-0x3a52ac000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msg711.acm" section .text at 0x3a52a1000 off 1000 size 2000 virt 1b40 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msg711.acm" section .data at 0x3a52a3000 off 3000 size 1000 virt 70 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msg711.acm" section .rodata at 0x3a52a4000 off 4000 size 1000 virt c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msg711.acm" section .rdata at 0x3a52a5000 off 5000 size 1000 virt ae0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msg711.acm" section .pdata at 0x3a52a6000 off 6000 size 1000 virt 108 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msg711.acm" section .xdata at 0x3a52a7000 off 7000 size 1000 virt e0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msg711.acm" section .bss at 0x3a52a8000 off 0 size 0 virt 140 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msg711.acm" section .edata at 0x3a52a9000 off 8000 size 1000 virt 11c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msg711.acm" section .idata at 0x3a52aa000 off 9000 size 1000 virt 45c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msg711.acm" section .reloc at 0x3a52ab000 off a000 size 1000 virt 20 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"winmm.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\winmm.dll" for L"winmm.dll" at 00000003B8F00000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msg711.acm" 000000000045FC50 00000003A52A0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msg711.acm" at 00000003A52A0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msg711.acm" at 00000003A52A0000 00d8:00dc:trace:module:process_attach (L"msg711.acm",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000003A52A0000 L"msg711.acm",PROCESS_ATTACH,0000000000000000) 00000003A52A20B0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000003A52A0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"msg711.acm",0000000000000000) - END 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031A3D0, base 000000000031A3C8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:load_dll looking for L"msg711.acm" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\msg711.acm" for L"msg711.acm" at 00000003A52A0000, count=2 00d8:00dc:trace:module:LdrUnloadDll (00000003A52A0000) 00d8:00dc:trace:module:LdrUnloadDll (L"msg711.acm") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"msg711.acm") ldr.LoadCount: 1 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (00000003A52A0000) 00d8:00dc:trace:module:LdrUnloadDll (L"msg711.acm") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"msg711.acm") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"winmm.dll") ldr.LoadCount: 2 00d8:00dc:trace:module:MODULE_InitDLL (00000003A52A0000 L"msg711.acm",PROCESS_DETACH,0000000000000000) 00000003A52A20B0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000003A52A0000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\msg711.acm" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:load_dll looking for L"msacm.l3acm" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:warn:module:load_dll Failed to load module L"msacm.l3acm"; status=c0000135 00d8:00dc:trace:module:load_dll looking for L"l3codeca.acm" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\l3codeca.acm" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"l3codeca.acm" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\l3codeca.acm" at 0x2fb4e0000-0x2fb527000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\l3codeca.acm" section .text at 0x2fb4e1000 off 1000 size 22000 virt 215a0 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\l3codeca.acm" section .data at 0x2fb503000 off 23000 size 1000 virt 750 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\l3codeca.acm" section .rodata at 0x2fb504000 off 24000 size 1000 virt c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\l3codeca.acm" section .rdata at 0x2fb505000 off 25000 size 18000 virt 174a0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\l3codeca.acm" section .pdata at 0x2fb51d000 off 3d000 size 2000 virt 11d0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\l3codeca.acm" section .xdata at 0x2fb51f000 off 3f000 size 2000 virt 112c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\l3codeca.acm" section .bss at 0x2fb521000 off 0 size 0 virt 140 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\l3codeca.acm" section .edata at 0x2fb522000 off 41000 size 3000 virt 21c0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\l3codeca.acm" section .idata at 0x2fb525000 off 44000 size 1000 virt 95c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\l3codeca.acm" section .reloc at 0x2fb526000 off 45000 size 1000 virt 33c flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernelbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"winmm.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\winmm.dll" for L"winmm.dll" at 00000003B8F00000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\l3codeca.acm" 000000000045FC60 00000002FB4E0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\l3codeca.acm" at 00000002FB4E0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\l3codeca.acm" at 00000002FB4E0000 00d8:00dc:trace:module:process_attach (L"l3codeca.acm",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000002FB4E0000 L"l3codeca.acm",PROCESS_ATTACH,0000000000000000) 00000002FB501A00 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000002FB4E0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"l3codeca.acm",0000000000000000) - END 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031A390, base 000000000031A388. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:load_dll looking for L"l3codeca.acm" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\l3codeca.acm" for L"l3codeca.acm" at 00000002FB4E0000, count=2 00d8:00dc:trace:module:LdrUnloadDll (00000002FB4E0000) 00d8:00dc:trace:module:LdrUnloadDll (L"l3codeca.acm") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"l3codeca.acm") ldr.LoadCount: 1 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (00000002FB4E0000) 00d8:00dc:trace:module:LdrUnloadDll (L"l3codeca.acm") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"l3codeca.acm") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"winmm.dll") ldr.LoadCount: 2 00d8:00dc:trace:module:MODULE_InitDLL (00000002FB4E0000 L"l3codeca.acm",PROCESS_DETACH,0000000000000000) 00000002FB501A00 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000002FB4E0000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\l3codeca.acm" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:load_dll looking for L"msacm.msgsm610" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:warn:module:load_dll Failed to load module L"msacm.msgsm610"; status=c0000135 00d8:00dc:trace:module:load_dll looking for L"msgsm32.acm" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\msgsm32.acm" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"msgsm32.acm" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\msgsm32.acm" at 0x29ea10000-0x29ea22000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msgsm32.acm" section .text at 0x29ea11000 off 1000 size 8000 virt 7ec0 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msgsm32.acm" section .data at 0x29ea19000 off 9000 size 1000 virt 110 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msgsm32.acm" section .rodata at 0x29ea1a000 off a000 size 1000 virt c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msgsm32.acm" section .rdata at 0x29ea1b000 off b000 size 1000 virt b80 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msgsm32.acm" section .pdata at 0x29ea1c000 off c000 size 1000 virt 294 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msgsm32.acm" section .xdata at 0x29ea1d000 off d000 size 1000 virt 288 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msgsm32.acm" section .bss at 0x29ea1e000 off 0 size 0 virt 140 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msgsm32.acm" section .edata at 0x29ea1f000 off e000 size 1000 virt 478 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msgsm32.acm" section .idata at 0x29ea20000 off f000 size 1000 virt 498 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msgsm32.acm" section .reloc at 0x29ea21000 off 10000 size 1000 virt 28 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"winmm.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\winmm.dll" for L"winmm.dll" at 00000003B8F00000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msgsm32.acm" 000000000045FC50 000000029EA10000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msgsm32.acm" at 000000029EA10000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msgsm32.acm" at 000000029EA10000 00d8:00dc:trace:module:process_attach (L"msgsm32.acm",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (000000029EA10000 L"msgsm32.acm",PROCESS_ATTACH,0000000000000000) 000000029EA18410 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000029EA10000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"msgsm32.acm",0000000000000000) - END 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031A3D0, base 000000000031A3C8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:load_dll looking for L"msgsm32.acm" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\msgsm32.acm" for L"msgsm32.acm" at 000000029EA10000, count=2 00d8:00dc:trace:module:LdrUnloadDll (000000029EA10000) 00d8:00dc:trace:module:LdrUnloadDll (L"msgsm32.acm") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"msgsm32.acm") ldr.LoadCount: 1 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (000000029EA10000) 00d8:00dc:trace:module:LdrUnloadDll (L"msgsm32.acm") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"msgsm32.acm") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"winmm.dll") ldr.LoadCount: 2 00d8:00dc:trace:module:MODULE_InitDLL (000000029EA10000 L"msgsm32.acm",PROCESS_DETACH,0000000000000000) 000000029EA18410 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000029EA10000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\msgsm32.acm" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:load_dll looking for L"msacm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\msacm32.dll" for L"msacm32.dll" at 00000001C8B40000, count=2 00d8:00dc:trace:module:load_dll looking for L"msacm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\msacm32.dll" for L"msacm32.dll" at 00000001C8B40000, count=3 00d8:00dc:trace:module:LdrUnloadDll (00000001C8B40000) 00d8:00dc:trace:module:LdrUnloadDll (L"msacm32.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"msacm32.dll") ldr.LoadCount: 2 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (00000001C8B40000) 00d8:00dc:trace:module:LdrUnloadDll (L"msacm32.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"msacm32.dll") ldr.LoadCount: 1 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:MODULE_InitDLL (00000001C8B40000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"msacm32.dll",0000000000000000) - END 00d8:00dc:trace:module:process_attach (L"msvfw32.dll",0000000000000000) - START 00d8:00dc:trace:module:process_attach (L"comctl32.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000002BB750000 L"comctl32.dll",PROCESS_ATTACH,0000000000000000) 00000002BB7FDA80 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C590, base 000000000031C588. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f01 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4C0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0009 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C450. 00d8:00dc:trace:module:FindResourceExW 00000002BB750000 #000e #0016 0000 00d8:00dc:trace:module:LoadResource 00000002BB750000 00000002BB8406B0 00d8:00dc:trace:module:FindResourceExW 00000002BB750000 #0003 #0002 0000 00d8:00dc:trace:module:LoadResource 00000002BB750000 00000002BB83F310 00d8:00dc:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031C0E0. 00d8:00dc:trace:module:FindResourceExW 00000002BB750000 #000e #0019 0000 00d8:00dc:trace:module:LoadResource 00000002BB750000 00000002BB8406C0 00d8:00dc:trace:module:FindResourceExW 00000002BB750000 #0003 #0003 0000 00d8:00dc:trace:module:LoadResource 00000002BB750000 00000002BB83F320 00d8:00dc:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031C0E0. 00d8:00dc:trace:module:FindResourceExW 00000002BB750000 #000e #001c 0000 00d8:00dc:trace:module:LoadResource 00000002BB750000 00000002BB8406D0 00d8:00dc:trace:module:FindResourceExW 00000002BB750000 #0003 #0004 0000 00d8:00dc:trace:module:LoadResource 00000002BB750000 00000002BB83F330 00d8:00dc:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031C0E0. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C460. 00d8:00dc:trace:module:MODULE_InitDLL (00000002BB750000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"comctl32.dll",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (000000039A620000 L"msvfw32.dll",PROCESS_ATTACH,0000000000000000) 000000039A62D460 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C630, base 000000000031C628. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (000000039A620000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"msvfw32.dll",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (0000000341D30000 L"quartz.dll",PROCESS_ATTACH,0000000000000000) 0000000341D9FDD0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000341D30000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"quartz.dll",0000000000000000) - END 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031CAB0, base 000000000031CAA8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000341D30000 L"WINE_REGISTRY" 0000000341DA0A00 31cfc0 00d8:00dc:trace:module:FindResourceExW 0000000341D30000 L"WINE_REGISTRY" L"DLLS/QUARTZ/CONTROL_TLB_T.RES" 0000 00d8:00dc:trace:module:LoadResource 0000000341D30000 0000000341DF6108 00d8:00dc:trace:module:load_dll looking for L"atl100.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\atl100.dll" for L"atl100.dll" at 00000001C1EF0000, count=3 00d8:00dc:trace:module:LdrGetDllFullName module 0000000341D30000, name 000000000031C8F0. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\quartz.dll" 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C950 260) 00d8:00dc:trace:module:FindResourceExW 0000000341D30000 L"WINE_REGISTRY" L"QUARTZ_STRMIF_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000341D30000 0000000341DF6118 00d8:00dc:trace:module:FindResourceExW 0000000341D30000 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 0000000341D30000 0000000341DF6128 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\quartz.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\quartz.dll" for L"C:\\windows\\system32\\quartz.dll" at 0000000341D30000, count=2 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C740, base 000000000031C738. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\devenum.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\devenum.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"devenum.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\devenum.dll" at 0x3ad720000-0x3ad74f000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\devenum.dll" section .text at 0x3ad721000 off 1000 size 9000 virt 8580 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\devenum.dll" section .data at 0x3ad72a000 off a000 size 1000 virt f0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\devenum.dll" section .rodata at 0x3ad72b000 off b000 size 1000 virt 18 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\devenum.dll" section .rdata at 0x3ad72c000 off c000 size b000 virt ac30 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\devenum.dll" section .pdata at 0x3ad737000 off 17000 size 1000 virt 468 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\devenum.dll" section .xdata at 0x3ad738000 off 18000 size 1000 virt 46c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\devenum.dll" section .bss at 0x3ad739000 off 0 size 0 virt 170 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\devenum.dll" section .edata at 0x3ad73a000 off 19000 size 12000 virt 11826 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\devenum.dll" section .idata at 0x3ad74c000 off 2b000 size 1000 virt e98 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\devenum.dll" section .rsrc at 0x3ad74d000 off 2c000 size 1000 virt ca8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\devenum.dll" section .reloc at 0x3ad74e000 off 2d000 size 1000 virt 1b4 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"avicap32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\avicap32.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"avicap32.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\avicap32.dll" at 0x3a77e0000-0x3a77ec000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\avicap32.dll" section .text at 0x3a77e1000 off 1000 size 2000 virt 1510 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\avicap32.dll" section .data at 0x3a77e3000 off 3000 size 1000 virt 70 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\avicap32.dll" section .rodata at 0x3a77e4000 off 4000 size 1000 virt 24 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\avicap32.dll" section .rdata at 0x3a77e5000 off 5000 size 1000 virt 380 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\avicap32.dll" section .pdata at 0x3a77e6000 off 6000 size 1000 virt 114 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\avicap32.dll" section .xdata at 0x3a77e7000 off 7000 size 1000 virt 12c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\avicap32.dll" section .bss at 0x3a77e8000 off 0 size 0 virt 170 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\avicap32.dll" section .edata at 0x3a77e9000 off 8000 size 1000 virt 21d flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\avicap32.dll" section .idata at 0x3a77ea000 off 9000 size 1000 virt 51c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\avicap32.dll" section .reloc at 0x3a77eb000 off a000 size 1000 virt 20 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\avicap32.dll" 0000000000460BD0 00000003A77E0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\avicap32.dll" at 00000003A77E0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\avicap32.dll" at 00000003A77E0000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"dsound.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\dsound.dll" for L"dsound.dll" at 0000000236DF0000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"msdmo.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\msdmo.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"msdmo.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\msdmo.dll" at 0x34abc0000-0x34abe1000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msdmo.dll" section .text at 0x34abc1000 off 1000 size 4000 virt 3a20 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msdmo.dll" section .data at 0x34abc5000 off 5000 size 1000 virt 80 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msdmo.dll" section .rodata at 0x34abc6000 off 6000 size 1000 virt 90 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msdmo.dll" section .rdata at 0x34abc7000 off 7000 size 7000 virt 6a50 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msdmo.dll" section .pdata at 0x34abce000 off e000 size 1000 virt 1ec flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msdmo.dll" section .xdata at 0x34abcf000 off f000 size 1000 virt 228 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msdmo.dll" section .bss at 0x34abd0000 off 0 size 0 virt 140 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msdmo.dll" section .edata at 0x34abd1000 off 10000 size d000 virt c691 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msdmo.dll" section .idata at 0x34abde000 off 1d000 size 1000 virt 638 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msdmo.dll" section .rsrc at 0x34abdf000 off 1e000 size 1000 virt 388 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msdmo.dll" section .reloc at 0x34abe0000 off 1f000 size 1000 virt 40 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=10 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msdmo.dll" 0000000000460EF0 000000034ABC0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msdmo.dll" at 000000034ABC0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msdmo.dll" at 000000034ABC0000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=11 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"oleaut32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\oleaut32.dll" for L"oleaut32.dll" at 00000002739C0000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"winmm.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\winmm.dll" for L"winmm.dll" at 00000003B8F00000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\devenum.dll" 000000000045FC80 00000003AD720000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\devenum.dll" at 00000003AD720000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\devenum.dll" at 00000003AD720000 00d8:00dc:trace:module:process_attach (L"devenum.dll",0000000000000000) - START 00d8:00dc:trace:module:process_attach (L"avicap32.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000003A77E0000 L"avicap32.dll",PROCESS_ATTACH,0000000000000000) 00000003A77E1A20 - CALL 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00d8:00dc:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00d8:00dc:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00d8:00dc:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031BCD0. 00d8:00dc:trace:module:MODULE_InitDLL (00000003A77E0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"avicap32.dll",0000000000000000) - END 00d8:00dc:trace:module:process_attach (L"msdmo.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (000000034ABC0000 L"msdmo.dll",PROCESS_ATTACH,0000000000000000) 000000034ABC3F20 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000034ABC0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"msdmo.dll",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (00000003AD720000 L"devenum.dll",PROCESS_ATTACH,0000000000000000) 00000003AD728700 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000003AD720000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"devenum.dll",0000000000000000) - END 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C5C0, base 000000000031C5B8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C270, base 000000000031C268. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031CBA0, base 000000000031CB98. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C8A0, base 000000000031C898. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031CCF0, base 000000000031CCE8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\cryptdlg.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\cryptdlg.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"cryptdlg.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\cryptdlg.dll" at 0x1c0ed0000-0x1c0ee3000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptdlg.dll" section .text at 0x1c0ed1000 off 1000 size 5000 virt 41d0 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptdlg.dll" section .data at 0x1c0ed6000 off 6000 size 1000 virt 1f0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptdlg.dll" section .rodata at 0x1c0ed7000 off 7000 size 1000 virt 148 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptdlg.dll" section .rdata at 0x1c0ed8000 off 8000 size 1000 virt 500 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptdlg.dll" section .pdata at 0x1c0ed9000 off 9000 size 1000 virt 15c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptdlg.dll" section .xdata at 0x1c0eda000 off a000 size 1000 virt 180 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptdlg.dll" section .bss at 0x1c0edb000 off 0 size 0 virt 160 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptdlg.dll" section .edata at 0x1c0edc000 off b000 size 1000 virt 69f flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptdlg.dll" section .idata at 0x1c0edd000 off c000 size 1000 virt a20 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptdlg.dll" section .rsrc at 0x1c0ede000 off d000 size 4000 virt 34f0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptdlg.dll" section .reloc at 0x1c0ee2000 off 11000 size 1000 virt 20 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"crypt32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\crypt32.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"crypt32.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\crypt32.dll" at 0x1dd3f0000-0x1dd4be000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\crypt32.dll" section .text at 0x1dd3f1000 off 1000 size 63000 virt 62550 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\crypt32.dll" section .data at 0x1dd454000 off 64000 size 3000 virt 2640 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\crypt32.dll" section .rodata at 0x1dd457000 off 67000 size 1000 virt 74c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\crypt32.dll" section .rdata at 0x1dd458000 off 68000 size 12000 virt 11830 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\crypt32.dll" section .pdata at 0x1dd46a000 off 7a000 size 3000 virt 2958 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\crypt32.dll" section .xdata at 0x1dd46d000 off 7d000 size 4000 virt 3260 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\crypt32.dll" section .bss at 0x1dd471000 off 0 size 0 virt 32d0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\crypt32.dll" section .edata at 0x1dd475000 off 81000 size 5000 virt 4c9c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\crypt32.dll" section .idata at 0x1dd47a000 off 86000 size 2000 virt 1650 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\crypt32.dll" section .rsrc at 0x1dd47c000 off 88000 size 41000 virt 40f48 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\crypt32.dll" section .reloc at 0x1dd4bd000 off c9000 size 1000 virt 514 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"bcrypt.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\bcrypt.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"bcrypt.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\bcrypt.dll" at 0x2d4d40000-0x2d4d57000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\bcrypt.dll" section .text at 0x2d4d41000 off 1000 size a000 virt 97c0 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\bcrypt.dll" section .data at 0x2d4d4b000 off b000 size 1000 virt 70 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\bcrypt.dll" section .rodata at 0x2d4d4c000 off c000 size 1000 virt 3b8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\bcrypt.dll" section .rdata at 0x2d4d4d000 off d000 size 2000 virt 1c40 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\bcrypt.dll" section .pdata at 0x2d4d4f000 off f000 size 1000 virt 420 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\bcrypt.dll" section .xdata at 0x2d4d50000 off 10000 size 1000 virt 52c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\bcrypt.dll" section .bss at 0x2d4d51000 off 0 size 0 virt 170 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\bcrypt.dll" section .edata at 0x2d4d52000 off 11000 size 2000 virt 1317 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\bcrypt.dll" section .idata at 0x2d4d54000 off 13000 size 1000 virt 6cc flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\bcrypt.dll" section .rsrc at 0x2d4d55000 off 14000 size 1000 virt 3c0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\bcrypt.dll" section .reloc at 0x2d4d56000 off 15000 size 1000 virt 44 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\bcrypt.dll" 00000000004619D0 00000002D4D40000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\bcrypt.dll" at 00000002D4D40000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\bcrypt.dll" at 00000002D4D40000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\crypt32.dll" 00000000004616F0 00000001DD3F0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\crypt32.dll" at 00000001DD3F0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\crypt32.dll" at 00000001DD3F0000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"cryptui.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\cryptui.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"cryptui.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\cryptui.dll" at 0x3bb250000-0x3bb358000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptui.dll" section .text at 0x3bb251000 off 1000 size 11000 virt 10c80 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptui.dll" section .data at 0x3bb262000 off 12000 size 1000 virt 2b0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptui.dll" section .rodata at 0x3bb263000 off 13000 size 1000 virt 44c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptui.dll" section .rdata at 0x3bb264000 off 14000 size 8000 virt 72e0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptui.dll" section .pdata at 0x3bb26c000 off 1c000 size 1000 virt 78c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptui.dll" section .xdata at 0x3bb26d000 off 1d000 size 1000 virt 940 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptui.dll" section .bss at 0x3bb26e000 off 0 size 0 virt 170 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptui.dll" section .edata at 0x3bb26f000 off 1e000 size e000 virt d1ea flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptui.dll" section .idata at 0x3bb27d000 off 2c000 size 2000 virt 188c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptui.dll" section .rsrc at 0x3bb27f000 off 2e000 size d8000 virt d7668 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptui.dll" section .reloc at 0x3bb357000 off 106000 size 1000 virt c4 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"comctl32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\comctl32.dll" for L"comctl32.dll" at 00000002BB750000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"comdlg32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\comdlg32.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"comdlg32.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\comdlg32.dll" at 0x31f800000-0x31f8ff000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .text at 0x31f801000 off 1000 size 2f000 virt 2e920 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .data at 0x31f830000 off 30000 size 1000 virt 150 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .rodata at 0x31f831000 off 31000 size 1000 virt c4 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .rdata at 0x31f832000 off 32000 size e000 virt d590 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .pdata at 0x31f840000 off 40000 size 2000 virt 12c0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .xdata at 0x31f842000 off 42000 size 2000 virt 1594 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .bss at 0x31f844000 off 0 size 0 virt a30 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .edata at 0x31f845000 off 44000 size d000 virt cacc flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .idata at 0x31f852000 off 51000 size 3000 virt 2ca8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .rsrc at 0x31f855000 off 54000 size a9000 virt a8780 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .reloc at 0x31f8fe000 off fd000 size 1000 virt 2e0 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"comctl32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\comctl32.dll" for L"comctl32.dll" at 00000002BB750000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"shell32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"shlwapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=4 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"winspool.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\winspool.drv" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"winspool.drv" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\winspool.drv" at 0x1c4ee0000-0x1c4f10000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .text at 0x1c4ee1000 off 1000 size 19000 virt 18c70 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .data at 0x1c4efa000 off 1a000 size 1000 virt 210 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .rodata at 0x1c4efb000 off 1b000 size 1000 virt 7c0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .rdata at 0x1c4efc000 off 1c000 size 4000 virt 3210 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .pdata at 0x1c4f00000 off 20000 size 1000 virt 930 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .xdata at 0x1c4f01000 off 21000 size 1000 virt bfc flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .bss at 0x1c4f02000 off 0 size 0 virt 450 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .edata at 0x1c4f03000 off 22000 size 3000 virt 28db flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .idata at 0x1c4f06000 off 25000 size 1000 virt f44 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .rsrc at 0x1c4f07000 off 26000 size 8000 virt 78d0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .reloc at 0x1c4f0f000 off 2e000 size 1000 virt 84 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\winspool.drv" 0000000000462540 00000001C4EE0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\winspool.drv" at 00000001C4EE0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\winspool.drv" at 00000001C4EE0000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\comdlg32.dll" 00000000004620A0 000000031F800000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\comdlg32.dll" at 000000031F800000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\comdlg32.dll" at 000000031F800000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"crypt32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\crypt32.dll" for L"crypt32.dll" at 00000001DD3F0000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=12 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\cryptui.dll" 0000000000461D70 00000003BB250000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\cryptui.dll" at 00000003BB250000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\cryptui.dll" at 00000003BB250000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"wintrust.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\wintrust.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"wintrust.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\wintrust.dll" at 0x1fdfd0000-0x1fdff8000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wintrust.dll" section .text at 0x1fdfd1000 off 1000 size 17000 virt 16330 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wintrust.dll" section .data at 0x1fdfe8000 off 18000 size 1000 virt 410 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wintrust.dll" section .rodata at 0x1fdfe9000 off 19000 size 1000 virt 604 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wintrust.dll" section .rdata at 0x1fdfea000 off 1a000 size 4000 virt 34e0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wintrust.dll" section .pdata at 0x1fdfee000 off 1e000 size 1000 virt 9cc flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wintrust.dll" section .xdata at 0x1fdfef000 off 1f000 size 1000 virt a8c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wintrust.dll" section .bss at 0x1fdff0000 off 0 size 0 virt 400 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wintrust.dll" section .edata at 0x1fdff1000 off 20000 size 3000 virt 281e flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wintrust.dll" section .idata at 0x1fdff4000 off 23000 size 2000 virt 1240 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wintrust.dll" section .rsrc at 0x1fdff6000 off 25000 size 1000 virt 3b8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wintrust.dll" section .reloc at 0x1fdff7000 off 26000 size 1000 virt 54 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"crypt32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\crypt32.dll" for L"crypt32.dll" at 00000001DD3F0000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wintrust.dll" 0000000000462A60 00000001FDFD0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wintrust.dll" at 00000001FDFD0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wintrust.dll" at 00000001FDFD0000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\cryptdlg.dll" 0000000000461370 00000001C0ED0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\cryptdlg.dll" at 00000001C0ED0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\cryptdlg.dll" at 00000001C0ED0000 00d8:00dc:trace:module:process_attach (L"cryptdlg.dll",0000000000000000) - START 00d8:00dc:trace:module:process_attach (L"crypt32.dll",0000000000000000) - START 00d8:00dc:trace:module:process_attach (L"bcrypt.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_ATTACH,0000000000000000) 00000002D4D49C40 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031CA70, base 000000000031CA68. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"bcrypt.dll",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_ATTACH,0000000000000000) 00000001DD4524D0 - CALL 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 00d8:00dc:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 00d8:00dc:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031CB00, base 000000000031CAF8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"crypt32.dll",0000000000000000) - END 00d8:00dc:trace:module:process_attach (L"cryptui.dll",0000000000000000) - START 00d8:00dc:trace:module:process_attach (L"comdlg32.dll",0000000000000000) - START 00d8:00dc:trace:module:process_attach (L"winspool.drv",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000001C4EE0000 L"winspool.drv",PROCESS_ATTACH,0000000000000000) 00000001C4EF90D0 - CALL 00d8:00dc:trace:module:load_dll looking for L"WINEPS.DRV" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" at 0x296a50000-0x296ac8000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .text at 0x296a51000 off 1000 size 1a000 virt 19c30 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .data at 0x296a6b000 off 1b000 size 6000 virt 5070 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .rodata at 0x296a71000 off 21000 size 1000 virt 14 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .rdata at 0x296a72000 off 22000 size 43000 virt 42bf0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .pdata at 0x296ab5000 off 65000 size 1000 virt ac8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .xdata at 0x296ab6000 off 66000 size 1000 virt d20 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .bss at 0x296ab7000 off 0 size 0 virt 1a0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .edata at 0x296ab8000 off 67000 size 2000 virt 142a flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .idata at 0x296aba000 off 69000 size 2000 virt 12a4 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .rsrc at 0x296abc000 off 6b000 size 6000 virt 54f0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .reloc at 0x296ac2000 off 71000 size 6000 virt 5ff8 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"winspool.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\winspool.drv" for L"winspool.drv" at 00000001C4EE0000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\WINEPS.DRV" 0000000000462DA0 0000000296A50000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\WINEPS.DRV" at 0000000296A50000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\WINEPS.DRV" at 0000000296A50000 00d8:00dc:trace:module:process_attach (L"WINEPS.DRV",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (0000000296A50000 L"WINEPS.DRV",PROCESS_ATTACH,0000000000000000) 0000000296A69F80 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C040, base 000000000031C038. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (0000000296A50000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"WINEPS.DRV",0000000000000000) - END 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C9E0, base 000000000031C9D8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031BDE0, base 000000000031BDD8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:process:GetEnvironmentVariableW (L"TMP" 000000000031C210 260) 00d8:00dc:trace:process:GetEnvironmentVariableW (L"TEMP" 000000000031C210 260) 00d8:00dc:trace:process:GetEnvironmentVariableW (L"USERPROFILE" 000000000031C210 260) 00d8:00dc:trace:module:load_dll looking for L"localspl.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\localspl.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"localspl.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\localspl.dll" at 0x2a7800000-0x2a782f000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\localspl.dll" section .text at 0x2a7801000 off 1000 size 12000 virt 11b10 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\localspl.dll" section .data at 0x2a7813000 off 13000 size 1000 virt 330 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\localspl.dll" section .rodata at 0x2a7814000 off 14000 size 1000 virt 590 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\localspl.dll" section .rdata at 0x2a7815000 off 15000 size 4000 virt 3a30 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\localspl.dll" section .pdata at 0x2a7819000 off 19000 size 1000 virt 3b4 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\localspl.dll" section .xdata at 0x2a781a000 off 1a000 size 1000 virt 4c8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\localspl.dll" section .bss at 0x2a781b000 off 0 size 0 virt 160 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\localspl.dll" section .edata at 0x2a781c000 off 1b000 size 2000 virt 1257 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\localspl.dll" section .idata at 0x2a781e000 off 1d000 size 1000 virt a14 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\localspl.dll" section .rsrc at 0x2a781f000 off 1e000 size f000 virt e128 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\localspl.dll" section .reloc at 0x2a782e000 off 2d000 size 1000 virt 1cc flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"spoolss.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\spoolss.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"spoolss.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\spoolss.dll" at 0x1d2b40000-0x1d2b50000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\spoolss.dll" section .text at 0x1d2b41000 off 1000 size 4000 virt 3400 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\spoolss.dll" section .data at 0x1d2b45000 off 5000 size 1000 virt 120 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\spoolss.dll" section .rodata at 0x1d2b46000 off 6000 size 1000 virt cb4 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\spoolss.dll" section .rdata at 0x1d2b47000 off 7000 size 1000 virt 660 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\spoolss.dll" section .pdata at 0x1d2b48000 off 8000 size 1000 virt 204 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\spoolss.dll" section .xdata at 0x1d2b49000 off 9000 size 1000 virt 218 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\spoolss.dll" section .bss at 0x1d2b4a000 off 0 size 0 virt 180 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\spoolss.dll" section .edata at 0x1d2b4b000 off a000 size 3000 virt 2a6c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\spoolss.dll" section .idata at 0x1d2b4e000 off d000 size 1000 virt 478 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\spoolss.dll" section .reloc at 0x1d2b4f000 off e000 size 1000 virt 28 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\spoolss.dll" 0000000000468530 00000001D2B40000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\spoolss.dll" at 00000001D2B40000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\spoolss.dll" at 00000001D2B40000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\localspl.dll" 0000000000468220 00000002A7800000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\localspl.dll" at 00000002A7800000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\localspl.dll" at 00000002A7800000 00d8:00dc:trace:module:process_attach (L"localspl.dll",0000000000000000) - START 00d8:00dc:trace:module:process_attach (L"spoolss.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000001D2B40000 L"spoolss.dll",PROCESS_ATTACH,0000000000000000) 00000001D2B43930 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031B9B0, base 000000000031B9A8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (00000001D2B40000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"spoolss.dll",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (00000002A7800000 L"localspl.dll",PROCESS_ATTACH,0000000000000000) 00000002A7811FB0 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031BA40, base 000000000031BA38. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (00000002A7800000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"localspl.dll",0000000000000000) - END 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\spool\\drivers\\w32x86\\3\\wineps.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:warn:module:load_dll Failed to load module L"C:\\windows\\system32\\spool\\drivers\\w32x86\\3\\wineps.drv"; status=c0000135 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" at 0x11a0000-0x1218000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .text at 0x11a1000 off 1000 size 1a000 virt 19c30 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .data at 0x11bb000 off 1b000 size 6000 virt 5070 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .rodata at 0x11c1000 off 21000 size 1000 virt 14 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .rdata at 0x11c2000 off 22000 size 43000 virt 42bf0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .pdata at 0x1205000 off 65000 size 1000 virt ac8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .xdata at 0x1206000 off 66000 size 1000 virt d20 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .bss at 0x1207000 off 0 size 0 virt 1a0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .edata at 0x1208000 off 67000 size 2000 virt 142a flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .idata at 0x120a000 off 69000 size 2000 virt 12a4 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .rsrc at 0x120c000 off 6b000 size 6000 virt 54f0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .reloc at 0x1212000 off 71000 size 6000 virt 5ff8 flags 42000040 00d8:00dc:trace:module:load_native_dll found L"C:\\windows\\system32\\WINEPS.DRV" for L"\\??\\C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" at 0000000296A50000, count=2 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" at 0000000296A50000 00d8:00dc:trace:module:LdrUnloadDll (0000000296A50000) 00d8:00dc:trace:module:LdrUnloadDll (L"WINEPS.DRV") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"WINEPS.DRV") ldr.LoadCount: 1 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\spool\\drivers\\arm\\3\\wineps.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:warn:module:load_dll Failed to load module L"C:\\windows\\system32\\spool\\drivers\\arm\\3\\wineps.drv"; status=c0000135 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\spool\\drivers\\arm64\\3\\wineps.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:warn:module:load_dll Failed to load module L"C:\\windows\\system32\\spool\\drivers\\arm64\\3\\wineps.drv"; status=c0000135 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\spool\\drivers\\win40\\0\\.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:warn:module:load_dll Failed to load module L"C:\\windows\\system32\\spool\\drivers\\win40\\0\\.dll"; status=c0000135 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" at 0x11a0000-0x1218000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .text at 0x11a1000 off 1000 size 1a000 virt 19c30 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .data at 0x11bb000 off 1b000 size 6000 virt 5070 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .rodata at 0x11c1000 off 21000 size 1000 virt 14 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .rdata at 0x11c2000 off 22000 size 43000 virt 42bf0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .pdata at 0x1205000 off 65000 size 1000 virt ac8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .xdata at 0x1206000 off 66000 size 1000 virt d20 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .bss at 0x1207000 off 0 size 0 virt 1a0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .edata at 0x1208000 off 67000 size 2000 virt 142a flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .idata at 0x120a000 off 69000 size 2000 virt 12a4 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .rsrc at 0x120c000 off 6b000 size 6000 virt 54f0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .reloc at 0x1212000 off 71000 size 6000 virt 5ff8 flags 42000040 00d8:00dc:trace:module:load_native_dll found L"C:\\windows\\system32\\WINEPS.DRV" for L"\\??\\C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" at 0000000296A50000, count=2 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" at 0000000296A50000 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C030, base 000000000031C028. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:FindResourceExW 00000001C4EE0000 L"PPDFILE" #0001 0000 00d8:00dc:trace:module:LoadResource 00000001C4EE0000 00000001C4F07358 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\spool\\drivers\\w32x86\\3\\wineps.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:warn:module:load_dll Failed to load module L"C:\\windows\\system32\\spool\\drivers\\w32x86\\3\\wineps.drv"; status=c0000135 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" at 0x11a0000-0x1218000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .text at 0x11a1000 off 1000 size 1a000 virt 19c30 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .data at 0x11bb000 off 1b000 size 6000 virt 5070 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .rodata at 0x11c1000 off 21000 size 1000 virt 14 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .rdata at 0x11c2000 off 22000 size 43000 virt 42bf0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .pdata at 0x1205000 off 65000 size 1000 virt ac8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .xdata at 0x1206000 off 66000 size 1000 virt d20 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .bss at 0x1207000 off 0 size 0 virt 1a0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .edata at 0x1208000 off 67000 size 2000 virt 142a flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .idata at 0x120a000 off 69000 size 2000 virt 12a4 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .rsrc at 0x120c000 off 6b000 size 6000 virt 54f0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .reloc at 0x1212000 off 71000 size 6000 virt 5ff8 flags 42000040 00d8:00dc:trace:module:load_native_dll found L"C:\\windows\\system32\\WINEPS.DRV" for L"\\??\\C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" at 0000000296A50000, count=3 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" at 0000000296A50000 00d8:00dc:trace:module:LdrUnloadDll (0000000296A50000) 00d8:00dc:trace:module:LdrUnloadDll (L"WINEPS.DRV") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"WINEPS.DRV") ldr.LoadCount: 2 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\spool\\drivers\\arm\\3\\wineps.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:warn:module:load_dll Failed to load module L"C:\\windows\\system32\\spool\\drivers\\arm\\3\\wineps.drv"; status=c0000135 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\spool\\drivers\\arm64\\3\\wineps.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:warn:module:load_dll Failed to load module L"C:\\windows\\system32\\spool\\drivers\\arm64\\3\\wineps.drv"; status=c0000135 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\spool\\drivers\\win40\\0\\\a120\c4ef\0001.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:warn:module:load_dll Failed to load module L"C:\\windows\\system32\\spool\\drivers\\win40\\0\\\a120\c4ef\0001.dll"; status=c0000135 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" at 0x11a0000-0x1218000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .text at 0x11a1000 off 1000 size 1a000 virt 19c30 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .data at 0x11bb000 off 1b000 size 6000 virt 5070 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .rodata at 0x11c1000 off 21000 size 1000 virt 14 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .rdata at 0x11c2000 off 22000 size 43000 virt 42bf0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .pdata at 0x1205000 off 65000 size 1000 virt ac8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .xdata at 0x1206000 off 66000 size 1000 virt d20 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .bss at 0x1207000 off 0 size 0 virt 1a0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .edata at 0x1208000 off 67000 size 2000 virt 142a flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .idata at 0x120a000 off 69000 size 2000 virt 12a4 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .rsrc at 0x120c000 off 6b000 size 6000 virt 54f0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\WINEPS.DRV" section .reloc at 0x1212000 off 71000 size 6000 virt 5ff8 flags 42000040 00d8:00dc:trace:module:load_native_dll found L"C:\\windows\\system32\\WINEPS.DRV" for L"\\??\\C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" at 0000000296A50000, count=3 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\spool\\drivers\\x64\\3\\wineps.drv" at 0000000296A50000 00d8:00dc:trace:module:MODULE_InitDLL (00000001C4EE0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"winspool.drv",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (000000031F800000 L"comdlg32.dll",PROCESS_ATTACH,0000000000000000) 000000031F82E950 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C590, base 000000000031C588. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031CA80, base 000000000031CA78. 00d8:00dc:trace:module:LdrGetDllHandleEx L"SHELL32.DLL" -> 00000001C69E0000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (000000031F800000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"comdlg32.dll",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (00000003BB250000 L"cryptui.dll",PROCESS_ATTACH,0000000000000000) 00000003BB260D90 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C630, base 000000000031C628. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (00000003BB250000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"cryptui.dll",0000000000000000) - END 00d8:00dc:trace:module:process_attach (L"wintrust.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000001FDFD0000 L"wintrust.dll",PROCESS_ATTACH,0000000000000000) 00000001FDFE63D0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000001FDFD0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"wintrust.dll",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (00000001C0ED0000 L"cryptdlg.dll",PROCESS_ATTACH,0000000000000000) 00000001C0ED4700 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C6C0, base 000000000031C6B8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (00000001C0ED0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"cryptdlg.dll",0000000000000000) - END 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031CC90, base 000000000031CC88. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C940, base 000000000031C938. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031CCA0, base 000000000031CC98. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C9A0, base 000000000031C998. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\cryptnet.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\cryptnet.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"cryptnet.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\cryptnet.dll" at 0x2d1070000-0x2d108a000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptnet.dll" section .text at 0x2d1071000 off 1000 size 7000 virt 68c0 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptnet.dll" section .data at 0x2d1078000 off 8000 size 1000 virt e0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptnet.dll" section .rodata at 0x2d1079000 off 9000 size 1000 virt 1a0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptnet.dll" section .rdata at 0x2d107a000 off a000 size 4000 virt 37e0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptnet.dll" section .pdata at 0x2d107e000 off e000 size 1000 virt 24c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptnet.dll" section .xdata at 0x2d107f000 off f000 size 1000 virt 2c0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptnet.dll" section .bss at 0x2d1080000 off 0 size 0 virt 180 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptnet.dll" section .edata at 0x2d1081000 off 10000 size 6000 virt 5469 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptnet.dll" section .idata at 0x2d1087000 off 16000 size 2000 virt 1274 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\cryptnet.dll" section .reloc at 0x2d1089000 off 18000 size 1000 virt 6c flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"crypt32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\crypt32.dll" for L"crypt32.dll" at 00000001DD3F0000, count=4 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=13 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"shell32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=4 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\cryptnet.dll" 0000000000468BA0 00000002D1070000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\cryptnet.dll" at 00000002D1070000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\cryptnet.dll" at 00000002D1070000 00d8:00dc:trace:module:process_attach (L"cryptnet.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000002D1070000 L"cryptnet.dll",PROCESS_ATTACH,0000000000000000) 00000002D1076CD0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000002D1070000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"cryptnet.dll",0000000000000000) - END 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031CB30, base 000000000031CB28. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\devenum.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\devenum.dll" for L"C:\\windows\\system32\\devenum.dll" at 00000003AD720000, count=2 00d8:00dc:trace:module:EnumResourceNamesExW 00000003AD720000 L"WINE_REGISTRY" 00000003AD7291C0 31d060 00d8:00dc:trace:module:FindResourceExW 00000003AD720000 L"WINE_REGISTRY" L"DEVENUM_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 00000003AD720000 00000003AD74D080 00d8:00dc:trace:module:load_dll looking for L"atl100.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\atl100.dll" for L"atl100.dll" at 00000001C1EF0000, count=4 00d8:00dc:trace:module:LdrGetDllFullName module 00000003AD720000, name 000000000031C990. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\devenum.dll" 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C9F0 260) 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\mp3dmod.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\mp3dmod.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"mp3dmod.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\mp3dmod.dll" at 0x258250000-0x2582ab000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mp3dmod.dll" section .text at 0x258251000 off 1000 size 23000 virt 22930 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mp3dmod.dll" section .data at 0x258274000 off 24000 size 1000 virt 750 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mp3dmod.dll" section .rodata at 0x258275000 off 25000 size 1000 virt 38 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mp3dmod.dll" section .rdata at 0x258276000 off 26000 size 1e000 virt 1dbe0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mp3dmod.dll" section .pdata at 0x258294000 off 44000 size 2000 virt 13b0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mp3dmod.dll" section .xdata at 0x258296000 off 46000 size 2000 virt 12d0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mp3dmod.dll" section .bss at 0x258298000 off 0 size 0 virt 150 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mp3dmod.dll" section .edata at 0x258299000 off 48000 size f000 virt e8d5 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mp3dmod.dll" section .idata at 0x2582a8000 off 57000 size 1000 virt b08 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mp3dmod.dll" section .rsrc at 0x2582a9000 off 58000 size 1000 virt 188 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mp3dmod.dll" section .reloc at 0x2582aa000 off 59000 size 1000 virt 3a4 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernelbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"msdmo.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\msdmo.dll" for L"msdmo.dll" at 000000034ABC0000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=14 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\mp3dmod.dll" 0000000000468DC0 0000000258250000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\mp3dmod.dll" at 0000000258250000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\mp3dmod.dll" at 0000000258250000 00d8:00dc:trace:module:process_attach (L"mp3dmod.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (0000000258250000 L"mp3dmod.dll",PROCESS_ATTACH,0000000000000000) 0000000258272A40 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000258250000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"mp3dmod.dll",0000000000000000) - END 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031CD00, base 000000000031CCF8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C9B0, base 000000000031C9A8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000258250000 L"WINE_REGISTRY" 00000002582734D0 31d030 00d8:00dc:trace:module:FindResourceExW 0000000258250000 L"WINE_REGISTRY" L"MP3DMOD_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000258250000 00000002582A9048 00d8:00dc:trace:module:load_dll looking for L"atl100.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\atl100.dll" for L"atl100.dll" at 00000001C1EF0000, count=5 00d8:00dc:trace:module:LdrGetDllFullName module 0000000258250000, name 000000000031C960. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\mp3dmod.dll" 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C9C0 260) 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\mshtml.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\mshtml.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"mshtml.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\mshtml.dll" at 0x34ea20000-0x34ebf8000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mshtml.dll" section .text at 0x34ea21000 off 1000 size 11a000 virt 119500 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mshtml.dll" section .data at 0x34eb3b000 off 11b000 size 4000 virt 3450 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mshtml.dll" section .rodata at 0x34eb3f000 off 11f000 size 1000 virt c8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mshtml.dll" section .rdata at 0x34eb40000 off 120000 size 6b000 virt 6a0b0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mshtml.dll" section .pdata at 0x34ebab000 off 18b000 size 13000 virt 1260c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mshtml.dll" section .xdata at 0x34ebbe000 off 19e000 size 11000 virt 102f8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mshtml.dll" section .bss at 0x34ebcf000 off 0 size 0 virt d30 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mshtml.dll" section .edata at 0x34ebd0000 off 1af000 size 12000 virt 1157a flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mshtml.dll" section .idata at 0x34ebe2000 off 1c1000 size 2000 virt 1f84 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mshtml.dll" section .rsrc at 0x34ebe4000 off 1c3000 size f000 virt ef00 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mshtml.dll" section .reloc at 0x34ebf3000 off 1d2000 size 5000 virt 4f54 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=15 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"oleaut32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\oleaut32.dll" for L"oleaut32.dll" at 00000002739C0000, count=4 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"shell32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=5 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"shlwapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=5 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"urlmon.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\urlmon.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"urlmon.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\urlmon.dll" at 0x3422e0000-0x34237c000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .text at 0x3422e1000 off 1000 size 55000 virt 54af0 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .data at 0x342336000 off 56000 size 1000 virt 760 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .rodata at 0x342337000 off 57000 size 1000 virt 948 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .rdata at 0x342338000 off 58000 size 17000 virt 164e0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .pdata at 0x34234f000 off 6f000 size 4000 virt 34ec flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .xdata at 0x342353000 off 73000 size 4000 virt 3484 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .bss at 0x342357000 off 0 size 0 virt 1f0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .edata at 0x342358000 off 77000 size 11000 virt 1037c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .idata at 0x342369000 off 88000 size 3000 virt 27ec flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .rsrc at 0x34236c000 off 8b000 size f000 virt e468 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .reloc at 0x34237b000 off 9a000 size 1000 virt acc flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=16 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"oleaut32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\oleaut32.dll" for L"oleaut32.dll" at 00000002739C0000, count=5 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"rpcrt4.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=6 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"shell32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=6 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"shlwapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=6 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"wininet.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\wininet.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"wininet.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\wininet.dll" at 0x3a0440000-0x3a04c3000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .text at 0x3a0441000 off 1000 size 47000 virt 46520 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .data at 0x3a0488000 off 48000 size 1000 virt 450 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .rodata at 0x3a0489000 off 49000 size 1000 virt 854 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .rdata at 0x3a048a000 off 4a000 size c000 virt b330 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .pdata at 0x3a0496000 off 56000 size 2000 virt 19b0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .xdata at 0x3a0498000 off 58000 size 2000 virt 1ebc flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .bss at 0x3a049a000 off 0 size 0 virt 1e0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .edata at 0x3a049b000 off 5a000 size 5000 virt 49b6 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .idata at 0x3a04a0000 off 5f000 size 2000 virt 1ec8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .rsrc at 0x3a04a2000 off 61000 size 20000 virt 1f3e8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .reloc at 0x3a04c2000 off 81000 size 1000 virt 300 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"mpr.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\mpr.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"mpr.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\mpr.dll" at 0x24f470000-0x24f48f000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .text at 0x24f471000 off 1000 size b000 virt a4a0 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .data at 0x24f47c000 off c000 size 1000 virt c0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .rodata at 0x24f47d000 off d000 size 1000 virt 31c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .rdata at 0x24f47e000 off e000 size 2000 virt 14a0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .pdata at 0x24f480000 off 10000 size 1000 virt 654 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .xdata at 0x24f481000 off 11000 size 1000 virt 6d4 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .bss at 0x24f482000 off 0 size 0 virt 160 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .edata at 0x24f483000 off 12000 size 2000 virt 19e3 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .idata at 0x24f485000 off 14000 size 1000 virt a00 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .rsrc at 0x24f486000 off 15000 size 8000 virt 77c0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .reloc at 0x24f48e000 off 1d000 size 1000 virt 20 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\mpr.dll" 0000000000463D30 000000024F470000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\mpr.dll" at 000000024F470000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\mpr.dll" at 000000024F470000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"shell32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=7 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"shlwapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=7 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ws2_32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\ws2_32.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"ws2_32.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" at 0x1ec2b0000-0x1ec2d6000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .text at 0x1ec2b1000 off 1000 size 13000 virt 12500 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .data at 0x1ec2c4000 off 14000 size 1000 virt 1b0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rodata at 0x1ec2c5000 off 15000 size 1000 virt 85c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rdata at 0x1ec2c6000 off 16000 size 5000 virt 4990 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .pdata at 0x1ec2cb000 off 1b000 size 1000 virt 954 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .xdata at 0x1ec2cc000 off 1c000 size 1000 virt a3c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .bss at 0x1ec2cd000 off 0 size 0 virt 170 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .edata at 0x1ec2ce000 off 1d000 size 3000 virt 23c6 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .idata at 0x1ec2d1000 off 20000 size 1000 virt c14 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rsrc at 0x1ec2d2000 off 21000 size 3000 virt 29b8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .reloc at 0x1ec2d5000 off 24000 size 1000 virt 70 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ws2_32.dll" 00000000004641C0 00000001EC2B0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ws2_32.dll" at 00000001EC2B0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ws2_32.dll" at 00000001EC2B0000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wininet.dll" 0000000000463A60 00000003A0440000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wininet.dll" at 00000003A0440000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wininet.dll" at 00000003A0440000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\urlmon.dll" 00000000004635C0 00000003422E0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\urlmon.dll" at 00000003422E0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\urlmon.dll" at 00000003422E0000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\mshtml.dll" 00000000004630D0 000000034EA20000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\mshtml.dll" at 000000034EA20000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\mshtml.dll" at 000000034EA20000 00d8:00dc:trace:module:process_attach (L"mshtml.dll",0000000000000000) - START 00d8:00dc:trace:module:process_attach (L"urlmon.dll",0000000000000000) - START 00d8:00dc:trace:module:process_attach (L"wininet.dll",0000000000000000) - START 00d8:00dc:trace:module:process_attach (L"mpr.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (000000024F470000 L"mpr.dll",PROCESS_ATTACH,0000000000000000) 000000024F47A960 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000024F470000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"mpr.dll",0000000000000000) - END 00d8:00dc:trace:module:process_attach (L"ws2_32.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000001EC2B0000 L"ws2_32.dll",PROCESS_ATTACH,0000000000000000) 00000001EC2C27C0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000001EC2B0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"ws2_32.dll",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (00000003A0440000 L"wininet.dll",PROCESS_ATTACH,0000000000000000) 00000003A0486300 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C590, base 000000000031C588. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31be5c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31be5c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31be5c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31be5c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31be5c,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31be5c,0x00000004,0x0) 00d8:00dc:trace:module:MODULE_InitDLL (00000003A0440000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"wininet.dll",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (00000003422E0000 L"urlmon.dll",PROCESS_ATTACH,0000000000000000) 0000000342334800 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C620, base 000000000031C618. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (00000003422E0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"urlmon.dll",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (000000034EA20000 L"mshtml.dll",PROCESS_ATTACH,0000000000000000) 000000034EB39480 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000034EA20000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"mshtml.dll",0000000000000000) - END 00d8:00dc:trace:module:EnumResourceNamesExW 000000034EA20000 L"WINE_REGISTRY" 000000034EB39F10 31d090 00d8:00dc:trace:module:FindResourceExW 000000034EA20000 L"WINE_REGISTRY" L"MSHTML_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 000000034EA20000 000000034EBE46B0 00d8:00dc:trace:module:load_dll looking for L"atl100.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\atl100.dll" for L"atl100.dll" at 00000001C1EF0000, count=6 00d8:00dc:trace:module:LdrGetDllFullName module 000000034EA20000, name 000000000031C9C0. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\mshtml.dll" 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CA20 260) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C850, base 000000000031C848. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:load_dll looking for L"advpack.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\advpack.dll" 00d8:00dc:trace:module:get_load_order_value got environment b for L"advpack" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\advpack.dll" at 0x1d1cc0000-0x1d1cd6000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .text at 0x1d1cc1000 off 1000 size a000 virt 9f00 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .data at 0x1d1ccb000 off b000 size 1000 virt a0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .rodata at 0x1d1ccc000 off c000 size 1000 virt 1d4 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .rdata at 0x1d1ccd000 off d000 size 2000 virt 1130 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .pdata at 0x1d1ccf000 off f000 size 1000 virt 51c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .xdata at 0x1d1cd0000 off 10000 size 1000 virt 6d0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .bss at 0x1d1cd1000 off 0 size 0 virt 160 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .edata at 0x1d1cd2000 off 11000 size 1000 virt ff7 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .idata at 0x1d1cd3000 off 12000 size 2000 virt 1004 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .reloc at 0x1d1cd5000 off 14000 size 1000 virt 24 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=17 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"setupapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\setupapi.dll" for L"setupapi.dll" at 000000021A7E0000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"version.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\version.dll" for L"version.dll" at 00000002F1FA0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advpack.dll" 00000000004656A0 00000001D1CC0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advpack.dll" at 00000001D1CC0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advpack.dll" at 00000001D1CC0000 00d8:00dc:trace:module:process_attach (L"advpack.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000001D1CC0000 L"advpack.dll",PROCESS_ATTACH,0000000000000000) 00000001D1CCA2E0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000001D1CC0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"advpack.dll",0000000000000000) - END 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031CAA0, base 000000000031CA98. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C7A0, base 000000000031C798. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:process:GetEnvironmentVariableW (L"TMP" 000000000031C1D0 260) 00d8:00dc:trace:process:GetEnvironmentVariableW (L"TEMP" 000000000031C1D0 260) 00d8:00dc:trace:process:GetEnvironmentVariableW (L"USERPROFILE" 000000000031C1D0 260) 00d8:00dc:trace:module:FindResourceExW 000000034EA20000 L"REGINST" L"REGINST" 0000 00d8:00dc:trace:module:LoadResource 000000034EA20000 000000034EBE4690 00d8:00dc:trace:module:LdrGetDllFullName module 000000034EA20000, name 000000000031C3D0. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\mshtml.dll" 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C660 260) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000021A7E0000, 000000021A817560, 0000000000000000, 000000007B60C498, 000000021A847BC0, 0x00000000) 00d8:00dc:trace:module:LdrUnloadDll (00000001D1CC0000) 00d8:00dc:trace:module:LdrUnloadDll (L"advpack.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"advpack.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 16 00d8:00dc:trace:module:MODULE_DecRefCount (L"setupapi.dll") ldr.LoadCount: 1 00d8:00dc:trace:module:MODULE_InitDLL (00000001D1CC0000 L"advpack.dll",PROCESS_DETACH,0000000000000000) 00000001D1CCA2E0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000001D1CC0000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\advpack.dll" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\msisip.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\msisip.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"msisip.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\msisip.dll" at 0x364870000-0x36487c000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msisip.dll" section .text at 0x364871000 off 1000 size 2000 virt 1570 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msisip.dll" section .data at 0x364873000 off 3000 size 1000 virt 230 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msisip.dll" section .rodata at 0x364874000 off 4000 size 1000 virt 9c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msisip.dll" section .rdata at 0x364875000 off 5000 size 1000 virt 300 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msisip.dll" section .pdata at 0x364876000 off 6000 size 1000 virt fc flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msisip.dll" section .xdata at 0x364877000 off 7000 size 1000 virt fc flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msisip.dll" section .bss at 0x364878000 off 0 size 0 virt 140 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msisip.dll" section .edata at 0x364879000 off 8000 size 1000 virt 39e flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msisip.dll" section .idata at 0x36487a000 off 9000 size 1000 virt 478 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msisip.dll" section .reloc at 0x36487b000 off a000 size 1000 virt 20 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"crypt32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\crypt32.dll" for L"crypt32.dll" at 00000001DD3F0000, count=5 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=17 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msisip.dll" 0000000000464AD0 0000000364870000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msisip.dll" at 0000000364870000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msisip.dll" at 0000000364870000 00d8:00dc:trace:module:process_attach (L"msisip.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (0000000364870000 L"msisip.dll",PROCESS_ATTACH,0000000000000000) 0000000364871AA0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000364870000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"msisip.dll",0000000000000000) - END 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\qcap.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\qcap.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"qcap.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\qcap.dll" at 0x24a370000-0x24a3b4000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qcap.dll" section .text at 0x24a371000 off 1000 size 14000 virt 13cb0 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qcap.dll" section .data at 0x24a385000 off 15000 size 1000 virt 1f0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qcap.dll" section .rodata at 0x24a386000 off 16000 size 1000 virt 18 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qcap.dll" section .rdata at 0x24a387000 off 17000 size 13000 virt 12ea0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qcap.dll" section .pdata at 0x24a39a000 off 2a000 size 2000 virt 126c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qcap.dll" section .xdata at 0x24a39c000 off 2c000 size 2000 virt 1140 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qcap.dll" section .bss at 0x24a39e000 off 0 size 0 virt 180 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qcap.dll" section .edata at 0x24a39f000 off 2e000 size 12000 virt 11761 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qcap.dll" section .idata at 0x24a3b1000 off 40000 size 1000 virt b1c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qcap.dll" section .rsrc at 0x24a3b2000 off 41000 size 1000 virt 9b0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qcap.dll" section .reloc at 0x24a3b3000 off 42000 size 1000 virt bc4 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=18 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"oleaut32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\oleaut32.dll" for L"oleaut32.dll" at 00000002739C0000, count=6 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\qcap.dll" 0000000000464D80 000000024A370000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\qcap.dll" at 000000024A370000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\qcap.dll" at 000000024A370000 00d8:00dc:trace:module:process_attach (L"qcap.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (000000024A370000 L"qcap.dll",PROCESS_ATTACH,0000000000000000) 000000024A383D80 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000024A370000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"qcap.dll",0000000000000000) - END 00d8:00dc:trace:module:EnumResourceNamesExW 000000024A370000 L"WINE_REGISTRY" 000000024A384810 31d060 00d8:00dc:trace:module:FindResourceExW 000000024A370000 L"WINE_REGISTRY" L"QCAP_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 000000024A370000 000000024A3B2080 00d8:00dc:trace:module:load_dll looking for L"atl100.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\atl100.dll" for L"atl100.dll" at 00000001C1EF0000, count=7 00d8:00dc:trace:module:LdrGetDllFullName module 000000024A370000, name 000000000031C990. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\qcap.dll" 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C9F0 260) 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\qedit.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\qedit.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"qedit.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\qedit.dll" at 0x38f0b0000-0x38f0f1000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qedit.dll" section .text at 0x38f0b1000 off 1000 size 12000 virt 11240 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qedit.dll" section .data at 0x38f0c3000 off 13000 size 1000 virt 110 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qedit.dll" section .rodata at 0x38f0c4000 off 14000 size 1000 virt 18 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qedit.dll" section .rdata at 0x38f0c5000 off 15000 size 13000 virt 12460 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qedit.dll" section .pdata at 0x38f0d8000 off 28000 size 2000 virt 1164 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qedit.dll" section .xdata at 0x38f0da000 off 2a000 size 1000 virt fe8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qedit.dll" section .bss at 0x38f0db000 off 0 size 0 virt 190 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qedit.dll" section .edata at 0x38f0dc000 off 2b000 size 12000 virt 11797 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qedit.dll" section .idata at 0x38f0ee000 off 3d000 size 1000 virt 95c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qedit.dll" section .rsrc at 0x38f0ef000 off 3e000 size 1000 virt 708 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\qedit.dll" section .reloc at 0x38f0f0000 off 3f000 size 1000 virt aa4 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=19 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"oleaut32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\oleaut32.dll" for L"oleaut32.dll" at 00000002739C0000, count=7 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\qedit.dll" 0000000000465070 000000038F0B0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\qedit.dll" at 000000038F0B0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\qedit.dll" at 000000038F0B0000 00d8:00dc:trace:module:process_attach (L"qedit.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (000000038F0B0000 L"qedit.dll",PROCESS_ATTACH,0000000000000000) 000000038F0C1430 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000038F0B0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"qedit.dll",0000000000000000) - END 00d8:00dc:trace:module:EnumResourceNamesExW 000000038F0B0000 L"WINE_REGISTRY" 000000038F0C1E90 31d060 00d8:00dc:trace:module:FindResourceExW 000000038F0B0000 L"WINE_REGISTRY" L"QEDIT_CLASSES_R_RES" 0000 00d8:00dc:trace:module:LoadResource 000000038F0B0000 000000038F0EF080 00d8:00dc:trace:module:load_dll looking for L"atl100.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\atl100.dll" for L"atl100.dll" at 00000001C1EF0000, count=8 00d8:00dc:trace:module:LdrGetDllFullName module 000000038F0B0000, name 000000000031C990. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\qedit.dll" 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C9F0 260) 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\urlmon.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\urlmon.dll" for L"C:\\windows\\system32\\urlmon.dll" at 00000003422E0000, count=2 00d8:00dc:trace:module:EnumResourceNamesExW 00000003422E0000 L"WINE_REGISTRY" 0000000342335450 31d060 00d8:00dc:trace:module:FindResourceExW 00000003422E0000 L"WINE_REGISTRY" L"URLMON_URLMON_R_RES" 0000 00d8:00dc:trace:module:LoadResource 00000003422E0000 000000034236C328 00d8:00dc:trace:module:load_dll looking for L"atl100.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\atl100.dll" for L"atl100.dll" at 00000001C1EF0000, count=9 00d8:00dc:trace:module:LdrGetDllFullName module 00000003422E0000, name 000000000031C990. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\urlmon.dll" 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C9F0 260) 00d8:00dc:trace:module:FindResourceExW 00000003422E0000 L"WINE_REGISTRY" #0001 0000 00d8:00dc:trace:module:LoadResource 00000003422E0000 000000034236C338 00d8:00dc:trace:module:load_dll looking for L"advpack.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\advpack.dll" 00d8:00dc:trace:module:get_load_order_value got environment b for L"advpack" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\advpack.dll" at 0x1d1cc0000-0x1d1cd6000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .text at 0x1d1cc1000 off 1000 size a000 virt 9f00 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .data at 0x1d1ccb000 off b000 size 1000 virt a0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .rodata at 0x1d1ccc000 off c000 size 1000 virt 1d4 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .rdata at 0x1d1ccd000 off d000 size 2000 virt 1130 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .pdata at 0x1d1ccf000 off f000 size 1000 virt 51c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .xdata at 0x1d1cd0000 off 10000 size 1000 virt 6d0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .bss at 0x1d1cd1000 off 0 size 0 virt 160 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .edata at 0x1d1cd2000 off 11000 size 1000 virt ff7 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .idata at 0x1d1cd3000 off 12000 size 2000 virt 1004 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .reloc at 0x1d1cd5000 off 14000 size 1000 virt 24 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=20 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"setupapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\setupapi.dll" for L"setupapi.dll" at 000000021A7E0000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"version.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\version.dll" for L"version.dll" at 00000002F1FA0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advpack.dll" 0000000000465360 00000001D1CC0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advpack.dll" at 00000001D1CC0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advpack.dll" at 00000001D1CC0000 00d8:00dc:trace:module:process_attach (L"advpack.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000001D1CC0000 L"advpack.dll",PROCESS_ATTACH,0000000000000000) 00000001D1CCA2E0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000001D1CC0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"advpack.dll",0000000000000000) - END 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031CDA0, base 000000000031CD98. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031CAA0, base 000000000031CA98. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:process:GetEnvironmentVariableW (L"TMP" 000000000031C4D0 260) 00d8:00dc:trace:process:GetEnvironmentVariableW (L"TEMP" 000000000031C4D0 260) 00d8:00dc:trace:process:GetEnvironmentVariableW (L"USERPROFILE" 000000000031C4D0 260) 00d8:00dc:trace:module:FindResourceExW 00000003422E0000 L"REGINST" L"REGINST" 0000 00d8:00dc:trace:module:LoadResource 00000003422E0000 000000034236C318 00d8:00dc:trace:module:LdrGetDllFullName module 00000003422E0000, name 000000000031C6D0. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\urlmon.dll" 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C960 260) 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\windowscodecs.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\windowscodecs.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"windowscodecs.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\windowscodecs.dll" at 0x361860000-0x3619ec000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\windowscodecs.dll" section .text at 0x361861000 off 1000 size fd000 virt fc860 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\windowscodecs.dll" section .data at 0x36195e000 off fe000 size 2000 virt 1080 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\windowscodecs.dll" section .rodata at 0x361960000 off 100000 size 1000 virt 29c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\windowscodecs.dll" section .rdata at 0x361961000 off 101000 size 50000 virt 4f790 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\windowscodecs.dll" section .pdata at 0x3619b1000 off 151000 size a000 virt 9348 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\windowscodecs.dll" section .xdata at 0x3619bb000 off 15b000 size a000 virt 92c0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\windowscodecs.dll" section .bss at 0x3619c5000 off 0 size 0 virt 3b0 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\windowscodecs.dll" section .edata at 0x3619c6000 off 165000 size 1d000 virt 1c3b5 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\windowscodecs.dll" section .idata at 0x3619e3000 off 182000 size 3000 virt 2280 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\windowscodecs.dll" section .rsrc at 0x3619e6000 off 185000 size 3000 virt 2ec0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\windowscodecs.dll" section .reloc at 0x3619e9000 off 188000 size 3000 virt 2014 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=21 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"oleaut32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\oleaut32.dll" for L"oleaut32.dll" at 00000002739C0000, count=8 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"propsys.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\propsys.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"propsys.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\propsys.dll" at 0x228450000-0x22847b000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\propsys.dll" section .text at 0x228451000 off 1000 size 8000 virt 7dc0 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\propsys.dll" section .data at 0x228459000 off 9000 size 1000 virt a0 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\propsys.dll" section .rodata at 0x22845a000 off a000 size 2000 virt 15ac flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\propsys.dll" section .rdata at 0x22845c000 off c000 size 8000 virt 7f80 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\propsys.dll" section .pdata at 0x228464000 off 14000 size 1000 virt 4f8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\propsys.dll" section .xdata at 0x228465000 off 15000 size 1000 virt 4e0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\propsys.dll" section .bss at 0x228466000 off 0 size 0 virt 150 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\propsys.dll" section .edata at 0x228467000 off 16000 size 11000 virt 10369 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\propsys.dll" section .idata at 0x228478000 off 27000 size 1000 virt 978 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\propsys.dll" section .rsrc at 0x228479000 off 28000 size 1000 virt 1a8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\propsys.dll" section .reloc at 0x22847a000 off 29000 size 1000 virt 134 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=22 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"oleaut32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\oleaut32.dll" for L"oleaut32.dll" at 00000002739C0000, count=9 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\propsys.dll" 0000000000465B20 0000000228450000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\propsys.dll" at 0000000228450000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\propsys.dll" at 0000000228450000 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"rpcrt4.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=7 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"shlwapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=8 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\windowscodecs.dll" 0000000000465750 0000000361860000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\windowscodecs.dll" at 0000000361860000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\windowscodecs.dll" at 0000000361860000 00d8:00dc:trace:module:process_attach (L"windowscodecs.dll",0000000000000000) - START 00d8:00dc:trace:module:process_attach (L"propsys.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (0000000228450000 L"propsys.dll",PROCESS_ATTACH,0000000000000000) 0000000228457F30 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000228450000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"propsys.dll",0000000000000000) - END 00d8:00dc:trace:module:MODULE_InitDLL (0000000361860000 L"windowscodecs.dll",PROCESS_ATTACH,0000000000000000) 000000036195C510 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000361860000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"windowscodecs.dll",0000000000000000) - END 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C9E0, base 000000000031C9D8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:EnumResourceNamesExW 0000000361860000 L"WINE_REGISTRY" 000000036195D140 31cef0 00d8:00dc:trace:module:FindResourceExW 0000000361860000 L"WINE_REGISTRY" L"WINDOWSCODECS_WINCODEC_R_RES" 0000 00d8:00dc:trace:module:LoadResource 0000000361860000 00000003619E6080 00d8:00dc:trace:module:load_dll looking for L"atl100.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\atl100.dll" for L"atl100.dll" at 00000001C1EF0000, count=10 00d8:00dc:trace:module:LdrGetDllFullName module 0000000361860000, name 000000000031C820. 00d8:00dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\windowscodecs.dll" 00d8:00dc:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031C880 260) 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\winegstreamer.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:warn:module:load_dll Failed to load module L"C:\\windows\\system32\\winegstreamer.dll"; status=c0000135 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\wineqtdecoder.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:warn:module:load_dll Failed to load module L"C:\\windows\\system32\\wineqtdecoder.dll"; status=c0000135 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\winevulkan.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\winevulkan.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"winevulkan.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\winevulkan.dll" at 0x3b6dc0000-0x3b6dec000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winevulkan.dll" section .text at 0x3b6dc1000 off 1000 size 12000 virt 11b40 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winevulkan.dll" section .data at 0x3b6dd3000 off 13000 size 1000 virt 80 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winevulkan.dll" section .rodata at 0x3b6dd4000 off 14000 size 1000 virt 518 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winevulkan.dll" section .rdata at 0x3b6dd5000 off 15000 size 7000 virt 6a90 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winevulkan.dll" section .pdata at 0x3b6ddc000 off 1c000 size 2000 virt 19e0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winevulkan.dll" section .xdata at 0x3b6dde000 off 1e000 size 2000 virt 123c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winevulkan.dll" section .bss at 0x3b6de0000 off 0 size 0 virt 170 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winevulkan.dll" section .edata at 0x3b6de1000 off 20000 size 8000 virt 7f6a flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winevulkan.dll" section .idata at 0x3b6de9000 off 28000 size 1000 virt 8e4 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winevulkan.dll" section .rsrc at 0x3b6dea000 off 29000 size 1000 virt 490 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winevulkan.dll" section .reloc at 0x3b6deb000 off 2a000 size 1000 virt 85c flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"setupapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\setupapi.dll" for L"setupapi.dll" at 000000021A7E0000, count=3 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"win32u.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AC60000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\winevulkan.dll" 0000000000465E40 00000003B6DC0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\winevulkan.dll" at 00000003B6DC0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\winevulkan.dll" at 00000003B6DC0000 00d8:00dc:trace:module:process_attach (L"winevulkan.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000003B6DC0000 L"winevulkan.dll",PROCESS_ATTACH,0000000000000000) 00000003B6DD1FA0 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C6C0, base 000000000031C6B8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (00000003B6DC0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"winevulkan.dll",0000000000000000) - END 00d8:00dc:trace:module:FindResourceExW 00000003B6DC0000 #000a L"winevulkan_json" 0000 00d8:00dc:trace:module:LoadResource 00000003B6DC0000 00000003B6DEA080 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\wintrust.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\wintrust.dll" for L"C:\\windows\\system32\\wintrust.dll" at 00000001FDFD0000, count=2 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C9B0, base 000000000031C9A8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (0000000330260000, 0000000330284E00, 0000000000000000, 000000007B60C498, 000000033029B128, 0x00000000) 00d8:00dc:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=8 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031CC80, base 000000000031CC78. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C930, base 000000000031C928. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\rsaenh.dll" 0000000000000000 0) 00d8:00dc:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\rsaenh.dll" 00000000004661C0 31) 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\rsaenh.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\rsaenh.dll" 00d8:00dc:trace:module:get_load_order got hardcoded default for L"rsaenh.dll" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\rsaenh.dll" at 0x2de970000-0x2de9a2000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .text at 0x2de971000 off 1000 size 16000 virt 15700 flags 60000020 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .data at 0x2de987000 off 17000 size 1000 virt 80 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .rodata at 0x2de988000 off 18000 size 1000 virt 8c flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .rdata at 0x2de989000 off 19000 size 12000 virt 114e0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .pdata at 0x2de99b000 off 2b000 size 1000 virt 840 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .xdata at 0x2de99c000 off 2c000 size 1000 virt a8c flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .bss at 0x2de99d000 off 0 size 0 virt 190 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .edata at 0x2de99e000 off 2d000 size 1000 virt df8 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .idata at 0x2de99f000 off 2e000 size 1000 virt adc flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .rsrc at 0x2de9a0000 off 2f000 size 1000 virt fc8 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .reloc at 0x2de9a1000 off 30000 size 1000 virt 24 flags 42000040 00d8:00dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"bcrypt.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\bcrypt.dll" for L"bcrypt.dll" at 00000002D4D40000, count=2 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"crypt32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\crypt32.dll" for L"crypt32.dll" at 00000001DD3F0000, count=6 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00d8:00dc:trace:module:import_dll is not hybrid module 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rsaenh.dll" 0000000000466490 00000002DE970000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rsaenh.dll" at 00000002DE970000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\rsaenh.dll" at 00000002DE970000 00d8:00dc:trace:module:process_attach (L"rsaenh.dll",0000000000000000) - START 00d8:00dc:trace:module:MODULE_InitDLL (00000002DE970000 L"rsaenh.dll",PROCESS_ATTACH,0000000000000000) 00000002DE9858F0 - CALL 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C4A0, base 000000000031C498. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:MODULE_InitDLL (00000002DE970000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:process_attach (L"rsaenh.dll",0000000000000000) - END 00d8:00dc:trace:module:LdrUnloadDll (00000002DE970000) 00d8:00dc:trace:module:LdrUnloadDll (L"rsaenh.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"rsaenh.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"bcrypt.dll") ldr.LoadCount: 1 00d8:00dc:trace:module:MODULE_DecRefCount (L"crypt32.dll") ldr.LoadCount: 5 00d8:00dc:trace:module:MODULE_InitDLL (00000002DE970000 L"rsaenh.dll",PROCESS_DETACH,0000000000000000) 00000002DE9858F0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000002DE970000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\rsaenh.dll" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:load_dll looking for L"C:\\windows\\system32\\iexplore.exe" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00d8:00dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\iexplore.exe" 00d8:00dc:trace:module:get_load_order_value got environment b for L"*iexplore.exe" 00d8:00dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\iexplore.exe" at 0x11a0000-0x11c0000 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .text at 0x11a1000 off 1000 size 2000 virt 10c0 flags 60000060 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .data at 0x11a3000 off 3000 size 1000 virt 60 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .rdata at 0x11a4000 off 4000 size 1000 virt 290 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .pdata at 0x11a5000 off 5000 size 1000 virt f0 flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .xdata at 0x11a6000 off 6000 size 1000 virt ec flags 40000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .bss at 0x11a7000 off 0 size 0 virt 140 flags c0000080 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .idata at 0x11a8000 off 7000 size 1000 virt 704 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .rsrc at 0x11a9000 off 8000 size 16000 virt 15410 flags c0000040 00d8:00dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .reloc at 0x11bf000 off 1e000 size 1000 virt 28 flags 42000040 00d8:00dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\iexplore.exe" 00000000004661C0 00000000011A0000 00d8:00dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\iexplore.exe" at 00000000011A0000: builtin 00d8:00dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\iexplore.exe" at 00000000011A0000 00d8:00dc:trace:module:LdrUnloadDll (00000000011A0000) 00d8:00dc:trace:module:LdrUnloadDll (L"iexplore.exe") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"iexplore.exe") ldr.LoadCount: 0 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\iexplore.exe" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:process:CreateProcessInternalW app L"C:\\windows\\system32\\iexplore.exe" cmdline L"\"C:\\windows\\system32\\iexplore.exe\" /RegServer" 00d8:00dc:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\iexplore.exe" image L"C:\\windows\\system32\\iexplore.exe" cmdline L"\"C:\\windows\\system32\\iexplore.exe\" /RegServer" parent 0x0 00d8:00dc:trace:process:send_to_cx_loader loader (null) wineserversocket 15 stdin_fd -1 stdout_fd -1 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 00d8:00dc:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\iexplore.exe" 00e0:00e4:trace:module:get_load_order_value got environment b for L"*iexplore.exe" 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\iexplore.exe" 00e0:00e4:trace:module:get_load_order_value got environment b for L"*iexplore.exe" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\iexplore.exe" at 0x140000000-0x140020000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .text at 0x140001000 off 1000 size 2000 virt 10c0 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .data at 0x140003000 off 3000 size 1000 virt 60 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .rdata at 0x140004000 off 4000 size 1000 virt 290 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .pdata at 0x140005000 off 5000 size 1000 virt f0 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .xdata at 0x140006000 off 6000 size 1000 virt ec flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .bss at 0x140007000 off 0 size 0 virt 140 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .idata at 0x140008000 off 7000 size 1000 virt 704 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .rsrc at 0x140009000 off 8000 size 16000 virt 15410 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\iexplore.exe" section .reloc at 0x14001f000 off 1e000 size 1000 virt 28 flags 42000040 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 00e0:00e4:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 00d8:00dc:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\iexplore.exe" pid 00e0 tid 00e4 handles 0xa0/0xa4 00d8:00dc:trace:process:CreateProcessInternalW started process pid 00e0 tid 00e4 00e0:00e4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\iexplore.exe" 00000000004320E0 0000000140000000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\iexplore.exe" at 0000000140000000: builtin 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernel32.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"kernel32.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernelbase.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"kernelbase.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 0000000000432960 000000007B000000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000432640 000000007B600000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 00e0:00e4:trace:module:load_dll looking for L"ieframe.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\ieframe.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"ieframe.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ieframe.dll" at 0x1ce210000-0x1ce291000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ieframe.dll" section .text at 0x1ce211000 off 1000 size 2e000 virt 2d110 flags 60000020 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ieframe.dll" section .data at 0x1ce23f000 off 2f000 size 1000 virt 2c0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ieframe.dll" section .rodata at 0x1ce240000 off 30000 size 1000 virt 30 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ieframe.dll" section .rdata at 0x1ce241000 off 31000 size 17000 virt 163a0 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ieframe.dll" section .pdata at 0x1ce258000 off 48000 size 3000 virt 2a54 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ieframe.dll" section .xdata at 0x1ce25b000 off 4b000 size 3000 virt 248c flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ieframe.dll" section .bss at 0x1ce25e000 off 0 size 0 virt 1d0 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ieframe.dll" section .edata at 0x1ce25f000 off 4e000 size d000 virt ca9d flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ieframe.dll" section .idata at 0x1ce26c000 off 5b000 size 2000 virt 1b20 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ieframe.dll" section .rsrc at 0x1ce26e000 off 5d000 size 22000 virt 21660 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ieframe.dll" section .reloc at 0x1ce290000 off 7f000 size 1000 virt d08 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\advapi32.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"advapi32.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"msvcrt.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvcrt.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"msvcrt.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 00000000004330F0 00000001C8DB0000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"sechost.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\sechost.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"sechost.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\ucrtbase.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"ucrtbase.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 0000000000433680 00000003AF670000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 0000000000433390 000000032A700000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 0000000000432DE0 0000000330260000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"comctl32.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\comctl32.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"comctl32.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\comctl32.dll" at 0x2bb750000-0x2bb88f000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .text at 0x2bb751000 off 1000 size ae000 virt ad9d0 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .data at 0x2bb7ff000 off af000 size 1000 virt 300 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .rodata at 0x2bb800000 off b0000 size 1000 virt 734 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .rdata at 0x2bb801000 off b1000 size 1f000 virt 1ef80 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .pdata at 0x2bb820000 off d0000 size 4000 virt 3198 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .xdata at 0x2bb824000 off d4000 size 5000 virt 40a8 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .bss at 0x2bb829000 off 0 size 0 virt 1720 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .edata at 0x2bb82b000 off d9000 size f000 virt eff3 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .idata at 0x2bb83a000 off e8000 size 4000 virt 3b2c flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .rsrc at 0x2bb83e000 off ec000 size 50000 virt 4fad8 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comctl32.dll" section .reloc at 0x2bb88e000 off 13c000 size 1000 virt 1d4 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"gdi32.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\gdi32.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"gdi32.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"user32.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\user32.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"user32.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=4 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"gdi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"sechost.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"version.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\version.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"version.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 00000000004342D0 00000002F1FA0000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 00000002F1FA0000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 00000002F1FA0000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"win32u.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\win32u.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"win32u.dll" 00e0:00e4:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\win32u.dll" is a fake Wine dll 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\win32u.dll" 00000000004345F0 000000006AC60000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\win32u.dll" at 000000006AC60000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\win32u.dll" at 000000006AC60000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\user32.dll" 0000000000433EF0 000000023D820000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\user32.dll" at 000000023D820000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\user32.dll" at 000000023D820000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"win32u.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AC60000, count=2 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\gdi32.dll" 0000000000433BD0 000000026B4C0000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"imm32.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\imm32.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"imm32.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=5 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"user32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imm32.dll" 00000000004348D0 00000003AFD00000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imm32.dll" at 00000003AFD00000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imm32.dll" at 00000003AFD00000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=11 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=6 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=13 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=6 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"user32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=3 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\comctl32.dll" 0000000000433850 00000002BB750000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\comctl32.dll" at 00000002BB750000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\comctl32.dll" at 00000002BB750000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"gdi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=12 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=14 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ole32.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\ole32.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"ole32.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" at 0x2e8f10000-0x2e902b000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .text at 0x2e8f11000 off 1000 size a8000 virt a76a0 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .data at 0x2e8fb9000 off a9000 size 1000 virt 480 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rodata at 0x2e8fba000 off aa000 size 1000 virt 778 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rdata at 0x2e8fbb000 off ab000 size 1e000 virt 1d750 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .pdata at 0x2e8fd9000 off c9000 size 7000 virt 6b10 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .xdata at 0x2e8fe0000 off d0000 size 7000 virt 67c4 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .bss at 0x2e8fe7000 off 0 size 0 virt 210 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .edata at 0x2e8fe8000 off d7000 size 18000 virt 17412 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .idata at 0x2e9000000 off ef000 size 4000 virt 367c flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rsrc at 0x2e9004000 off f3000 size 25000 virt 24bc0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .reloc at 0x2e9029000 off 118000 size 2000 virt 1804 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=6 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"combase.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\combase.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"combase.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" at 0x327020000-0x327073000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .text at 0x327021000 off 1000 size 27000 virt 26590 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .data at 0x327048000 off 28000 size 1000 virt 580 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rodata at 0x327049000 off 29000 size 2000 virt 16c0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rdata at 0x32704b000 off 2b000 size d000 virt cf90 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .pdata at 0x327058000 off 38000 size 2000 virt 17a0 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .xdata at 0x32705a000 off 3a000 size 2000 virt 18e4 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .bss at 0x32705c000 off 0 size 0 virt 1a0 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .edata at 0x32705d000 off 3c000 size 13000 virt 12d6e flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .idata at 0x327070000 off 4f000 size 2000 virt 1804 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .reloc at 0x327072000 off 51000 size 1000 virt 23c flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=7 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"gdi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=3 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=13 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=15 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ole32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\rpcrt4.dll" 00e0:00e4:trace:module:get_load_order_value got environment b for L"rpcrt4" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0x231ae0000-0x231b62000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .text at 0x231ae1000 off 1000 size 47000 virt 46400 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .data at 0x231b28000 off 48000 size 1000 virt 710 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rodata at 0x231b29000 off 49000 size 2000 virt 1b44 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rdata at 0x231b2b000 off 4b000 size 15000 virt 14b90 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .pdata at 0x231b40000 off 60000 size 3000 virt 2334 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .xdata at 0x231b43000 off 63000 size 3000 virt 289c flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .bss at 0x231b46000 off 0 size 0 virt 690 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .edata at 0x231b47000 off 66000 size 17000 virt 16730 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .idata at 0x231b5e000 off 7d000 size 2000 virt 19a8 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rsrc at 0x231b60000 off 7f000 size 1000 virt 3a8 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .reloc at 0x231b61000 off 80000 size 1000 virt 504 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=8 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=14 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=16 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=7 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rpcrt4.dll" 0000000000435330 0000000231AE0000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=8 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"user32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=4 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\combase.dll" 0000000000434FD0 0000000327020000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\combase.dll" at 0000000327020000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\combase.dll" at 0000000327020000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"gdi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=4 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=15 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=7 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=17 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=2 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=9 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"user32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=5 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ole32.dll" 0000000000434CF0 00000002E8F10000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ole32.dll" at 00000002E8F10000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ole32.dll" at 00000002E8F10000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"oleaut32.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\oleaut32.dll" 00e0:00e4:trace:module:get_load_order_value got environment b for L"oleaut32" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" at 0x2739c0000-0x273af6000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .text at 0x2739c1000 off 1000 size ab000 virt aa720 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .data at 0x273a6c000 off ac000 size 2000 virt 1100 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rodata at 0x273a6e000 off ae000 size 1000 virt 984 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rdata at 0x273a6f000 off af000 size 1f000 virt 1e700 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .pdata at 0x273a8e000 off ce000 size 6000 virt 57e4 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .xdata at 0x273a94000 off d4000 size 6000 virt 50e4 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .bss at 0x273a9a000 off 0 size 0 virt 38230 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .edata at 0x273ad3000 off da000 size 19000 virt 18c59 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .idata at 0x273aec000 off f3000 size 3000 virt 2aa0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rsrc at 0x273aef000 off f6000 size 5000 virt 4ee0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .reloc at 0x273af4000 off fb000 size 2000 virt 14e4 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=9 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"gdi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=5 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=16 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=18 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ole32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=3 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=10 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"user32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=6 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\oleaut32.dll" 0000000000435820 00000002739C0000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\oleaut32.dll" at 00000002739C0000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\oleaut32.dll" at 00000002739C0000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"shell32.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\shell32.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"shell32.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" at 0x1c69e0000-0x1c72fe000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .text at 0x1c69e1000 off 1000 size 89000 virt 88c60 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .data at 0x1c6a6a000 off 8a000 size 2000 virt 13e0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rodata at 0x1c6a6c000 off 8c000 size 2000 virt 18ec flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rdata at 0x1c6a6e000 off 8e000 size 29000 virt 28e90 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .pdata at 0x1c6a97000 off b7000 size 6000 virt 5748 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .xdata at 0x1c6a9d000 off bd000 size 6000 virt 5c20 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .bss at 0x1c6aa3000 off 0 size 0 virt 570 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .edata at 0x1c6aa4000 off c3000 size 15000 virt 14070 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .idata at 0x1c6ab9000 off d8000 size 5000 virt 4aa0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rsrc at 0x1c6abe000 off dd000 size 83e000 virt 83d918 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .reloc at 0x1c72fc000 off 91b000 size 2000 virt 1264 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=10 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"gdi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=6 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=17 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=19 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"shlwapi.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\shlwapi.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"shlwapi.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" at 0x2e3540000-0x2e3591000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .text at 0x2e3541000 off 1000 size 1e000 virt 1dac0 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .data at 0x2e355f000 off 1f000 size 1000 virt 210 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rodata at 0x2e3560000 off 20000 size 2000 virt 18fc flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rdata at 0x2e3562000 off 22000 size b000 virt a290 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .pdata at 0x2e356d000 off 2d000 size 2000 virt 11b8 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .xdata at 0x2e356f000 off 2f000 size 2000 virt 13a8 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .bss at 0x2e3571000 off 0 size 0 virt 1c0 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .edata at 0x2e3572000 off 31000 size 14000 virt 13ab5 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .idata at 0x2e3586000 off 45000 size 5000 virt 442c flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rsrc at 0x2e358b000 off 4a000 size 5000 virt 4ed0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .reloc at 0x2e3590000 off 4f000 size 1000 virt e0 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=11 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"gdi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=7 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=18 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=8 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=20 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"shcore.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\shcore.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"shcore.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" at 0x3126f0000-0x312709000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .text at 0x3126f1000 off 1000 size 9000 virt 8b70 flags 60000020 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .data at 0x3126fa000 off a000 size 1000 virt b0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rodata at 0x3126fb000 off b000 size 1000 virt fb4 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rdata at 0x3126fc000 off c000 size 3000 virt 2360 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .pdata at 0x3126ff000 off f000 size 1000 virt 57c flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .xdata at 0x312700000 off 10000 size 1000 virt 61c flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .bss at 0x312701000 off 0 size 0 virt 160 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .edata at 0x312702000 off 11000 size 5000 virt 480e flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .idata at 0x312707000 off 16000 size 1000 virt c74 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .reloc at 0x312708000 off 17000 size 1000 virt a8 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=12 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=19 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=21 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ole32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=3 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=11 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"user32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=7 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shcore.dll" 00000000004362B0 00000003126F0000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shcore.dll" at 00000003126F0000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shcore.dll" at 00000003126F0000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=12 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"user32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=8 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shlwapi.dll" 0000000000435F50 00000002E3540000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shlwapi.dll" at 00000002E3540000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shlwapi.dll" at 00000002E3540000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=13 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"user32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=9 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shell32.dll" 0000000000435C70 00000001C69E0000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shell32.dll" at 00000001C69E0000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shell32.dll" at 00000001C69E0000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"shlwapi.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=2 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=14 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"urlmon.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\urlmon.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"urlmon.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\urlmon.dll" at 0x3422e0000-0x34237c000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .text at 0x3422e1000 off 1000 size 55000 virt 54af0 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .data at 0x342336000 off 56000 size 1000 virt 760 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .rodata at 0x342337000 off 57000 size 1000 virt 948 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .rdata at 0x342338000 off 58000 size 17000 virt 164e0 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .pdata at 0x34234f000 off 6f000 size 4000 virt 34ec flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .xdata at 0x342353000 off 73000 size 4000 virt 3484 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .bss at 0x342357000 off 0 size 0 virt 1f0 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .edata at 0x342358000 off 77000 size 11000 virt 1037c flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .idata at 0x342369000 off 88000 size 3000 virt 27ec flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .rsrc at 0x34236c000 off 8b000 size f000 virt e468 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\urlmon.dll" section .reloc at 0x34237b000 off 9a000 size 1000 virt acc flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=13 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=20 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=22 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ole32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=4 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"oleaut32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\oleaut32.dll" for L"oleaut32.dll" at 00000002739C0000, count=2 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=4 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"shell32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=2 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"shlwapi.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=3 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=15 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"user32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=10 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"wininet.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\wininet.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"wininet.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\wininet.dll" at 0x3a0440000-0x3a04c3000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .text at 0x3a0441000 off 1000 size 47000 virt 46520 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .data at 0x3a0488000 off 48000 size 1000 virt 450 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .rodata at 0x3a0489000 off 49000 size 1000 virt 854 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .rdata at 0x3a048a000 off 4a000 size c000 virt b330 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .pdata at 0x3a0496000 off 56000 size 2000 virt 19b0 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .xdata at 0x3a0498000 off 58000 size 2000 virt 1ebc flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .bss at 0x3a049a000 off 0 size 0 virt 1e0 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .edata at 0x3a049b000 off 5a000 size 5000 virt 49b6 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .idata at 0x3a04a0000 off 5f000 size 2000 virt 1ec8 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .rsrc at 0x3a04a2000 off 61000 size 20000 virt 1f3e8 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wininet.dll" section .reloc at 0x3a04c2000 off 81000 size 1000 virt 300 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=14 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=21 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"mpr.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\mpr.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"mpr.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\mpr.dll" at 0x24f470000-0x24f48f000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .text at 0x24f471000 off 1000 size b000 virt a4a0 flags 60000020 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .data at 0x24f47c000 off c000 size 1000 virt c0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .rodata at 0x24f47d000 off d000 size 1000 virt 31c flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .rdata at 0x24f47e000 off e000 size 2000 virt 14a0 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .pdata at 0x24f480000 off 10000 size 1000 virt 654 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .xdata at 0x24f481000 off 11000 size 1000 virt 6d4 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .bss at 0x24f482000 off 0 size 0 virt 160 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .edata at 0x24f483000 off 12000 size 2000 virt 19e3 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .idata at 0x24f485000 off 14000 size 1000 virt a00 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .rsrc at 0x24f486000 off 15000 size 8000 virt 77c0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\mpr.dll" section .reloc at 0x24f48e000 off 1d000 size 1000 virt 20 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=15 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=22 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=23 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=16 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"user32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=11 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\mpr.dll" 0000000000436F40 000000024F470000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\mpr.dll" at 000000024F470000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\mpr.dll" at 000000024F470000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=24 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"shell32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=3 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"shlwapi.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=4 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=17 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"user32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=12 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ws2_32.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\ws2_32.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"ws2_32.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" at 0x1ec2b0000-0x1ec2d6000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .text at 0x1ec2b1000 off 1000 size 13000 virt 12500 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .data at 0x1ec2c4000 off 14000 size 1000 virt 1b0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rodata at 0x1ec2c5000 off 15000 size 1000 virt 85c flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rdata at 0x1ec2c6000 off 16000 size 5000 virt 4990 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .pdata at 0x1ec2cb000 off 1b000 size 1000 virt 954 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .xdata at 0x1ec2cc000 off 1c000 size 1000 virt a3c flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .bss at 0x1ec2cd000 off 0 size 0 virt 170 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .edata at 0x1ec2ce000 off 1d000 size 3000 virt 23c6 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .idata at 0x1ec2d1000 off 20000 size 1000 virt c14 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rsrc at 0x1ec2d2000 off 21000 size 3000 virt 29b8 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .reloc at 0x1ec2d5000 off 24000 size 1000 virt 70 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=23 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=25 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=18 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ws2_32.dll" 00000000004373D0 00000001EC2B0000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ws2_32.dll" at 00000001EC2B0000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ws2_32.dll" at 00000001EC2B0000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wininet.dll" 0000000000436C70 00000003A0440000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wininet.dll" at 00000003A0440000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wininet.dll" at 00000003A0440000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\urlmon.dll" 00000000004367D0 00000003422E0000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\urlmon.dll" at 00000003422E0000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\urlmon.dll" at 00000003422E0000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"user32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=13 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ieframe.dll" 0000000000432B30 00000001CE210000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ieframe.dll" at 00000001CE210000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ieframe.dll" at 00000001CE210000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=24 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=26 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=19 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 00e0:00e4:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 00e0:00e4:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 00e0:00e4:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 00e0:00e4:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 00e0:00e4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 00e0:00e4:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 00e0:00e4:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 00e0:00e4:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 00e0:00e4:trace:module:process_attach (L"ieframe.dll",000000000031FB00) - START 00e0:00e4:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 00e0:00e4:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 00e0:00e4:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 00e0:00e4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 00e0:00e4:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\iexplore.exe" 00e0:00e4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 00e0:00e4:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\iexplore.exe" 00e0:00e4:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 00e0:00e4:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 00e0:00e4:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 00e0:00e4:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 00e0:00e4:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 00e0:00e4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F290. 00e0:00e4:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\iexplore.exe" 00e0:00e4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F2E0. 00e0:00e4:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\iexplore.exe" 00e0:00e4:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 00e0:00e4:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 00e0:00e4:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 00e0:00e4:trace:module:process_attach (L"comctl32.dll",000000000031FB00) - START 00e0:00e4:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - START 00e0:00e4:trace:module:process_attach (L"user32.dll",000000000031FB00) - START 00e0:00e4:trace:module:process_attach (L"version.dll",000000000031FB00) - START 00e0:00e4:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000031FB00) 00000002F1FA2510 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"version.dll",000000000031FB00) - END 00e0:00e4:trace:module:process_attach (L"win32u.dll",000000000031FB00) - START 00e0:00e4:trace:module:MODULE_InitDLL (000000006AC60000 L"win32u.dll",PROCESS_ATTACH,000000000031FB00) 000000006AD09460 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (000000006AC60000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"win32u.dll",000000000031FB00) - END 00e0:00e4:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000031FB00) 000000023D8C5690 - CALL 00e0:00e4:trace:module:load_dll looking for L"imm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\imm32.dll" for L"imm32.dll" at 00000003AFD00000, count=2 00e0:00e4:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 00e0:00e4:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EA90, base 000000000031EA88. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EF30, base 000000000031EF28. 00e0:00e4:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EA40, base 000000000031EA38. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00e0:00e4:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 00e0:00e4:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"user32.dll",000000000031FB00) - END 00e0:00e4:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000031FB00) 000000026B509F00 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - END 00e0:00e4:trace:module:MODULE_InitDLL (00000002BB750000 L"comctl32.dll",PROCESS_ATTACH,000000000031FB00) 00000002BB7FDA80 - CALL 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F090, base 000000000031F088. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F300, base 000000000031F2F8. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:module:load_dll looking for L"winemac.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\winemac.drv" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"winemac.drv" 00e0:00e4:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\winemac.drv" is a fake Wine dll 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"win32u.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AC60000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\winemac.drv" 000000000043F4B0 000000006DD10000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\winemac.drv" at 000000006DD10000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\winemac.drv" at 000000006DD10000 00e0:00e4:trace:module:process_attach (L"winemac.drv",0000000000000000) - START 00e0:00e4:trace:module:MODULE_InitDLL (000000006DD10000 L"winemac.drv",PROCESS_ATTACH,0000000000000000) 000000006DD28C10 - CALL 00e0:00e4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031B740. 00e0:00e4:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\iexplore.exe" 00e0:00e4:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 00e0:00e4:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 00e0:00e4:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 00e0:00e4:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 00e0:00e4:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 00e0:00e4:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 00e0:00e4:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 00e0:00e4:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 00e0:00e4:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 00e0:00e4:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 00e0:00e4:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 00e0:00e4:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 00e0:00e4:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 00e0:00e4:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 00e0:00e4:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 00e0:00e4:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 00e0:00e4:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 00e0:00e4:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 00e0:00e4:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 00e0:00e4:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 00e0:00e4:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 00e0:00e4:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 00e0:00e4:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 00e0:00e4:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 00e0:00e4:trace:module:MODULE_InitDLL (000000006DD10000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00e0:00e4:trace:module:process_attach (L"winemac.drv",0000000000000000) - END 00e0:00e4:trace:module:EnumResourceNamesExW 0000000000000000 #000e 000000006DD1FB00 31cfd8 00e0:00e4:trace:module:FindResourceExW 0000000140000000 #000e #0001 0000 00e0:00e4:trace:module:LoadResource 0000000000000000 00000001400092C0 00e0:00e4:trace:module:FindResourceExW 0000000000000000 #0003 #000a 0000 00e0:00e4:trace:module:LoadResource 0000000000000000 00000001400092B0 00e0:00e4:trace:module:FindResourceExW 0000000000000000 #0003 #0009 0000 00e0:00e4:trace:module:LoadResource 0000000000000000 00000001400092A0 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C760, base 000000000031C758. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:module:FindResourceExW 0000000000000000 #0003 #0008 0000 00e0:00e4:trace:module:LoadResource 0000000000000000 0000000140009290 00e0:00e4:trace:module:FindResourceExW 0000000000000000 #0003 #0007 0000 00e0:00e4:trace:module:LoadResource 0000000000000000 0000000140009280 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C800. 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D908880 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C440. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C800. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C800. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C800. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f01 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4C0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0009 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C800. 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D9088E0 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C440. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C800. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C800. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C800. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C800. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C800. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C800. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C800. 00e0:00e4:trace:module:load_dll looking for L"uxtheme.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\uxtheme.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"uxtheme.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 0x2f7230000-0x2f7265000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .text at 0x2f7231000 off 1000 size 13000 virt 123c0 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .data at 0x2f7244000 off 14000 size 1000 virt 110 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rodata at 0x2f7245000 off 15000 size 1000 virt 430 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rdata at 0x2f7246000 off 16000 size 16000 virt 15a30 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .pdata at 0x2f725c000 off 2c000 size 1000 virt 87c flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .xdata at 0x2f725d000 off 2d000 size 1000 virt 97c flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .bss at 0x2f725e000 off 0 size 0 virt 4a0 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .edata at 0x2f725f000 off 2e000 size 2000 virt 1de0 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .idata at 0x2f7261000 off 30000 size 2000 virt 14ac flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rsrc at 0x2f7263000 off 32000 size 1000 virt 5f8 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .reloc at 0x2f7264000 off 33000 size 1000 virt bc flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\uxtheme.dll" 000000000043F7C0 00000002F7230000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\uxtheme.dll" at 00000002F7230000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 00000002F7230000 00e0:00e4:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - START 00e0:00e4:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_ATTACH,0000000000000000) 00000002F72424B0 - CALL 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C630, base 000000000031C628. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00e0:00e4:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - END 00e0:00e4:trace:module:LdrUnloadDll (00000002F7230000) 00e0:00e4:trace:module:LdrUnloadDll (L"uxtheme.dll") - START 00e0:00e4:trace:module:MODULE_DecRefCount (L"uxtheme.dll") ldr.LoadCount: 0 00e0:00e4:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_DETACH,0000000000000000) 00000002F72424B0 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_DETACH,0000000000000000) - RETURN 1 00e0:00e4:trace:module:free_modref unloading L"C:\\windows\\system32\\uxtheme.dll" 00e0:00e4:trace:module:LdrUnloadDll END 00e0:00e4:trace:module:load_dll looking for L"winemac.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\winemac.drv" for L"winemac.drv" at 000000006DD10000, count=2 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f01 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4C0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0009 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF50. 00e0:00e4:trace:module:FindResourceExW 00000002BB750000 #000e #0016 0000 00e0:00e4:trace:module:LoadResource 00000002BB750000 00000002BB8406B0 00e0:00e4:trace:module:FindResourceExW 00000002BB750000 #0003 #0002 0000 00e0:00e4:trace:module:LoadResource 00000002BB750000 00000002BB83F310 00e0:00e4:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031EBE0. 00e0:00e4:trace:module:FindResourceExW 00000002BB750000 #000e #0019 0000 00e0:00e4:trace:module:LoadResource 00000002BB750000 00000002BB8406C0 00e0:00e4:trace:module:FindResourceExW 00000002BB750000 #0003 #0003 0000 00e0:00e4:trace:module:LoadResource 00000002BB750000 00000002BB83F320 00e0:00e4:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031EBE0. 00e0:00e4:trace:module:FindResourceExW 00000002BB750000 #000e #001c 0000 00e0:00e4:trace:module:LoadResource 00000002BB750000 00000002BB8406D0 00e0:00e4:trace:module:FindResourceExW 00000002BB750000 #0003 #0004 0000 00e0:00e4:trace:module:LoadResource 00000002BB750000 00000002BB83F330 00e0:00e4:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031EBE0. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EF60. 00e0:00e4:trace:module:MODULE_InitDLL (00000002BB750000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"comctl32.dll",000000000031FB00) - END 00e0:00e4:trace:module:process_attach (L"ole32.dll",000000000031FB00) - START 00e0:00e4:trace:module:process_attach (L"combase.dll",000000000031FB00) - START 00e0:00e4:trace:module:process_attach (L"rpcrt4.dll",000000000031FB00) - START 00e0:00e4:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_ATTACH,000000000031FB00) 0000000231B26040 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"rpcrt4.dll",000000000031FB00) - END 00e0:00e4:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_ATTACH,000000000031FB00) 00000003270465C0 - CALL 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EFF0, base 000000000031EFE8. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"combase.dll",000000000031FB00) - END 00e0:00e4:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_ATTACH,000000000031FB00) 00000002E8FB74E0 - CALL 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F0A0, base 000000000031F098. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"ole32.dll",000000000031FB00) - END 00e0:00e4:trace:module:process_attach (L"oleaut32.dll",000000000031FB00) - START 00e0:00e4:trace:module:MODULE_InitDLL (00000002739C0000 L"oleaut32.dll",PROCESS_ATTACH,000000000031FB00) 0000000273A6A370 - CALL 00e0:00e4:trace:process:GetEnvironmentVariableW (L"oanocache" 0000000000000000 0) 00e0:00e4:trace:module:MODULE_InitDLL (00000002739C0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"oleaut32.dll",000000000031FB00) - END 00e0:00e4:trace:module:process_attach (L"shell32.dll",000000000031FB00) - START 00e0:00e4:trace:module:process_attach (L"shlwapi.dll",000000000031FB00) - START 00e0:00e4:trace:module:process_attach (L"shcore.dll",000000000031FB00) - START 00e0:00e4:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_ATTACH,000000000031FB00) 00000003126F8FD0 - CALL 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EF80, base 000000000031EF78. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"shcore.dll",000000000031FB00) - END 00e0:00e4:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_ATTACH,000000000031FB00) 00000002E355DE00 - CALL 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F010, base 000000000031F008. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"shlwapi.dll",000000000031FB00) - END 00e0:00e4:trace:module:MODULE_InitDLL (00000001C69E0000 L"shell32.dll",PROCESS_ATTACH,000000000031FB00) 00000001C6A688D0 - CALL 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F0A0, base 000000000031F098. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:module:LdrGetDllFullName module 00000001C69E0000, name 000000000031F5C0. 00e0:00e4:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\shell32.dll" 00e0:00e4:trace:module:MODULE_InitDLL (00000001C69E0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"shell32.dll",000000000031FB00) - END 00e0:00e4:trace:module:process_attach (L"urlmon.dll",000000000031FB00) - START 00e0:00e4:trace:module:process_attach (L"wininet.dll",000000000031FB00) - START 00e0:00e4:trace:module:process_attach (L"mpr.dll",000000000031FB00) - START 00e0:00e4:trace:module:MODULE_InitDLL (000000024F470000 L"mpr.dll",PROCESS_ATTACH,000000000031FB00) 000000024F47A960 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (000000024F470000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"mpr.dll",000000000031FB00) - END 00e0:00e4:trace:module:process_attach (L"ws2_32.dll",000000000031FB00) - START 00e0:00e4:trace:module:MODULE_InitDLL (00000001EC2B0000 L"ws2_32.dll",PROCESS_ATTACH,000000000031FB00) 00000001EC2C27C0 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000001EC2B0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"ws2_32.dll",000000000031FB00) - END 00e0:00e4:trace:module:MODULE_InitDLL (00000003A0440000 L"wininet.dll",PROCESS_ATTACH,000000000031FB00) 00000003A0486300 - CALL 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F000, base 000000000031EFF8. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8cc,0x00000004,0x0) 00e0:00e4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8cc,0x00000004,0x0) 00e0:00e4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8cc,0x00000004,0x0) 00e0:00e4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8cc,0x00000004,0x0) 00e0:00e4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8cc,0x00000004,0x0) 00e0:00e4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8cc,0x00000004,0x0) 00e0:00e4:trace:module:MODULE_InitDLL (00000003A0440000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"wininet.dll",000000000031FB00) - END 00e0:00e4:trace:module:MODULE_InitDLL (00000003422E0000 L"urlmon.dll",PROCESS_ATTACH,000000000031FB00) 0000000342334800 - CALL 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F090, base 000000000031F088. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:module:MODULE_InitDLL (00000003422E0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"urlmon.dll",000000000031FB00) - END 00e0:00e4:trace:module:MODULE_InitDLL (00000001CE210000 L"ieframe.dll",PROCESS_ATTACH,000000000031FB00) 00000001CE23D230 - CALL 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F130, base 000000000031F128. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:module:FindResourceExW 0000000140000000 #000e #0001 0000 00e0:00e4:trace:module:LoadResource 0000000140000000 00000001400092C0 00e0:00e4:trace:module:FindResourceExW 0000000140000000 #0003 #0008 0000 00e0:00e4:trace:module:LdrGetDllFullName module 0000000140000000, name 000000000031EFE0. 00e0:00e4:trace:module:LoadResource 0000000140000000 0000000140009290 00e0:00e4:trace:module:LdrGetDllFullName module 0000000140000000, name 000000000031EC20. 00e0:00e4:trace:module:FindResourceExW 0000000140000000 #000e #0001 0000 00e0:00e4:trace:module:LoadResource 0000000140000000 00000001400092C0 00e0:00e4:trace:module:FindResourceExW 0000000140000000 #0003 #0007 0000 00e0:00e4:trace:module:LdrGetDllFullName module 0000000140000000, name 000000000031F030. 00e0:00e4:trace:module:LoadResource 0000000140000000 0000000140009280 00e0:00e4:trace:module:LdrGetDllFullName module 0000000140000000, name 000000000031EC70. 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00e0:00e4:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00e0:00e4:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00e0:00e4:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFE0. 00e0:00e4:trace:module:MODULE_InitDLL (00000001CE210000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00e0:00e4:trace:module:process_attach (L"ieframe.dll",000000000031FB00) - END 00e0:00e4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 00e0:00e4:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140002080, 0000000000000000, 000000007B60C498, 0000000140008354, 0x00000000) 00e0:00e4:trace:module:load_dll looking for L"user32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 00e0:00e4:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140002060, 0000000000000000, 000000007B60C498, 0000000140008374, 0x00000000) 00e0:00e4:trace:module:load_dll looking for L"version.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\version.dll" for L"version.dll" at 00000002F1FA0000, count=-1 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000441620, dll_characteristics 0000000000000000, name 000000000031FB50, base 000000000031FAE8. 00e0:00e4:trace:module:LdrGetDllHandleEx L"browseui.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 00e0:00e4:trace:module:FindResourceExW 0000000000F30001 #0010 #0001 0000 00e0:00e4:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140002060, 0000000000000000, 000000007B60C498, 000000014000837C, 0x00000000) 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000441D50, dll_characteristics 0000000000000000, name 000000000031FB20, base 000000000031FAB8. 00e0:00e4:trace:module:LdrGetDllHandleEx L"browseui.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 00e0:00e4:trace:module:FindResourceExW 0000000000F30001 #0010 #0001 0000 00e0:00e4:trace:module:LoadResource 0000000000F30001 0000000000F50888 00e0:00e4:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140002060, 0000000000000000, 000000007B60C498, 0000000140008384, 0x00000000) 00e0:00e4:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140002080, 0000000000000000, 000000007B60C498, 000000014000835C, 0x00000000) 00e0:00e4:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140002040, 0000000000000000, 000000007B60C498, 0000000140008204, 0x00000000) 00e0:00e4:trace:module:load_dll looking for L"advpack.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\advpack.dll" 00e0:00e4:trace:module:get_load_order_value got environment b for L"advpack" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\advpack.dll" at 0x1d1cc0000-0x1d1cd6000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .text at 0x1d1cc1000 off 1000 size a000 virt 9f00 flags 60000020 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .data at 0x1d1ccb000 off b000 size 1000 virt a0 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .rodata at 0x1d1ccc000 off c000 size 1000 virt 1d4 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .rdata at 0x1d1ccd000 off d000 size 2000 virt 1130 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .pdata at 0x1d1ccf000 off f000 size 1000 virt 51c flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .xdata at 0x1d1cd0000 off 10000 size 1000 virt 6d0 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .bss at 0x1d1cd1000 off 0 size 0 virt 160 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .edata at 0x1d1cd2000 off 11000 size 1000 virt ff7 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .idata at 0x1d1cd3000 off 12000 size 2000 virt 1004 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\advpack.dll" section .reloc at 0x1d1cd5000 off 14000 size 1000 virt 24 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ole32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"setupapi.dll" in (null) 00e0:00e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\setupapi.dll" 00e0:00e4:trace:module:get_load_order got hardcoded default for L"setupapi.dll" 00e0:00e4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" at 0x21a7e0000-0x21a856000 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .text at 0x21a7e1000 off 1000 size 37000 virt 365e0 flags 60000060 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .data at 0x21a818000 off 38000 size 1000 virt 230 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rodata at 0x21a819000 off 39000 size 3000 virt 244c flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rdata at 0x21a81c000 off 3c000 size e000 virt d010 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .pdata at 0x21a82a000 off 4a000 size 2000 virt 1818 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .xdata at 0x21a82c000 off 4c000 size 2000 virt 1d24 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .bss at 0x21a82e000 off 0 size 0 virt 720 flags c0000080 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .edata at 0x21a82f000 off 4e000 size 18000 virt 171c8 flags 40000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .idata at 0x21a847000 off 66000 size 2000 virt 1f34 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rsrc at 0x21a849000 off 68000 size c000 virt bf00 flags c0000040 00e0:00e4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .reloc at 0x21a855000 off 74000 size 1000 virt d8 flags 42000040 00e0:00e4:trace:module:load_dll looking for L"advapi32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"version.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\version.dll" for L"version.dll" at 00000002F1FA0000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\setupapi.dll" 0000000000441AD0 000000021A7E0000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\setupapi.dll" at 000000021A7E0000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\setupapi.dll" at 000000021A7E0000 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:load_dll looking for L"version.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\version.dll" for L"version.dll" at 00000002F1FA0000, count=-1 00e0:00e4:trace:module:import_dll is not hybrid module 00e0:00e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advpack.dll" 00000000004417A0 00000001D1CC0000 00e0:00e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advpack.dll" at 00000001D1CC0000: builtin 00e0:00e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advpack.dll" at 00000001D1CC0000 00e0:00e4:trace:module:process_attach (L"advpack.dll",0000000000000000) - START 00e0:00e4:trace:module:process_attach (L"setupapi.dll",0000000000000000) - START 00e0:00e4:trace:module:MODULE_InitDLL (000000021A7E0000 L"setupapi.dll",PROCESS_ATTACH,0000000000000000) 000000021A816860 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (000000021A7E0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00e0:00e4:trace:module:process_attach (L"setupapi.dll",0000000000000000) - END 00e0:00e4:trace:module:MODULE_InitDLL (00000001D1CC0000 L"advpack.dll",PROCESS_ATTACH,0000000000000000) 00000001D1CCA2E0 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000001D1CC0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00e0:00e4:trace:module:process_attach (L"advpack.dll",0000000000000000) - END 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F920, base 000000000031F918. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F620, base 000000000031F618. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:process:GetEnvironmentVariableW (L"TMP" 000000000031F050 260) 00e0:00e4:trace:process:GetEnvironmentVariableW (L"TEMP" 000000000031F050 260) 00e0:00e4:trace:process:GetEnvironmentVariableW (L"USERPROFILE" 000000000031F050 260) 00e0:00e4:trace:module:FindResourceExW 0000000000000000 L"REGINST" L"REGINST" 0000 00e0:00e4:trace:module:LoadResource 0000000000000000 0000000140009210 00e0:00e4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F250. 00e0:00e4:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\iexplore.exe" 00e0:00e4:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031F4E0 260) 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EE80, base 000000000031EE78. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EB70, base 000000000031EB68. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:module:LdrResolveDelayLoadedAPI (000000021A7E0000, 000000021A817560, 0000000000000000, 000000007B60C498, 000000021A847BB8, 0x00000000) 00e0:00e4:trace:module:load_dll looking for L"ole32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=-1 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E070, base 000000000031E068. 00e0:00e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00e0:00e4:trace:module:LdrResolveDelayLoadedAPI (000000021A7E0000, 000000021A817560, 0000000000000000, 000000007B60C498, 000000021A847BC0, 0x00000000) 00e0:00e4:trace:module:LdrResolveDelayLoadedAPI (000000021A7E0000, 000000021A817520, 0000000000000000, 000000007B60C498, 000000021A847BF8, 0x00000000) 00e0:00e4:trace:module:load_dll looking for L"shell32.dll" in (null) 00e0:00e4:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=-1 00e0:00e4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c2fc,0x00000004,0x0) 00e0:00e4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c2fc,0x00000004,0x0) 00e0:00e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FD50, base 000000000031FD48. 00e0:00e4:trace:module:LdrGetDllHandleEx L"mscoree" -> 0000000000000000 (load path (null)) 00e0:00e4:trace:module:LdrShutdownProcess () 00e0:00e4:trace:module:MODULE_InitDLL (00000001D1CC0000 L"advpack.dll",PROCESS_DETACH,0000000000000001) 00000001D1CCA2E0 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000001D1CC0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (000000021A7E0000 L"setupapi.dll",PROCESS_DETACH,0000000000000001) 000000021A816860 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (000000021A7E0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (00000001CE210000 L"ieframe.dll",PROCESS_DETACH,0000000000000001) 00000001CE23D230 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000001CE210000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (00000003422E0000 L"urlmon.dll",PROCESS_DETACH,0000000000000001) 0000000342334800 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000003422E0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (00000003A0440000 L"wininet.dll",PROCESS_DETACH,0000000000000001) 00000003A0486300 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000003A0440000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (00000001EC2B0000 L"ws2_32.dll",PROCESS_DETACH,0000000000000001) 00000001EC2C27C0 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000001EC2B0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (000000024F470000 L"mpr.dll",PROCESS_DETACH,0000000000000001) 000000024F47A960 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (000000024F470000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (00000001C69E0000 L"shell32.dll",PROCESS_DETACH,0000000000000001) 00000001C6A688D0 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000001C69E0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_DETACH,0000000000000001) 00000002E355DE00 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_DETACH,0000000000000001) 00000003126F8FD0 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (00000002739C0000 L"oleaut32.dll",PROCESS_DETACH,0000000000000001) 0000000273A6A370 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000002739C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_DETACH,0000000000000001) 00000002E8FB74E0 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_DETACH,0000000000000001) 00000003270465C0 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_DETACH,0000000000000001) 0000000231B26040 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (000000006DD10000 L"winemac.drv",PROCESS_DETACH,0000000000000001) 000000006DD28C10 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (000000006DD10000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (00000002BB750000 L"comctl32.dll",PROCESS_DETACH,0000000000000001) 00000002BB7FDA80 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000002BB750000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (000000006AC60000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006AD09460 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (000000006AC60000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 00e0:00e4:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 00e0:00e4:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:LdrUnloadDll (00000001C69E0000) 00d8:00dc:trace:module:LdrUnloadDll (L"shell32.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"shell32.dll") ldr.LoadCount: 6 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (0000000341D30000) 00d8:00dc:trace:module:LdrUnloadDll (L"quartz.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"quartz.dll") ldr.LoadCount: 1 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (00000001C0ED0000) 00d8:00dc:trace:module:LdrUnloadDll (L"cryptdlg.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"cryptdlg.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"crypt32.dll") ldr.LoadCount: 4 00d8:00dc:trace:module:MODULE_DecRefCount (L"cryptui.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"comctl32.dll") ldr.LoadCount: 2 00d8:00dc:trace:module:MODULE_DecRefCount (L"comdlg32.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"comctl32.dll") ldr.LoadCount: 1 00d8:00dc:trace:module:MODULE_DecRefCount (L"shell32.dll") ldr.LoadCount: 5 00d8:00dc:trace:module:MODULE_DecRefCount (L"shlwapi.dll") ldr.LoadCount: 7 00d8:00dc:trace:module:MODULE_DecRefCount (L"winspool.drv") ldr.LoadCount: 1 00d8:00dc:trace:module:MODULE_DecRefCount (L"crypt32.dll") ldr.LoadCount: 3 00d8:00dc:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 21 00d8:00dc:trace:module:MODULE_DecRefCount (L"wintrust.dll") ldr.LoadCount: 1 00d8:00dc:trace:module:MODULE_InitDLL (00000001C0ED0000 L"cryptdlg.dll",PROCESS_DETACH,0000000000000000) 00000001C0ED4700 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000001C0ED0000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000003BB250000 L"cryptui.dll",PROCESS_DETACH,0000000000000000) 00000003BB260D90 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000003BB250000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (000000031F800000 L"comdlg32.dll",PROCESS_DETACH,0000000000000000) 000000031F82E950 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000031F800000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\cryptdlg.dll" 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\cryptui.dll" 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\comdlg32.dll" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (00000002D1070000) 00d8:00dc:trace:module:LdrUnloadDll (L"cryptnet.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"cryptnet.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"crypt32.dll") ldr.LoadCount: 2 00d8:00dc:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 20 00d8:00dc:trace:module:MODULE_DecRefCount (L"shell32.dll") ldr.LoadCount: 4 00d8:00dc:trace:module:MODULE_InitDLL (00000002D1070000 L"cryptnet.dll",PROCESS_DETACH,0000000000000000) 00000002D1076CD0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000002D1070000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\cryptnet.dll" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (00000003AD720000) 00d8:00dc:trace:module:LdrUnloadDll (L"devenum.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"devenum.dll") ldr.LoadCount: 1 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (0000000258250000) 00d8:00dc:trace:module:LdrUnloadDll (L"mp3dmod.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"mp3dmod.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"msdmo.dll") ldr.LoadCount: 1 00d8:00dc:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 19 00d8:00dc:trace:module:MODULE_InitDLL (0000000258250000 L"mp3dmod.dll",PROCESS_DETACH,0000000000000000) 0000000258272A40 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000258250000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\mp3dmod.dll" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (000000034EA20000) 00d8:00dc:trace:module:LdrUnloadDll (L"mshtml.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"mshtml.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 18 00d8:00dc:trace:module:MODULE_DecRefCount (L"oleaut32.dll") ldr.LoadCount: 8 00d8:00dc:trace:module:MODULE_DecRefCount (L"shell32.dll") ldr.LoadCount: 3 00d8:00dc:trace:module:MODULE_DecRefCount (L"shlwapi.dll") ldr.LoadCount: 6 00d8:00dc:trace:module:MODULE_DecRefCount (L"urlmon.dll") ldr.LoadCount: 1 00d8:00dc:trace:module:MODULE_InitDLL (000000034EA20000 L"mshtml.dll",PROCESS_DETACH,0000000000000000) 000000034EB39480 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000034EA20000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\mshtml.dll" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (0000000364870000) 00d8:00dc:trace:module:LdrUnloadDll (L"msisip.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"msisip.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"crypt32.dll") ldr.LoadCount: 1 00d8:00dc:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 17 00d8:00dc:trace:module:MODULE_InitDLL (0000000364870000 L"msisip.dll",PROCESS_DETACH,0000000000000000) 0000000364871AA0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000364870000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\msisip.dll" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (000000024A370000) 00d8:00dc:trace:module:LdrUnloadDll (L"qcap.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"qcap.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 16 00d8:00dc:trace:module:MODULE_DecRefCount (L"oleaut32.dll") ldr.LoadCount: 7 00d8:00dc:trace:module:MODULE_InitDLL (000000024A370000 L"qcap.dll",PROCESS_DETACH,0000000000000000) 000000024A383D80 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000024A370000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\qcap.dll" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (000000038F0B0000) 00d8:00dc:trace:module:LdrUnloadDll (L"qedit.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"qedit.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 15 00d8:00dc:trace:module:MODULE_DecRefCount (L"oleaut32.dll") ldr.LoadCount: 6 00d8:00dc:trace:module:MODULE_InitDLL (000000038F0B0000 L"qedit.dll",PROCESS_DETACH,0000000000000000) 000000038F0C1430 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000038F0B0000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\qedit.dll" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (00000003422E0000) 00d8:00dc:trace:module:LdrUnloadDll (L"urlmon.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"urlmon.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 14 00d8:00dc:trace:module:MODULE_DecRefCount (L"oleaut32.dll") ldr.LoadCount: 5 00d8:00dc:trace:module:MODULE_DecRefCount (L"rpcrt4.dll") ldr.LoadCount: 7 00d8:00dc:trace:module:MODULE_DecRefCount (L"shell32.dll") ldr.LoadCount: 2 00d8:00dc:trace:module:MODULE_DecRefCount (L"shlwapi.dll") ldr.LoadCount: 5 00d8:00dc:trace:module:MODULE_DecRefCount (L"wininet.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"mpr.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"shell32.dll") ldr.LoadCount: 1 00d8:00dc:trace:module:MODULE_DecRefCount (L"shlwapi.dll") ldr.LoadCount: 4 00d8:00dc:trace:module:MODULE_DecRefCount (L"ws2_32.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_InitDLL (00000003422E0000 L"urlmon.dll",PROCESS_DETACH,0000000000000000) 0000000342334800 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000003422E0000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000003A0440000 L"wininet.dll",PROCESS_DETACH,0000000000000000) 00000003A0486300 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000003A0440000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000001EC2B0000 L"ws2_32.dll",PROCESS_DETACH,0000000000000000) 00000001EC2C27C0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000001EC2B0000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (000000024F470000 L"mpr.dll",PROCESS_DETACH,0000000000000000) 000000024F47A960 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000024F470000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\urlmon.dll" 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\wininet.dll" 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\ws2_32.dll" 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\mpr.dll" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (0000000361860000) 00d8:00dc:trace:module:LdrUnloadDll (L"windowscodecs.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"windowscodecs.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 13 00d8:00dc:trace:module:MODULE_DecRefCount (L"oleaut32.dll") ldr.LoadCount: 4 00d8:00dc:trace:module:MODULE_DecRefCount (L"propsys.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 12 00d8:00dc:trace:module:MODULE_DecRefCount (L"oleaut32.dll") ldr.LoadCount: 3 00d8:00dc:trace:module:MODULE_DecRefCount (L"rpcrt4.dll") ldr.LoadCount: 6 00d8:00dc:trace:module:MODULE_DecRefCount (L"shlwapi.dll") ldr.LoadCount: 3 00d8:00dc:trace:module:MODULE_InitDLL (0000000361860000 L"windowscodecs.dll",PROCESS_DETACH,0000000000000000) 000000036195C510 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000361860000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (0000000228450000 L"propsys.dll",PROCESS_DETACH,0000000000000000) 0000000228457F30 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000228450000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\windowscodecs.dll" 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\propsys.dll" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (00000003B6DC0000) 00d8:00dc:trace:module:LdrUnloadDll (L"winevulkan.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"winevulkan.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"setupapi.dll") ldr.LoadCount: 2 00d8:00dc:trace:module:MODULE_InitDLL (00000003B6DC0000 L"winevulkan.dll",PROCESS_DETACH,0000000000000000) 00000003B6DD1FA0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000003B6DC0000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\winevulkan.dll" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrUnloadDll (00000001FDFD0000) 00d8:00dc:trace:module:LdrUnloadDll (L"wintrust.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"wintrust.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"crypt32.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_DecRefCount (L"bcrypt.dll") ldr.LoadCount: 0 00d8:00dc:trace:module:MODULE_InitDLL (00000001FDFD0000 L"wintrust.dll",PROCESS_DETACH,0000000000000000) 00000001FDFE63D0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000001FDFD0000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_DETACH,0000000000000000) 00000001DD4524D0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_DETACH,0000000000000000) 00000002D4D49C40 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\wintrust.dll" 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\crypt32.dll" 00d8:00dc:trace:module:free_modref unloading L"C:\\windows\\system32\\bcrypt.dll" 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c7bc,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c7bc,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c7bc,0x00000004,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31c7bc,0x00000004,0x0) 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031AD00, base 000000000031ACF8. 00d8:00dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726624, 0x00000000) 00d8:00dc:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 00d8:00dc:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=7 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726704, 0x00000000) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266EC, 0x00000000) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726714, 0x00000000) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266A4, 0x00000000) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726684, 0x00000000) 0030:00e8:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:00e8:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:00e8:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:00e8:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:00e8:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:00e8:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266AC, 0x00000000) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266BC, 0x00000000) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72661C, 0x00000000) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72667C, 0x00000000) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266DC, 0x00000000) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72660C, 0x00000000) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72665C, 0x00000000) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726614, 0x00000000) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726664, 0x00000000) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266B4, 0x00000000) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72662C, 0x00000000) 00d8:00dc:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726634, 0x00000000) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 00d8:00dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31b1b8,0x00000008,0x0) 0030:00e8:trace:module:LdrShutdownThread () 0030:00e8:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_DETACH,0000000000000000) 0000000231B26040 - CALL 0030:00e8:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:00e8:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_DETACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:00e8:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:00e8:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_DETACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:00e8:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_DETACH,0000000000000000) - RETURN 1 00d8:00dc:trace:module:LdrUnloadDll (000000021A7E0000) 00d8:00dc:trace:module:LdrUnloadDll (L"setupapi.dll") - START 00d8:00dc:trace:module:MODULE_DecRefCount (L"setupapi.dll") ldr.LoadCount: 1 00d8:00dc:trace:module:LdrUnloadDll END 00d8:00dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FD50, base 000000000031FD48. 00d8:00dc:trace:module:LdrGetDllHandleEx L"mscoree" -> 0000000000000000 (load path (null)) 00d8:00dc:trace:module:LdrShutdownProcess () 00d8:00dc:trace:module:MODULE_InitDLL (00000001D1CC0000 L"advpack.dll",PROCESS_DETACH,0000000000000001) 00000001D1CCA2E0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000001D1CC0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000002A7800000 L"localspl.dll",PROCESS_DETACH,0000000000000001) 00000002A7811FB0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000002A7800000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000001D2B40000 L"spoolss.dll",PROCESS_DETACH,0000000000000001) 00000001D2B43930 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000001D2B40000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (0000000296A50000 L"WINEPS.DRV",PROCESS_DETACH,0000000000000001) 0000000296A69F80 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000296A50000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000001C4EE0000 L"winspool.drv",PROCESS_DETACH,0000000000000001) 00000001C4EF90D0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000001C4EE0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000003AD720000 L"devenum.dll",PROCESS_DETACH,0000000000000001) 00000003AD728700 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000003AD720000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (000000034ABC0000 L"msdmo.dll",PROCESS_DETACH,0000000000000001) 000000034ABC3F20 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000034ABC0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000003A77E0000 L"avicap32.dll",PROCESS_DETACH,0000000000000001) 00000003A77E1A20 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000003A77E0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (0000000341D30000 L"quartz.dll",PROCESS_DETACH,0000000000000001) 0000000341D9FDD0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000341D30000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (000000039A620000 L"msvfw32.dll",PROCESS_DETACH,0000000000000001) 000000039A62D460 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000039A620000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000002BB750000 L"comctl32.dll",PROCESS_DETACH,0000000000000001) 00000002BB7FDA80 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000002BB750000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000001C8B40000 L"msacm32.dll",PROCESS_DETACH,0000000000000001) 00000001C8B4D580 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000001C8B40000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000003B8F00000 L"winmm.dll",PROCESS_DETACH,0000000000000001) 00000003B8F219F0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000003B8F00000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (0000000236DF0000 L"dsound.dll",PROCESS_DETACH,0000000000000001) 0000000236E09F90 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000236DF0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000001C69E0000 L"shell32.dll",PROCESS_DETACH,0000000000000001) 00000001C6A688D0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000001C69E0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000001C1EF0000 L"atl100.dll",PROCESS_DETACH,0000000000000001) 00000001C1EFB6D0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000001C1EF0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_DETACH,0000000000000001) 00000002E355DE00 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_DETACH,0000000000000001) 00000003126F8FD0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000002739C0000 L"oleaut32.dll",PROCESS_DETACH,0000000000000001) 0000000273A6A370 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000002739C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_DETACH,0000000000000001) 00000002E8FB74E0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_DETACH,0000000000000001) 00000003270465C0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (000000021A7E0000 L"setupapi.dll",PROCESS_DETACH,0000000000000001) 000000021A816860 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000021A7E0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_DETACH,0000000000000001) 0000000231B26040 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (000000006E5B0000 L"winemac.drv",PROCESS_DETACH,0000000000000001) 000000006E5D3C10 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000006E5B0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (000000006AC60000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006AD09460 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000006AC60000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 00d8:00dc:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 00d8:00dc:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:process:CreateProcessInternalW app L"C:\\windows\\syswow64\\rundll32.exe" cmdline L"C:\\windows\\syswow64\\rundll32.exe setupapi,InstallHinfSection Wow64Install 128 \\\\?\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\wine.inf" 0028:002c:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\syswow64\\rundll32.exe" image L"C:\\windows\\syswow64\\rundll32.exe" cmdline L"C:\\windows\\syswow64\\rundll32.exe setupapi,InstallHinfSection Wow64Install 128 \\\\?\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\wine.inf" parent 0x0 0028:002c:trace:process:get_pe_file_info assuming 014c builtin for L"\\??\\C:\\windows\\syswow64\\rundll32.exe" 0028:002c:trace:process:send_to_cx_loader loader (null) wineserversocket 12 stdin_fd -1 stdout_fd -1 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 0028:002c:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 00ec:00f0:trace:module:get_load_order looking for L"C:\\windows\\syswow64\\rundll32.exe" 00ec:00f0:trace:module:get_load_order got main exe default n,b for L"C:\\windows\\syswow64\\rundll32.exe" 00ec:00f0:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\syswow64\\rundll32.exe" at 0x400000-0x409000 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\rundll32.exe" section .text at 0x401000 off 1000 size 3000 virt 2028 flags 60000020 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\rundll32.exe" section .data at 0x404000 off 4000 size 1000 virt 38 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\rundll32.exe" section .rdata at 0x405000 off 5000 size 1000 virt 234 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\rundll32.exe" section .bss at 0x406000 off 0 size 0 virt c0 flags c0000080 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\rundll32.exe" section .idata at 0x407000 off 6000 size 1000 virt 5cc flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\rundll32.exe" section .reloc at 0x408000 off 7000 size 1000 virt 1c4 flags 42000040 00ec:00f0:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 00ec:00f0:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\syswow64\\ntdll.dll" at 0x7bc00000-0x7bc97000 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .text at 0x7bc01000 off 1000 size 66000 virt 652b8 flags 60000020 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .data at 0x7bc67000 off 67000 size 1000 virt b60 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .rodata at 0x7bc68000 off 68000 size 2000 virt 1ff4 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .rdata at 0x7bc6a000 off 6a000 size 11000 virt 10568 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .bss at 0x7bc7b000 off 0 size 0 virt 24e4 flags c0000080 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .edata at 0x7bc7e000 off 7b000 size 13000 virt 12769 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .idata at 0x7bc91000 off 8e000 size 1000 virt 14 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .rsrc at 0x7bc92000 off 8f000 size 1000 virt 3ac flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .reloc at 0x7bc93000 off 90000 size 4000 virt 3e18 flags 42000040 00ec:00f0:trace:module:load_wow64_ntdll loaded L"\\??\\C:\\windows\\syswow64\\ntdll.dll" at 0x7bc00000 00ec:00f0:fixme:module:dlopen_32on64_opengl32 loaded "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_32on64-unix/opengl32.dll.so" early @ 0x69958000 00ec:00f0:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x331000 0028:002c:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\syswow64\\rundll32.exe" pid 00ec tid 00f0 handles 0x94/0x98 0028:002c:trace:process:CreateProcessInternalW started process pid 00ec tid 00f0 00ec:00f0:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x50f790,0x00000040,0x0) 00ec:00f0:trace:module:build_module loaded L"\\??\\C:\\windows\\syswow64\\rundll32.exe" 00000000006121F0 0000000000400000 00ec:00f0:trace:loaddll:build_module Loaded L"C:\\windows\\syswow64\\rundll32.exe" at 0000000000400000: builtin 00ec:00f0:trace:module:load_dll looking for L"C:\\windows\\system32\\wow64.dll" in (null) 00ec:00f0:trace:module:get_load_order looking for L"C:\\windows\\system32\\wow64.dll" 00ec:00f0:trace:module:get_load_order got hardcoded default for L"wow64.dll" 00ec:00f0:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\wow64.dll" at 0x6f000000-0x6f026000 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .text at 0x6f001000 off 1000 size 12000 virt 11ab0 flags 60000020 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .data at 0x6f013000 off 13000 size 1000 virt 840 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .rodata at 0x6f014000 off 14000 size 1000 virt 2a8 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .rdata at 0x6f015000 off 15000 size 3000 virt 2c70 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .pdata at 0x6f018000 off 18000 size 1000 virt d68 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .xdata at 0x6f019000 off 19000 size 1000 virt d5c flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .bss at 0x6f01a000 off 0 size 0 virt 4160 flags c0000080 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .edata at 0x6f01f000 off 1a000 size 3000 virt 2c2c flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .idata at 0x6f022000 off 1d000 size 3000 virt 2908 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .reloc at 0x6f025000 off 20000 size 1000 virt 3f8 flags 42000040 00ec:00f0:trace:module:load_dll looking for L"ntdll.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wow64.dll" 0000000000612670 000000006F000000 00ec:00f0:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wow64.dll" at 000000006F000000: builtin 00ec:00f0:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wow64.dll" at 000000006F000000 00ec:00f0:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000050F3C0, base 000000000050F3B0. 00ec:00f0:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00ec:00f0:trace:module:load_dll looking for L"\\??\\C:\\windows\\system32\\wow64cpu.dll" in (null) 00ec:00f0:trace:module:get_load_order looking for L"C:\\windows\\system32\\wow64cpu.dll" 00ec:00f0:trace:module:get_load_order got hardcoded default for L"wow64cpu.dll" 00ec:00f0:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\wow64cpu.dll" at 0x6f100000-0x6f10c000 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .text at 0x6f101000 off 1000 size 1000 virt 7c0 flags 60000020 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .data at 0x6f102000 off 2000 size 1000 virt 40 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .rodata at 0x6f103000 off 3000 size 1000 virt 24 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .rdata at 0x6f104000 off 4000 size 1000 virt a0 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .pdata at 0x6f105000 off 5000 size 1000 virt 84 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .xdata at 0x6f106000 off 6000 size 1000 virt 5c flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .bss at 0x6f107000 off 0 size 0 virt 2000 flags c0000080 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .edata at 0x6f109000 off 7000 size 1000 virt 21e flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .idata at 0x6f10a000 off 8000 size 1000 virt 21c flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .reloc at 0x6f10b000 off 9000 size 1000 virt 1c flags 42000040 00ec:00f0:trace:module:load_dll looking for L"ntdll.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"wow64.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\wow64.dll" for L"wow64.dll" at 000000006F000000, count=2 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wow64cpu.dll" 00000000006128A0 000000006F100000 00ec:00f0:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wow64cpu.dll" at 000000006F100000: builtin 00ec:00f0:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wow64cpu.dll" at 000000006F100000 00ec:00f0:trace:module:process_attach (L"wow64cpu.dll",0000000000000000) - START 00ec:00f0:trace:module:process_attach (L"wow64.dll",0000000000000000) - START 00ec:00f0:trace:module:MODULE_InitDLL (000000006F000000 L"wow64.dll",PROCESS_ATTACH,0000000000000000) 000000006F012780 - CALL 00ec:00f0:trace:module:MODULE_InitDLL (000000006F000000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00ec:00f0:trace:module:process_attach (L"wow64.dll",0000000000000000) - END 00ec:00f0:trace:module:MODULE_InitDLL (000000006F100000 L"wow64cpu.dll",PROCESS_ATTACH,0000000000000000) 000000006F101790 - CALL 00ec:00f0:trace:module:MODULE_InitDLL (000000006F100000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00ec:00f0:trace:module:process_attach (L"wow64cpu.dll",0000000000000000) - END 00ec:00f0:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x50ef70,0x00000040,0x0) 00ec:00f0:trace:module:build_module loaded L"\\??\\C:\\windows\\syswow64\\rundll32.exe" 00721F70 00400000 00ec:00f0:trace:loaddll:build_module Loaded L"C:\\windows\\syswow64\\rundll32.exe" at 00400000: builtin 00ec:00f0:trace:module:load_dll looking for L"kernel32.dll" in (null) 00ec:00f0:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" 00ec:00f0:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" 00ec:00f0:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 30c10 flags 60000020 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 220 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 3000 virt 2050 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .rdata at 0x7b636000 off 36000 size 4000 virt 31a4 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .bss at 0x7b63a000 off 0 size 0 virt 180 flags c0000080 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .edata at 0x7b63b000 off 3a000 size 10000 virt f594 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .idata at 0x7b64b000 off 4a000 size 8000 virt 7484 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .rsrc at 0x7b653000 off 52000 size 8000 virt 7dfc flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .reloc at 0x7b65b000 off 5a000 size 3000 virt 24c8 flags 42000040 00ec:00f0:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00ec:00f0:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" 00ec:00f0:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" 00ec:00f0:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" at 0x7b000000-0x7b24a000 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 85000 virt 84860 flags 60000020 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .data at 0x7b086000 off 86000 size 2000 virt 1c6c flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .rodata at 0x7b088000 off 88000 size 2000 virt 1d88 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .rdata at 0x7b08a000 off 8a000 size 1e000 virt 1d218 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .bss at 0x7b0a8000 off 0 size 0 virt 1da0 flags c0000080 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .edata at 0x7b0aa000 off a8000 size 20000 virt 1f88e flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .idata at 0x7b0ca000 off c8000 size 4000 virt 3700 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .rsrc at 0x7b0ce000 off cc000 size 176000 virt 1757f0 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .reloc at 0x7b244000 off 242000 size 6000 virt 5450 flags 42000040 00ec:00f0:trace:module:load_dll looking for L"ntdll.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=2 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 00722410 7B000000 00ec:00f0:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 7B000000: builtin 00ec:00f0:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 7B000000 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"ntdll.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=3 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 00722248 7B600000 00ec:00f0:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 7B600000: builtin 00ec:00f0:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 7B600000 00ec:00f0:trace:module:load_dll looking for L"kernel32.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=2 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"ntdll.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=4 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00ec:00f0:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" 00ec:00f0:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" 00ec:00f0:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" at 0x870000-0x935000 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .text at 0x871000 off 1000 size 8c000 virt 8b1a0 flags 60000060 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .data at 0x8fd000 off 8d000 size 2000 virt 11b8 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .rodata at 0x8ff000 off 8f000 size 4000 virt 3ad4 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .rdata at 0x903000 off 93000 size d000 virt c1e4 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .bss at 0x910000 off 0 size 0 virt 16e0 flags c0000080 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .edata at 0x912000 off a0000 size 1a000 virt 19455 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .idata at 0x92c000 off ba000 size 2000 virt 14cc flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .rsrc at 0x92e000 off bc000 size 1000 virt 3c8 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .reloc at 0x92f000 off bd000 size 6000 virt 5d7c flags 42000040 00ec:00f0:trace:module:perform_relocations relocating from 70B40000-70C05000 to 00870000-00935000 00ec:00f0:trace:module:load_dll looking for L"kernel32.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=3 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"ntdll.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=5 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 00722578 00870000 00ec:00f0:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00870000: builtin 00ec:00f0:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00870000 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"user32.dll" in (null) 00ec:00f0:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" 00ec:00f0:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" 00ec:00f0:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" at 0x6ed00000-0x6eece000 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .text at 0x6ed01000 off 1000 size b1000 virt b0720 flags 60000060 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .data at 0x6edb2000 off b2000 size 1000 virt 694 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .rodata at 0x6edb3000 off b3000 size 1000 virt eb8 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .rdata at 0x6edb4000 off b4000 size 17000 virt 16570 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .bss at 0x6edcb000 off 0 size 0 virt 244 flags c0000080 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .edata at 0x6edcc000 off cb000 size 11000 virt 10fb1 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .idata at 0x6eddd000 off dc000 size 4000 virt 3e50 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .rsrc at 0x6ede1000 off e0000 size e5000 virt e4818 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .reloc at 0x6eec6000 off 1c5000 size 8000 virt 7140 flags 42000040 00ec:00f0:trace:module:load_dll looking for L"advapi32.dll" in (null) 00ec:00f0:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" 00ec:00f0:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" 00ec:00f0:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" at 0x61740000-0x6177d000 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .text at 0x61741000 off 1000 size 25000 virt 24f34 flags 60000060 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .data at 0x61766000 off 26000 size 1000 virt 140 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .rodata at 0x61767000 off 27000 size 1000 virt e5c flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .rdata at 0x61768000 off 28000 size 6000 virt 51a0 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .bss at 0x6176e000 off 0 size 0 virt d00 flags c0000080 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .edata at 0x6176f000 off 2e000 size 8000 virt 73da flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .idata at 0x61777000 off 36000 size 3000 virt 25d8 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .rsrc at 0x6177a000 off 39000 size 1000 virt 3c8 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .reloc at 0x6177b000 off 3a000 size 2000 virt 1be0 flags 42000040 00ec:00f0:trace:module:load_dll looking for L"kernel32.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=4 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 7B000000, count=2 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"msvcrt.dll" in (null) 00ec:00f0:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" 00ec:00f0:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" 00ec:00f0:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" at 0x940000-0x9db000 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .text at 0x941000 off 1000 size 73000 virt 72cc0 flags 60000060 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .data at 0x9b4000 off 74000 size 2000 virt 1094 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .rodata at 0x9b6000 off 76000 size 2000 virt 1554 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .rdata at 0x9b8000 off 78000 size b000 virt a244 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .bss at 0x9c3000 off 0 size 0 virt 14a0 flags c0000080 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .edata at 0x9c5000 off 83000 size e000 virt d915 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .idata at 0x9d3000 off 91000 size 2000 virt 1310 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .rsrc at 0x9d5000 off 93000 size 1000 virt 398 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .reloc at 0x9d6000 off 94000 size 5000 virt 4710 flags 42000040 00ec:00f0:trace:module:perform_relocations relocating from 6A280000-6A31B000 to 00940000-009DB000 00ec:00f0:trace:module:load_dll looking for L"kernel32.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=5 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"ntdll.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=6 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 00722A58 00940000 00ec:00f0:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00940000: builtin 00ec:00f0:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00940000 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"ntdll.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=7 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"sechost.dll" in (null) 00ec:00f0:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" 00ec:00f0:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" 00ec:00f0:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" at 0x6bc00000-0x6bc28000 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" section .text at 0x6bc01000 off 1000 size 18000 virt 17578 flags 60000060 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" section .data at 0x6bc19000 off 19000 size 1000 virt 104 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" section .rodata at 0x6bc1a000 off 1a000 size 1000 virt f0c flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" section .rdata at 0x6bc1b000 off 1b000 size 4000 virt 34a0 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" section .bss at 0x6bc1f000 off 0 size 0 virt c0 flags c0000080 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" section .edata at 0x6bc20000 off 1f000 size 5000 virt 46ad flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" section .idata at 0x6bc25000 off 24000 size 1000 virt e78 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" section .reloc at 0x6bc26000 off 25000 size 2000 virt 1018 flags 42000040 00ec:00f0:trace:module:load_dll looking for L"kernel32.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=6 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 7B000000, count=3 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"ntdll.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=8 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00870000, count=2 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 00722C10 6BC00000 00ec:00f0:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 6BC00000: builtin 00ec:00f0:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 6BC00000 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 00722878 61740000 00ec:00f0:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 61740000: builtin 00ec:00f0:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 61740000 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"gdi32.dll" in (null) 00ec:00f0:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" 00ec:00f0:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" 00ec:00f0:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" at 0x6c9c0000-0x6ca3b000 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .text at 0x6c9c1000 off 1000 size 4e000 virt 4d580 flags 60000060 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .data at 0x6ca0f000 off 4f000 size 1000 virt 6ec flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .rodata at 0x6ca10000 off 50000 size 1000 virt d8c flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .rdata at 0x6ca11000 off 51000 size 14000 virt 13018 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .bss at 0x6ca25000 off 0 size 0 virt e0 flags c0000080 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .edata at 0x6ca26000 off 65000 size 9000 virt 8564 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .idata at 0x6ca2f000 off 6e000 size 3000 virt 20f0 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .rsrc at 0x6ca32000 off 71000 size 5000 virt 422c flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .reloc at 0x6ca37000 off 76000 size 4000 virt 32e8 flags 42000040 00ec:00f0:trace:module:load_dll looking for L"advapi32.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 61740000, count=2 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"kernel32.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=7 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"ntdll.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=9 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00870000, count=3 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"user32.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 6ED00000, count=2 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"win32u.dll" in (null) 00ec:00f0:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\win32u.dll" 00ec:00f0:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\win32u.dll" 00ec:00f0:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\win32u.dll" is a fake Wine dll 00ec:00f0:trace:module:load_dll looking for L"kernel32.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=8 00ec:00f0:trace:module:load_dll looking for L"ntdll.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=10 00ec:00f0:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\win32u.dll" 00722FA8 69D80000 00ec:00f0:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\win32u.dll" at 69D80000: builtin 00ec:00f0:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\win32u.dll" at 69D80000 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\gdi32.dll" 00722D90 6C9C0000 00ec:00f0:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\gdi32.dll" at 6C9C0000: builtin 00ec:00f0:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\gdi32.dll" at 6C9C0000 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"kernel32.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=9 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 7B000000, count=4 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"ntdll.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=11 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"sechost.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\sechost.dll" for L"sechost.dll" at 6BC00000, count=2 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00870000, count=4 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"version.dll" in (null) 00ec:00f0:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" 00ec:00f0:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" 00ec:00f0:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" at 0x63480000-0x6348b000 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .text at 0x63481000 off 1000 size 2000 virt 1ff8 flags 60000020 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .data at 0x63483000 off 3000 size 1000 virt 50 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .rodata at 0x63484000 off 4000 size 1000 virt 84 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .rdata at 0x63485000 off 5000 size 1000 virt 210 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .bss at 0x63486000 off 0 size 0 virt a0 flags c0000080 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .edata at 0x63487000 off 6000 size 1000 virt 327 flags 40000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .idata at 0x63488000 off 7000 size 1000 virt 604 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .rsrc at 0x63489000 off 8000 size 1000 virt 3b4 flags c0000040 00ec:00f0:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .reloc at 0x6348a000 off 9000 size 1000 virt 1b8 flags 42000040 00ec:00f0:trace:module:load_dll looking for L"kernel32.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=10 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 7B000000, count=5 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"ntdll.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=12 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00870000, count=5 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 00723160 63480000 00ec:00f0:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 63480000: builtin 00ec:00f0:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 63480000 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:load_dll looking for L"win32u.dll" in (null) 00ec:00f0:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 69D80000, count=2 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\user32.dll" 007226F8 6ED00000 00ec:00f0:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\user32.dll" at 6ED00000: builtin 00ec:00f0:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\user32.dll" at 6ED00000 00ec:00f0:trace:module:import_dll is not hybrid module 00ec:00f0:trace:module:process_attach (L"ntdll.dll",0032FD24) - START 00ec:00f0:trace:module:MODULE_InitDLL (7BC00000 L"ntdll.dll",PROCESS_ATTACH,0032FD24) 7BC658D0 - CALL 00ec:00f0:trace:module:MODULE_InitDLL (7BC00000,PROCESS_ATTACH,0032FD24) - RETURN 1 00ec:00f0:trace:module:process_attach (L"ntdll.dll",0032FD24) - END 00ec:00f0:trace:module:process_attach (L"kernel32.dll",0032FD24) - START 00ec:00f0:trace:module:process_attach (L"kernelbase.dll",0032FD24) - START 00ec:00f0:trace:module:MODULE_InitDLL (7B000000 L"kernelbase.dll",PROCESS_ATTACH,0032FD24) 7B03CDC0 - CALL 00ec:00f0:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x50ef70,0x00000008,0x0) 00ec:00f0:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 0032F65A 85) 00ec:00f0:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 00000000 0) 00ec:00f0:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 00723338 17) 00ec:00f0:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 00000000 0) 00ec:00f0:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 00723338 17) 00ec:00f0:trace:module:MODULE_InitDLL (7B000000,PROCESS_ATTACH,0032FD24) - RETURN 1 00ec:00f0:trace:module:process_attach (L"kernelbase.dll",0032FD24) - END 00ec:00f0:trace:module:MODULE_InitDLL (7B600000 L"kernel32.dll",PROCESS_ATTACH,0032FD24) 7B631790 - CALL 00ec:00f0:trace:process:set_entry_point setting FT_Thunk at 7B63B634 to 00000000 00ec:00f0:trace:module:MODULE_InitDLL (7B600000,PROCESS_ATTACH,0032FD24) - RETURN 1 00ec:00f0:trace:module:process_attach (L"kernel32.dll",0032FD24) - END 00ec:00f0:trace:module:process_attach (L"ucrtbase.dll",0032FD24) - START 00ec:00f0:trace:module:MODULE_InitDLL (00870000 L"ucrtbase.dll",PROCESS_ATTACH,0032FD24) 008FB780 - CALL 00ec:00f0:trace:module:LdrGetDllFullName module 00000000, name 0032F7D8. 00ec:00f0:trace:module:GetModuleFileNameW L"C:\\windows\\syswow64\\rundll32.exe" 00ec:00f0:trace:module:LdrGetDllFullName module 00000000, name 0032F828. 00ec:00f0:trace:module:GetModuleFileNameW L"C:\\windows\\syswow64\\rundll32.exe" 00ec:00f0:trace:module:MODULE_InitDLL (00870000,PROCESS_ATTACH,0032FD24) - RETURN 1 00ec:00f0:trace:module:process_attach (L"ucrtbase.dll",0032FD24) - END 00ec:00f0:trace:module:process_attach (L"user32.dll",0032FD24) - START 00ec:00f0:trace:module:process_attach (L"advapi32.dll",0032FD24) - START 00ec:00f0:trace:module:process_attach (L"msvcrt.dll",0032FD24) - START 00ec:00f0:trace:module:MODULE_InitDLL (00940000 L"msvcrt.dll",PROCESS_ATTACH,0032FD24) 009B34A0 - CALL 00ec:00f0:trace:module:LdrGetDllFullName module 00000000, name 0032F718. 00ec:00f0:trace:module:GetModuleFileNameW L"C:\\windows\\syswow64\\rundll32.exe" 00ec:00f0:trace:module:LdrGetDllFullName module 00000000, name 0032F768. 00ec:00f0:trace:module:GetModuleFileNameW L"C:\\windows\\syswow64\\rundll32.exe" 00ec:00f0:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 00ec:00f0:trace:module:MODULE_InitDLL (00940000,PROCESS_ATTACH,0032FD24) - RETURN 1 00ec:00f0:trace:module:process_attach (L"msvcrt.dll",0032FD24) - END 00ec:00f0:trace:module:process_attach (L"sechost.dll",0032FD24) - START 00ec:00f0:trace:module:MODULE_InitDLL (6BC00000 L"sechost.dll",PROCESS_ATTACH,0032FD24) 6BC17830 - CALL 00ec:00f0:trace:module:MODULE_InitDLL (6BC00000,PROCESS_ATTACH,0032FD24) - RETURN 1 00ec:00f0:trace:module:process_attach (L"sechost.dll",0032FD24) - END 00ec:00f0:trace:module:MODULE_InitDLL (61740000 L"advapi32.dll",PROCESS_ATTACH,0032FD24) 61765190 - CALL 00ec:00f0:trace:module:MODULE_InitDLL (61740000,PROCESS_ATTACH,0032FD24) - RETURN 1 00ec:00f0:trace:module:process_attach (L"advapi32.dll",0032FD24) - END 00ec:00f0:trace:module:process_attach (L"gdi32.dll",0032FD24) - START 00ec:00f0:trace:module:process_attach (L"win32u.dll",0032FD24) - START 00ec:00f0:trace:module:MODULE_InitDLL (69D80000 L"win32u.dll",PROCESS_ATTACH,0032FD24) 69E37E90 - CALL 00ec:00f0:trace:seh:dispatch_exception code=c00000fd flags=0 addr=0000000069DA10A0 ip=0000000069DA10A0 tid=00f0 00ec:00f0:warn:seh:dispatch_exception EXCEPTION_STACK_OVERFLOW exception (code=c00000fd) raised 00ec:00f0:trace:seh:dispatch_exception rax=000000000032ca50 rbx=000000000032ca50 rcx=000000000032ca30 rdx=0000000000000000 00ec:00f0:trace:seh:dispatch_exception rsi=000000000032ca30 rdi=000000000010e000 rbp=000000000032caf0 rsp=000000000032ca28 00ec:00f0:trace:seh:dispatch_exception r8=0000000069da10b8 r9=0000000069f00107 r10=000000000010e000 r11=0000000000000246 00ec:00f0:trace:seh:dispatch_exception r12=0000000000000001 r13=0000000000000000 r14=0000000000000001 r15=0000000000000000 00ec:00f0:err:seh:call_stack_handlers invalid frame 000000000032CA28 (0000000000412000-000000000050FD20) 00ec:00f0:err:seh:NtRaiseException Exception frame is not in stack limits => unable to dispatch exception. 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004D00, 0000000000000000, 000000007B60C498, 0000000140015A74, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004D20, 0000000000000000, 000000007B60C498, 000000014001588C, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004D20, 0000000000000000, 000000007B60C498, 0000000140015884, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004D20, 0000000000000000, 000000007B60C498, 000000014001589C, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004D20, 0000000000000000, 000000007B60C498, 000000014001587C, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004D40, 0000000000000000, 000000007B60C498, 000000014001580C, 0x00000000) 0028:002c:trace:module:load_dll looking for L"newdev.dll" in (null) 0028:002c:trace:module:get_load_order looking for L"C:\\windows\\system32\\newdev.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"newdev.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\newdev.dll" at 0x284810000-0x28481c000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\newdev.dll" section .text at 0x284811000 off 1000 size 2000 virt 18d0 flags 60000020 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\newdev.dll" section .data at 0x284813000 off 3000 size 1000 virt 70 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\newdev.dll" section .rodata at 0x284814000 off 4000 size 1000 virt 180 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\newdev.dll" section .rdata at 0x284815000 off 5000 size 1000 virt 320 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\newdev.dll" section .pdata at 0x284816000 off 6000 size 1000 virt 120 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\newdev.dll" section .xdata at 0x284817000 off 7000 size 1000 virt 12c flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\newdev.dll" section .bss at 0x284818000 off 0 size 0 virt 140 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\newdev.dll" section .edata at 0x284819000 off 8000 size 1000 virt 649 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\newdev.dll" section .idata at 0x28481a000 off 9000 size 1000 virt 60c flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\newdev.dll" section .reloc at 0x28481b000 off a000 size 1000 virt 20 flags 42000040 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"setupapi.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\setupapi.dll" for L"setupapi.dll" at 000000021A7E0000, count=2 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\newdev.dll" 000000000045C970 0000000284810000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\newdev.dll" at 0000000284810000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\newdev.dll" at 0000000284810000 0028:002c:trace:module:process_attach (L"newdev.dll",0000000000000000) - START 0028:002c:trace:module:MODULE_InitDLL (0000000284810000 L"newdev.dll",PROCESS_ATTACH,0000000000000000) 0000000284811DD0 - CALL 0028:002c:trace:module:MODULE_InitDLL (0000000284810000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:process_attach (L"newdev.dll",0000000000000000) - END 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E4A0, base 000000000031E498. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E190, base 000000000031E188. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000021A7E0000, 000000021A817560, 0000000000000000, 000000007B60C498, 000000021A847BB8, 0x00000000) 0028:002c:trace:module:load_dll looking for L"ole32.dll" in (null) 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=6 0028:002c:trace:module:load_dll looking for L"winemac.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:get_load_order looking for L"C:\\windows\\system32\\winemac.drv" 0028:002c:trace:module:get_load_order got hardcoded default for L"winemac.drv" 0028:002c:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\winemac.drv" is a fake Wine dll 0028:002c:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=7 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=11 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"win32u.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AD60000, count=3 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\winemac.drv" 0000000000447B50 000000006FB10000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\winemac.drv" at 000000006FB10000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\winemac.drv" at 000000006FB10000 0028:002c:trace:module:process_attach (L"winemac.drv",0000000000000000) - START 0028:002c:trace:module:MODULE_InitDLL (000000006FB10000 L"winemac.drv",PROCESS_ATTACH,0000000000000000) 000000006FB28C10 - CALL 0028:002c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031B620. 0028:002c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\wineboot.exe" 0028:002c:trace:module:FindResourceExW 000000006FB10000 #0006 #0011 0000 0028:002c:trace:module:LoadResource 000000006FB10000 000000006FB8E9D8 0028:002c:trace:module:FindResourceExW 000000006FB10000 #0006 #0011 0000 0028:002c:trace:module:LoadResource 000000006FB10000 000000006FB8E9D8 0028:002c:trace:module:FindResourceExW 000000006FB10000 #0006 #0011 0000 0028:002c:trace:module:LoadResource 000000006FB10000 000000006FB8E9D8 0028:002c:trace:module:FindResourceExW 000000006FB10000 #0006 #0011 0000 0028:002c:trace:module:LoadResource 000000006FB10000 000000006FB8E9D8 0028:002c:trace:module:FindResourceExW 000000006FB10000 #0006 #0011 0000 0028:002c:trace:module:LoadResource 000000006FB10000 000000006FB8E9D8 0028:002c:trace:module:FindResourceExW 000000006FB10000 #0006 #0011 0000 0028:002c:trace:module:LoadResource 000000006FB10000 000000006FB8E9D8 0028:002c:trace:module:FindResourceExW 000000006FB10000 #0006 #0011 0000 0028:002c:trace:module:LoadResource 000000006FB10000 000000006FB8E9D8 0028:002c:trace:module:FindResourceExW 000000006FB10000 #0006 #0012 0000 0028:002c:trace:module:LoadResource 000000006FB10000 000000006FB8EBC8 0028:002c:trace:module:FindResourceExW 000000006FB10000 #0006 #0012 0000 0028:002c:trace:module:LoadResource 000000006FB10000 000000006FB8EBC8 0028:002c:trace:module:FindResourceExW 000000006FB10000 #0006 #0012 0000 0028:002c:trace:module:LoadResource 000000006FB10000 000000006FB8EBC8 0028:002c:trace:module:FindResourceExW 000000006FB10000 #0006 #0012 0000 0028:002c:trace:module:LoadResource 000000006FB10000 000000006FB8EBC8 0028:002c:trace:module:FindResourceExW 000000006FB10000 #0006 #0012 0000 0028:002c:trace:module:LoadResource 000000006FB10000 000000006FB8EBC8 0028:002c:trace:module:MODULE_InitDLL (000000006FB10000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:process_attach (L"winemac.drv",0000000000000000) - END 0028:002c:trace:module:EnumResourceNamesExW 0000000000000000 #000e 000000006FB1FB00 31ceb8 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031CC10, base 000000000031CC08. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0028:002c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0028:002c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0028:002c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C6E0. 0028:002c:trace:module:LoadResource 000000023D820000 000000023D908880 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031BED0, base 000000000031BEC8. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C320. 0028:002c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0028:002c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0028:002c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0028:002c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C6E0. 0028:002c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0028:002c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0028:002c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0028:002c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C6E0. 0028:002c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0028:002c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0028:002c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0028:002c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C6E0. 0028:002c:trace:module:FindResourceExW 000000023D820000 #000c #7f01 0000 0028:002c:trace:module:LoadResource 000000023D820000 000000023D90A4C0 0028:002c:trace:module:FindResourceExW 000000023D820000 #0001 #0009 0000 0028:002c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C6E0. 0028:002c:trace:module:LoadResource 000000023D820000 000000023D9088E0 0028:002c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C320. 0028:002c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0028:002c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0028:002c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0028:002c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C6E0. 0028:002c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0028:002c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0028:002c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0028:002c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C6E0. 0028:002c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0028:002c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0028:002c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0028:002c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C6E0. 0028:002c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0028:002c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0028:002c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0028:002c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C6E0. 0028:002c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0028:002c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0028:002c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0028:002c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C6E0. 0028:002c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0028:002c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0028:002c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0028:002c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C6E0. 0028:002c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0028:002c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0028:002c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0028:002c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C6E0. 0028:002c:trace:module:load_dll looking for L"uxtheme.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:get_load_order looking for L"C:\\windows\\system32\\uxtheme.dll" 0028:002c:trace:module:get_load_order got hardcoded default for L"uxtheme.dll" 0028:002c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 0x2f7230000-0x2f7265000 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .text at 0x2f7231000 off 1000 size 13000 virt 123c0 flags 60000060 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .data at 0x2f7244000 off 14000 size 1000 virt 110 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rodata at 0x2f7245000 off 15000 size 1000 virt 430 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rdata at 0x2f7246000 off 16000 size 16000 virt 15a30 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .pdata at 0x2f725c000 off 2c000 size 1000 virt 87c flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .xdata at 0x2f725d000 off 2d000 size 1000 virt 97c flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .bss at 0x2f725e000 off 0 size 0 virt 4a0 flags c0000080 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .edata at 0x2f725f000 off 2e000 size 2000 virt 1de0 flags 40000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .idata at 0x2f7261000 off 30000 size 2000 virt 14ac flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rsrc at 0x2f7263000 off 32000 size 1000 virt 5f8 flags c0000040 0028:002c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .reloc at 0x2f7264000 off 33000 size 1000 virt bc flags 42000040 0028:002c:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=8 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 0028:002c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=12 0028:002c:trace:module:import_dll is not hybrid module 0028:002c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\uxtheme.dll" 0000000000447F40 00000002F7230000 0028:002c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\uxtheme.dll" at 00000002F7230000: builtin 0028:002c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 00000002F7230000 0028:002c:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - START 0028:002c:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_ATTACH,0000000000000000) 00000002F72424B0 - CALL 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C510, base 000000000031C508. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C6C0, base 000000000031C6B8. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000448160, dll_characteristics 0000000000000000, name 000000000031C8E0, base 000000000031C878. 0028:002c:trace:module:LdrGetDllHandleEx L"C:\\windows\\resources\\themes\\light\\light.msstyles" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 0028:002c:trace:module:FindResourceExW 0000000000F10001 L"PACKTHEM_VERSION" #0001 0000 0028:002c:trace:module:LoadResource 0000000000F10001 0000000000F15310 0028:002c:trace:module:FindResourceExW 0000000000F10001 L"COLORNAMES" #0001 0000 0028:002c:trace:module:LoadResource 0000000000F10001 0000000000F152F0 0028:002c:trace:module:FindResourceExW 0000000000F10001 L"SIZENAMES" #0001 0000 0028:002c:trace:module:LoadResource 0000000000F10001 0000000000F15320 0028:002c:trace:module:FindResourceExW 0000000000F10001 L"FILERESNAMES" #0001 0000 0028:002c:trace:module:LoadResource 0000000000F10001 0000000000F15300 0028:002c:trace:module:FindResourceExW 0000000000F10001 L"TEXTFILE" L"BLUE_INI" 0000 0028:002c:trace:module:LoadResource 0000000000F10001 0000000000F15330 0028:002c:fixme:msg:pack_message msg 14 (WM_ERASEBKGND) not supported yet 0028:002c:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - END 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031D250, base 000000000031D248. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000021A7E0000, 000000021A817560, 0000000000000000, 000000007B60C498, 000000021A847BC0, 0x00000000) 0030:00f4:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:00f4:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:00f4:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:00f4:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:00f4:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:00f4:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x3198d8,0x00000008,0x0) 0030:00f4:trace:module:LdrShutdownThread () 0030:00f4:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_DETACH,0000000000000000) 0000000231B26040 - CALL 0030:00f4:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:00f4:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_DETACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:00f4:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:00f4:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_DETACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:00f4:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:00f8:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:00f8:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:00f8:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:00f8:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:00f8:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:00f8:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:0050:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\winebus.sys" 0000000000000000 0) 0030:0050:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\winebus.sys" 0000000000451420 40) 0030:0050:trace:module:GetBinaryTypeW L"C:\\windows\\system32\\drivers\\winebus.sys" 0030:0050:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\winedevice.exe" 0000000000000000 0) 0030:0050:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\winedevice.exe" 0000000000458180 35) 0030:0050:trace:process:CreateProcessInternalW app (null) cmdline L"C:\\windows\\system32\\winedevice.exe" 0030:0050:trace:process:find_exe_file looking for L"C:\\windows\\system32\\winedevice.exe" in L"C:\\windows\\system32;.;C:\\windows\\system32;C:\\windows\\system;C:\\windows;" 0030:0050:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\winedevice.exe" image L"C:\\windows\\system32\\winedevice.exe" cmdline L"C:\\windows\\system32\\winedevice.exe" parent 0x0 0030:0050:trace:process:send_to_cx_loader loader (null) wineserversocket 18 stdin_fd -1 stdout_fd -1 unixdir (null) winedebug (null) wineloader (null) 0030:0050:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 00fc:0100:trace:module:get_load_order looking for L"C:\\windows\\system32\\winedevice.exe" 00fc:0100:trace:module:get_load_order got hardcoded default for L"winedevice.exe" 00fc:0100:trace:module:get_load_order looking for L"C:\\windows\\system32\\winedevice.exe" 00fc:0100:trace:module:get_load_order got hardcoded default for L"winedevice.exe" 00fc:0100:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\winedevice.exe" at 0x140000000-0x14000a000 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winedevice.exe" section .text at 0x140001000 off 1000 size 2000 virt 13f0 flags 60000020 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winedevice.exe" section .data at 0x140003000 off 3000 size 1000 virt 60 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winedevice.exe" section .rdata at 0x140004000 off 4000 size 1000 virt 2a0 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winedevice.exe" section .pdata at 0x140005000 off 5000 size 1000 virt d8 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winedevice.exe" section .xdata at 0x140006000 off 6000 size 1000 virt e0 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winedevice.exe" section .bss at 0x140007000 off 0 size 0 virt 160 flags c0000080 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winedevice.exe" section .idata at 0x140008000 off 7000 size 1000 virt 7a4 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winedevice.exe" section .reloc at 0x140009000 off 8000 size 1000 virt 10 flags 42000040 00fc:0100:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 00fc:0100:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0030:0050:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\winedevice.exe" pid 00fc tid 0100 handles 0x13c/0x140 0030:0050:trace:process:CreateProcessInternalW started process pid 00fc tid 0100 00fc:0100:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 00fc:0100:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\winedevice.exe" 00000000004315F0 0000000140000000 00fc:0100:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\winedevice.exe" at 0000000140000000: builtin 00fc:0100:trace:module:load_dll looking for L"kernel32.dll" in (null) 00fc:0100:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernel32.dll" 00fc:0100:trace:module:get_load_order got hardcoded default for L"kernel32.dll" 00fc:0100:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 00fc:0100:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00fc:0100:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernelbase.dll" 00fc:0100:trace:module:get_load_order got hardcoded default for L"kernelbase.dll" 00fc:0100:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 00fc:0100:trace:module:load_dll looking for L"ntdll.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 0000000000431E70 000000007B000000 00fc:0100:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 00fc:0100:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"ntdll.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000431B50 000000007B600000 00fc:0100:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 00fc:0100:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 00fc:0100:trace:module:load_dll looking for L"advapi32.dll" in (null) 00fc:0100:trace:module:get_load_order looking for L"C:\\windows\\system32\\advapi32.dll" 00fc:0100:trace:module:get_load_order got hardcoded default for L"advapi32.dll" 00fc:0100:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 00fc:0100:trace:module:load_dll looking for L"kernel32.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"msvcrt.dll" in (null) 00fc:0100:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvcrt.dll" 00fc:0100:trace:module:get_load_order got hardcoded default for L"msvcrt.dll" 00fc:0100:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 00fc:0100:trace:module:load_dll looking for L"kernel32.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"ntdll.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 0000000000432320 00000001C8DB0000 00fc:0100:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 00fc:0100:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"ntdll.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"sechost.dll" in (null) 00fc:0100:trace:module:get_load_order looking for L"C:\\windows\\system32\\sechost.dll" 00fc:0100:trace:module:get_load_order got hardcoded default for L"sechost.dll" 00fc:0100:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 00fc:0100:trace:module:load_dll looking for L"kernel32.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"ntdll.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00fc:0100:trace:module:get_load_order looking for L"C:\\windows\\system32\\ucrtbase.dll" 00fc:0100:trace:module:get_load_order got hardcoded default for L"ucrtbase.dll" 00fc:0100:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 00fc:0100:trace:module:load_dll looking for L"kernel32.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"ntdll.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 00000000004328B0 00000003AF670000 00fc:0100:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 00fc:0100:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 00000000004325C0 000000032A700000 00fc:0100:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 00fc:0100:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 0000000000432040 0000000330260000 00fc:0100:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 00fc:0100:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"kernel32.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"ntdll.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"ntoskrnl.exe" in (null) 00fc:0100:trace:module:get_load_order looking for L"C:\\windows\\system32\\ntoskrnl.exe" 00fc:0100:trace:module:get_load_order got hardcoded default for L"ntoskrnl.exe" 00fc:0100:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" at 0x2279a0000-0x2279f9000 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .text at 0x2279a1000 off 1000 size 25000 virt 24e20 flags 60000060 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .data at 0x2279c6000 off 26000 size 1000 virt 530 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .rodata at 0x2279c7000 off 27000 size 6000 virt 5e74 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .rdata at 0x2279cd000 off 2d000 size 6000 virt 5050 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .pdata at 0x2279d3000 off 33000 size 2000 virt 11c4 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .xdata at 0x2279d5000 off 35000 size 2000 virt 10b4 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .bss at 0x2279d7000 off 0 size 0 virt 620 flags c0000080 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .edata at 0x2279d8000 off 37000 size 18000 virt 1777e flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .idata at 0x2279f0000 off 4f000 size 7000 virt 68bc flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .rsrc at 0x2279f7000 off 56000 size 1000 virt 3b8 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" section .reloc at 0x2279f8000 off 57000 size 1000 virt 144 flags 42000040 00fc:0100:trace:module:load_dll looking for L"advapi32.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"kernel32.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"msvcrt.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\msvcrt.dll" for L"msvcrt.dll" at 00000001C8DB0000, count=2 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"ntdll.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" 0000000000432A80 00000002279A0000 00fc:0100:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ntoskrnl.exe" at 00000002279A0000: builtin 00fc:0100:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ntoskrnl.exe" at 00000002279A0000 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 00fc:0100:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 00fc:0100:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00fc:0100:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 00fc:0100:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 00fc:0100:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 00fc:0100:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 00fc:0100:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 00fc:0100:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 00fc:0100:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 00fc:0100:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000434DE0 17) 00fc:0100:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000434EF0, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 00fc:0100:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 00fc:0100:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 00fc:0100:trace:module:get_load_order got hardcoded default for L"tzres.dll" 00fc:0100:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 00fc:0100:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 00fc:0100:trace:module:LoadResource 0000000010000002 00000000100077D8 00fc:0100:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 00fc:0100:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000434E30 17) 00fc:0100:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000435010, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 00fc:0100:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 00fc:0100:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 00fc:0100:trace:module:get_load_order got hardcoded default for L"tzres.dll" 00fc:0100:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 00fc:0100:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 00fc:0100:trace:module:LoadResource 0000000010000002 00000000100077D8 00fc:0100:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00fc:0100:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 00fc:0100:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 00fc:0100:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00fc:0100:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 00fc:0100:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 00fc:0100:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 00fc:0100:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 00fc:0100:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F3B0. 00fc:0100:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\winedevice.exe" 00fc:0100:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F400. 00fc:0100:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\winedevice.exe" 00fc:0100:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 00fc:0100:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00fc:0100:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 00fc:0100:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 00fc:0100:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 00fc:0100:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 00fc:0100:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 00fc:0100:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\winedevice.exe" 00fc:0100:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 00fc:0100:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\winedevice.exe" 00fc:0100:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00fc:0100:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 00fc:0100:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 00fc:0100:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00fc:0100:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 00fc:0100:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 00fc:0100:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00fc:0100:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 00fc:0100:trace:module:process_attach (L"ntoskrnl.exe",000000000031FB00) - START 00fc:0100:trace:module:MODULE_InitDLL (00000002279A0000 L"ntoskrnl.exe",PROCESS_ATTACH,000000000031FB00) 00000002279C3D50 - CALL 00fc:0100:trace:module:LdrRegisterDllNotification (0, 00000002279AEE00, 0000000000000000, 00000002279D7420) 00fc:0100:trace:module:MODULE_InitDLL (00000002279A0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 00fc:0100:trace:module:process_attach (L"ntoskrnl.exe",000000000031FB00) - END 00fc:0100:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 00fc:0100:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F7D0, base 000000000031F7C8. 00fc:0100:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0100:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726624, 0x00000000) 00fc:0100:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 00fc:0100:trace:module:get_load_order looking for L"C:\\windows\\system32\\rpcrt4.dll" 00fc:0100:trace:module:get_load_order_value got environment b for L"rpcrt4" 00fc:0100:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0x231ae0000-0x231b62000 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .text at 0x231ae1000 off 1000 size 47000 virt 46400 flags 60000060 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .data at 0x231b28000 off 48000 size 1000 virt 710 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rodata at 0x231b29000 off 49000 size 2000 virt 1b44 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rdata at 0x231b2b000 off 4b000 size 15000 virt 14b90 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .pdata at 0x231b40000 off 60000 size 3000 virt 2334 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .xdata at 0x231b43000 off 63000 size 3000 virt 289c flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .bss at 0x231b46000 off 0 size 0 virt 690 flags c0000080 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .edata at 0x231b47000 off 66000 size 17000 virt 16730 flags 40000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .idata at 0x231b5e000 off 7d000 size 2000 virt 19a8 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rsrc at 0x231b60000 off 7f000 size 1000 virt 3a8 flags c0000040 00fc:0100:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .reloc at 0x231b61000 off 80000 size 1000 virt 504 flags 42000040 00fc:0100:trace:module:load_dll looking for L"advapi32.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"kernel32.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"ntdll.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00fc:0100:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00fc:0100:trace:module:import_dll is not hybrid module 00fc:0100:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rpcrt4.dll" 000000000043A7B0 0000000231AE0000 00fc:0100:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000: builtin 00fc:0100:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000 00fc:0100:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - START 00fc:0100:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EDE0, base 000000000031EDD8. 00fc:0100:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0100:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EAE0, base 000000000031EAD8. 00fc:0100:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0100:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_ATTACH,0000000000000000) 0000000231B26040 - CALL 00fc:0100:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00fc:0100:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - END 00fc:0100:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EED0, base 000000000031EEC8. 00fc:0100:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0100:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726704, 0x00000000) 00fc:0100:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F0D0, base 000000000031F0C8. 00fc:0100:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0100:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266EC, 0x00000000) 00fc:0100:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726714, 0x00000000) 00fc:0100:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266A4, 0x00000000) 00fc:0100:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726684, 0x00000000) 0030:0104:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:0104:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:0104:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:0104:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:0104:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:0104:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0100:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266AC, 0x00000000) 00fc:0100:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266BC, 0x00000000) 00fc:0100:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72661C, 0x00000000) 00fc:0100:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72667C, 0x00000000) 00fc:0100:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266DC, 0x00000000) 00fc:0108:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 00fc:0108:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0108:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 00fc:0108:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0108:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 00fc:0108:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72660C, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72665C, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726614, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726664, 0x00000000) 00fc:010c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 00fc:010c:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:010c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 00fc:010c:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:010c:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 00fc:010c:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:010c:trace:module:LdrAddDllDirectory L"\\??\\C:\\windows\\system32\\drivers" 00fc:010c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 00000000012CF8D0, base 00000000012CF8C8. 00fc:010c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:010c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 00000000012CF5C0, base 00000000012CF5B8. 00fc:010c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:010c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266C4, 0x00000000) 00fc:010c:trace:process:NtQueryInformationProcess (0x54,0x00000000,0x440258,0x00000030,0x0) 00fc:010c:trace:process:NtQueryInformationProcess (0x54,0x0000001a,0x12cf2b8,0x00000008,0x0) 00fc:010c:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DA0, 0000000000000000, 000000007B60C498, 00000002279F2944, 0x00000000) 00fc:010c:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 00fc:010c:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=2 00fc:010c:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DA0, 0000000000000000, 000000007B60C498, 00000002279F2934, 0x00000000) 00fc:010c:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DA0, 0000000000000000, 000000007B60C498, 00000002279F294C, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72663C, 0x00000000) 00fc:0108:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\winebus.sys" 0000000000000000 0) 00fc:0108:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\winebus.sys" 00000000004405B0 40) 00fc:0108:trace:module:load_dll looking for L"C:\\windows\\system32\\drivers\\winebus.sys" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:get_load_order looking for L"C:\\windows\\system32\\drivers\\winebus.sys" 00fc:0108:trace:module:get_load_order got hardcoded default for L"C:\\windows\\system32\\drivers\\winebus.sys" 00fc:0108:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\drivers\\winebus.sys" at 0x1c9230000-0x1c923e000 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winebus.sys" section .text at 0x1c9231000 off 1000 size 4000 virt 3e50 flags 60000020 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winebus.sys" section .data at 0x1c9235000 off 5000 size 1000 virt d0 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winebus.sys" section .rdata at 0x1c9236000 off 6000 size 1000 virt ca0 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winebus.sys" section .pdata at 0x1c9237000 off 7000 size 1000 virt 15c flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winebus.sys" section .xdata at 0x1c9238000 off 8000 size 1000 virt 18c flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winebus.sys" section .bss at 0x1c9239000 off 0 size 0 virt 210 flags c0000080 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winebus.sys" section .edata at 0x1c923a000 off 9000 size 1000 virt 118 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winebus.sys" section .idata at 0x1c923b000 off a000 size 1000 virt 9a8 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winebus.sys" section .rsrc at 0x1c923c000 off b000 size 1000 virt 230 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winebus.sys" section .reloc at 0x1c923d000 off c000 size 1000 virt 28 flags 42000040 00fc:0108:trace:module:load_dll looking for L"hidparse.sys" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:get_load_order looking for L"C:\\windows\\system32\\drivers\\hidparse.sys" 00fc:0108:trace:module:get_load_order got hardcoded default for L"C:\\windows\\system32\\drivers\\hidparse.sys" 00fc:0108:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\drivers\\hidparse.sys" at 0x2adf30000-0x2adf41000 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidparse.sys" section .text at 0x2adf31000 off 1000 size 6000 virt 57a0 flags 60000020 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidparse.sys" section .data at 0x2adf37000 off 7000 size 1000 virt 80 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidparse.sys" section .rodata at 0x2adf38000 off 8000 size 1000 virt 190 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidparse.sys" section .rdata at 0x2adf39000 off 9000 size 2000 virt 1480 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidparse.sys" section .pdata at 0x2adf3b000 off b000 size 1000 virt 2c4 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidparse.sys" section .xdata at 0x2adf3c000 off c000 size 1000 virt 320 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidparse.sys" section .bss at 0x2adf3d000 off 0 size 0 virt 140 flags c0000080 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidparse.sys" section .edata at 0x2adf3e000 off d000 size 1000 virt a10 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidparse.sys" section .idata at 0x2adf3f000 off e000 size 1000 virt 488 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidparse.sys" section .reloc at 0x2adf40000 off f000 size 1000 virt 20 flags 42000040 00fc:0108:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ntoskrnl.exe" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ntoskrnl.exe" for L"ntoskrnl.exe" at 00000002279A0000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\drivers\\hidparse.sys" 00000000004425A0 00000002ADF30000 00fc:0108:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\drivers\\hidparse.sys" at 00000002ADF30000: builtin 00fc:0108:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\drivers\\hidparse.sys" at 00000002ADF30000 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ntoskrnl.exe" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ntoskrnl.exe" for L"ntoskrnl.exe" at 00000002279A0000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\drivers\\winebus.sys" 00000000004422B0 00000001C9230000 00fc:0108:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\drivers\\winebus.sys" at 00000001C9230000: builtin 00fc:0108:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\drivers\\winebus.sys" at 00000001C9230000 00fc:0108:trace:module:process_attach (L"winebus.sys",0000000000000000) - START 00fc:0108:trace:module:process_attach (L"hidparse.sys",0000000000000000) - START 00fc:0108:trace:module:MODULE_InitDLL (00000002ADF30000 L"hidparse.sys",PROCESS_ATTACH,0000000000000000) 00000002ADF35CC0 - CALL 00fc:0108:trace:module:MODULE_InitDLL (00000002ADF30000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00fc:0108:trace:module:process_attach (L"hidparse.sys",0000000000000000) - END 00fc:0108:trace:module:process_attach (L"winebus.sys",0000000000000000) - END 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCF840, base 0000000000FCF838. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCF530, base 0000000000FCF528. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F299C, 0x00000000) 00fc:0108:trace:module:load_dll looking for L"setupapi.dll" in (null) 00fc:0108:trace:module:get_load_order looking for L"C:\\windows\\system32\\setupapi.dll" 00fc:0108:trace:module:get_load_order got hardcoded default for L"setupapi.dll" 00fc:0108:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" at 0x21a7e0000-0x21a856000 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .text at 0x21a7e1000 off 1000 size 37000 virt 365e0 flags 60000060 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .data at 0x21a818000 off 38000 size 1000 virt 230 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rodata at 0x21a819000 off 39000 size 3000 virt 244c flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rdata at 0x21a81c000 off 3c000 size e000 virt d010 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .pdata at 0x21a82a000 off 4a000 size 2000 virt 1818 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .xdata at 0x21a82c000 off 4c000 size 2000 virt 1d24 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .bss at 0x21a82e000 off 0 size 0 virt 720 flags c0000080 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .edata at 0x21a82f000 off 4e000 size 18000 virt 171c8 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .idata at 0x21a847000 off 66000 size 2000 virt 1f34 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rsrc at 0x21a849000 off 68000 size c000 virt bf00 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .reloc at 0x21a855000 off 74000 size 1000 virt d8 flags 42000040 00fc:0108:trace:module:load_dll looking for L"advapi32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"kernel32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ntdll.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=3 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"version.dll" in (null) 00fc:0108:trace:module:get_load_order looking for L"C:\\windows\\system32\\version.dll" 00fc:0108:trace:module:get_load_order got hardcoded default for L"version.dll" 00fc:0108:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 00fc:0108:trace:module:load_dll looking for L"kernel32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ntdll.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 0000000000442AE0 00000002F1FA0000 00fc:0108:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 00000002F1FA0000: builtin 00fc:0108:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 00000002F1FA0000 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\setupapi.dll" 0000000000442780 000000021A7E0000 00fc:0108:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\setupapi.dll" at 000000021A7E0000: builtin 00fc:0108:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\setupapi.dll" at 000000021A7E0000 00fc:0108:trace:module:process_attach (L"setupapi.dll",0000000000000000) - START 00fc:0108:trace:module:process_attach (L"version.dll",0000000000000000) - START 00fc:0108:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,0000000000000000) 00000002F1FA2510 - CALL 00fc:0108:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00fc:0108:trace:module:process_attach (L"version.dll",0000000000000000) - END 00fc:0108:trace:module:MODULE_InitDLL (000000021A7E0000 L"setupapi.dll",PROCESS_ATTACH,0000000000000000) 000000021A816860 - CALL 00fc:0108:trace:module:MODULE_InitDLL (000000021A7E0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00fc:0108:trace:module:process_attach (L"setupapi.dll",0000000000000000) - END 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCF2B0, base 0000000000FCF2A8. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCEFA0, base 0000000000FCEF98. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F2994, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F29B4, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F29A4, 0x00000000) 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCECE0, base 0000000000FCECD8. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F2974, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F297C, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F29BC, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F29D4, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F2964, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F296C, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (000000021A7E0000, 000000021A817560, 0000000000000000, 000000007B60C498, 000000021A847BB8, 0x00000000) 00fc:0108:trace:module:load_dll looking for L"ole32.dll" in (null) 00fc:0108:trace:module:get_load_order looking for L"C:\\windows\\system32\\ole32.dll" 00fc:0108:trace:module:get_load_order got hardcoded default for L"ole32.dll" 00fc:0108:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" at 0x2e8f10000-0x2e902b000 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .text at 0x2e8f11000 off 1000 size a8000 virt a76a0 flags 60000060 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .data at 0x2e8fb9000 off a9000 size 1000 virt 480 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rodata at 0x2e8fba000 off aa000 size 1000 virt 778 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rdata at 0x2e8fbb000 off ab000 size 1e000 virt 1d750 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .pdata at 0x2e8fd9000 off c9000 size 7000 virt 6b10 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .xdata at 0x2e8fe0000 off d0000 size 7000 virt 67c4 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .bss at 0x2e8fe7000 off 0 size 0 virt 210 flags c0000080 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .edata at 0x2e8fe8000 off d7000 size 18000 virt 17412 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .idata at 0x2e9000000 off ef000 size 4000 virt 367c flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rsrc at 0x2e9004000 off f3000 size 25000 virt 24bc0 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .reloc at 0x2e9029000 off 118000 size 2000 virt 1804 flags 42000040 00fc:0108:trace:module:load_dll looking for L"advapi32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"combase.dll" in (null) 00fc:0108:trace:module:get_load_order looking for L"C:\\windows\\system32\\combase.dll" 00fc:0108:trace:module:get_load_order got hardcoded default for L"combase.dll" 00fc:0108:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" at 0x327020000-0x327073000 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .text at 0x327021000 off 1000 size 27000 virt 26590 flags 60000060 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .data at 0x327048000 off 28000 size 1000 virt 580 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rodata at 0x327049000 off 29000 size 2000 virt 16c0 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rdata at 0x32704b000 off 2b000 size d000 virt cf90 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .pdata at 0x327058000 off 38000 size 2000 virt 17a0 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .xdata at 0x32705a000 off 3a000 size 2000 virt 18e4 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .bss at 0x32705c000 off 0 size 0 virt 1a0 flags c0000080 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .edata at 0x32705d000 off 3c000 size 13000 virt 12d6e flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .idata at 0x327070000 off 4f000 size 2000 virt 1804 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .reloc at 0x327072000 off 51000 size 1000 virt 23c flags 42000040 00fc:0108:trace:module:load_dll looking for L"advapi32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"gdi32.dll" in (null) 00fc:0108:trace:module:get_load_order looking for L"C:\\windows\\system32\\gdi32.dll" 00fc:0108:trace:module:get_load_order got hardcoded default for L"gdi32.dll" 00fc:0108:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 00fc:0108:trace:module:load_dll looking for L"advapi32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"kernel32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ntdll.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"user32.dll" in (null) 00fc:0108:trace:module:get_load_order looking for L"C:\\windows\\system32\\user32.dll" 00fc:0108:trace:module:get_load_order got hardcoded default for L"user32.dll" 00fc:0108:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 00fc:0108:trace:module:load_dll looking for L"advapi32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"gdi32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"kernel32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ntdll.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"sechost.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"version.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\version.dll" for L"version.dll" at 00000002F1FA0000, count=2 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"win32u.dll" in (null) 00fc:0108:trace:module:get_load_order looking for L"C:\\windows\\system32\\win32u.dll" 00fc:0108:trace:module:get_load_order got hardcoded default for L"win32u.dll" 00fc:0108:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\win32u.dll" is a fake Wine dll 00fc:0108:trace:module:load_dll looking for L"kernel32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ntdll.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\win32u.dll" 0000000000447DC0 000000006A360000 00fc:0108:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\win32u.dll" at 000000006A360000: builtin 00fc:0108:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\win32u.dll" at 000000006A360000 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\user32.dll" 00000000004479A0 000000023D820000 00fc:0108:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\user32.dll" at 000000023D820000: builtin 00fc:0108:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\user32.dll" at 000000023D820000 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"win32u.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006A360000, count=2 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\gdi32.dll" 0000000000447680 000000026B4C0000 00fc:0108:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000: builtin 00fc:0108:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"kernel32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ntdll.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ole32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=4 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"user32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\combase.dll" 00000000004473E0 0000000327020000 00fc:0108:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\combase.dll" at 0000000327020000: builtin 00fc:0108:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\combase.dll" at 0000000327020000 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"gdi32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"kernel32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"kernelbase.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ntdll.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=5 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"user32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=3 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ole32.dll" 0000000000446A80 00000002E8F10000 00fc:0108:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ole32.dll" at 00000002E8F10000: builtin 00fc:0108:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ole32.dll" at 00000002E8F10000 00fc:0108:trace:module:process_attach (L"ole32.dll",0000000000000000) - START 00fc:0108:trace:module:process_attach (L"combase.dll",0000000000000000) - START 00fc:0108:trace:module:process_attach (L"gdi32.dll",0000000000000000) - START 00fc:0108:trace:module:process_attach (L"user32.dll",0000000000000000) - START 00fc:0108:trace:module:process_attach (L"win32u.dll",0000000000000000) - START 00fc:0108:trace:module:MODULE_InitDLL (000000006A360000 L"win32u.dll",PROCESS_ATTACH,0000000000000000) 000000006A409460 - CALL 00fc:0108:trace:module:MODULE_InitDLL (000000006A360000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00fc:0108:trace:module:process_attach (L"win32u.dll",0000000000000000) - END 00fc:0108:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,0000000000000000) 000000023D8C5690 - CALL 00fc:0108:trace:module:load_dll looking for L"imm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00fc:0108:trace:module:get_load_order looking for L"C:\\windows\\system32\\imm32.dll" 00fc:0108:trace:module:get_load_order got hardcoded default for L"imm32.dll" 00fc:0108:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 00fc:0108:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=4 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imm32.dll" 0000000000448250 00000003AFD00000 00fc:0108:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imm32.dll" at 00000003AFD00000: builtin 00fc:0108:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imm32.dll" at 00000003AFD00000 00fc:0108:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 00fc:0108:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCD270, base 0000000000FCD268. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCD710, base 0000000000FCD708. 00fc:0108:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCD220, base 0000000000FCD218. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00fc:0108:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 00fc:0108:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00fc:0108:trace:module:process_attach (L"user32.dll",0000000000000000) - END 00fc:0108:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,0000000000000000) 000000026B509F00 - CALL 00fc:0108:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00fc:0108:trace:module:process_attach (L"gdi32.dll",0000000000000000) - END 00fc:0108:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_ATTACH,0000000000000000) 00000003270465C0 - CALL 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCD860, base 0000000000FCD858. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00fc:0108:trace:module:process_attach (L"combase.dll",0000000000000000) - END 00fc:0108:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_ATTACH,0000000000000000) 00000002E8FB74E0 - CALL 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCD910, base 0000000000FCD908. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00fc:0108:trace:module:process_attach (L"ole32.dll",0000000000000000) - END 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCCE20, base 0000000000FCCE18. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00fc:0108:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00fc:0108:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00fc:0108:trace:module:LdrGetDllFullName module 000000023D820000, name 0000000000FCC8F0. 00fc:0108:trace:module:LoadResource 000000023D820000 000000023D908880 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCC0E0, base 0000000000FCC0D8. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:LdrGetDllFullName module 000000023D820000, name 0000000000FCC530. 00fc:0108:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00fc:0108:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00fc:0108:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00fc:0108:trace:module:LdrGetDllFullName module 000000023D820000, name 0000000000FCC8F0. 00fc:0108:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00fc:0108:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00fc:0108:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00fc:0108:trace:module:LdrGetDllFullName module 000000023D820000, name 0000000000FCC8F0. 00fc:0108:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00fc:0108:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00fc:0108:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00fc:0108:trace:module:LdrGetDllFullName module 000000023D820000, name 0000000000FCC8F0. 00fc:0108:trace:module:FindResourceExW 000000023D820000 #000c #7f01 0000 00fc:0108:trace:module:LoadResource 000000023D820000 000000023D90A4C0 00fc:0108:trace:module:FindResourceExW 000000023D820000 #0001 #0009 0000 00fc:0108:trace:module:LdrGetDllFullName module 000000023D820000, name 0000000000FCC8F0. 00fc:0108:trace:module:LoadResource 000000023D820000 000000023D9088E0 00fc:0108:trace:module:LdrGetDllFullName module 000000023D820000, name 0000000000FCC530. 00fc:0108:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00fc:0108:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00fc:0108:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00fc:0108:trace:module:LdrGetDllFullName module 000000023D820000, name 0000000000FCC8F0. 00fc:0108:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00fc:0108:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00fc:0108:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00fc:0108:trace:module:LdrGetDllFullName module 000000023D820000, name 0000000000FCC8F0. 00fc:0108:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00fc:0108:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00fc:0108:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00fc:0108:trace:module:LdrGetDllFullName module 000000023D820000, name 0000000000FCC8F0. 00fc:0108:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00fc:0108:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00fc:0108:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00fc:0108:trace:module:LdrGetDllFullName module 000000023D820000, name 0000000000FCC8F0. 00fc:0108:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00fc:0108:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00fc:0108:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00fc:0108:trace:module:LdrGetDllFullName module 000000023D820000, name 0000000000FCC8F0. 00fc:0108:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00fc:0108:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00fc:0108:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00fc:0108:trace:module:LdrGetDllFullName module 000000023D820000, name 0000000000FCC8F0. 00fc:0108:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 00fc:0108:trace:module:LoadResource 000000023D820000 000000023D90A4B0 00fc:0108:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 00fc:0108:trace:module:LdrGetDllFullName module 000000023D820000, name 0000000000FCC8F0. 00fc:0108:trace:module:load_dll looking for L"uxtheme.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00fc:0108:trace:module:get_load_order looking for L"C:\\windows\\system32\\uxtheme.dll" 00fc:0108:trace:module:get_load_order got hardcoded default for L"uxtheme.dll" 00fc:0108:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 0x2f7230000-0x2f7265000 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .text at 0x2f7231000 off 1000 size 13000 virt 123c0 flags 60000060 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .data at 0x2f7244000 off 14000 size 1000 virt 110 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rodata at 0x2f7245000 off 15000 size 1000 virt 430 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rdata at 0x2f7246000 off 16000 size 16000 virt 15a30 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .pdata at 0x2f725c000 off 2c000 size 1000 virt 87c flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .xdata at 0x2f725d000 off 2d000 size 1000 virt 97c flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .bss at 0x2f725e000 off 0 size 0 virt 4a0 flags c0000080 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .edata at 0x2f725f000 off 2e000 size 2000 virt 1de0 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .idata at 0x2f7261000 off 30000 size 2000 virt 14ac flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rsrc at 0x2f7263000 off 32000 size 1000 virt 5f8 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .reloc at 0x2f7264000 off 33000 size 1000 virt bc flags 42000040 00fc:0108:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=3 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=5 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\uxtheme.dll" 0000000000449320 00000002F7230000 00fc:0108:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\uxtheme.dll" at 00000002F7230000: builtin 00fc:0108:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 00000002F7230000 00fc:0108:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - START 00fc:0108:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_ATTACH,0000000000000000) 00000002F72424B0 - CALL 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCC720, base 0000000000FCC718. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCC8D0, base 0000000000FCC8C8. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000449540, dll_characteristics 0000000000000000, name 0000000000FCCAF0, base 0000000000FCCA88. 00fc:0108:trace:module:LdrGetDllHandleEx L"C:\\windows\\resources\\themes\\light\\light.msstyles" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;") 00fc:0108:trace:module:FindResourceExW 0000000001620001 L"PACKTHEM_VERSION" #0001 0000 00fc:0108:trace:module:LoadResource 0000000001620001 0000000001625310 00fc:0108:trace:module:FindResourceExW 0000000001620001 L"COLORNAMES" #0001 0000 00fc:0108:trace:module:LoadResource 0000000001620001 00000000016252F0 00fc:0108:trace:module:FindResourceExW 0000000001620001 L"SIZENAMES" #0001 0000 00fc:0108:trace:module:LoadResource 0000000001620001 0000000001625320 00fc:0108:trace:module:FindResourceExW 0000000001620001 L"FILERESNAMES" #0001 0000 00fc:0108:trace:module:LoadResource 0000000001620001 0000000001625300 00fc:0108:trace:module:FindResourceExW 0000000001620001 L"TEXTFILE" L"BLUE_INI" 0000 00fc:0108:trace:module:LoadResource 0000000001620001 0000000001625330 00fc:0108:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00fc:0108:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - END 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCD460, base 0000000000FCD458. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (000000021A7E0000, 000000021A817560, 0000000000000000, 000000007B60C498, 000000021A847BC0, 0x00000000) 00fc:0108:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0xfc9ae8,0x00000008,0x0) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266B4, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A72662C, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A726634, 0x00000000) 00fc:0108:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\winehid.sys" 0000000000000000 0) 00fc:0108:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\drivers\\winehid.sys" 00000000004481A0 40) 00fc:0108:trace:module:load_dll looking for L"C:\\windows\\system32\\drivers\\winehid.sys" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:get_load_order looking for L"C:\\windows\\system32\\drivers\\winehid.sys" 00fc:0108:trace:module:get_load_order got hardcoded default for L"C:\\windows\\system32\\drivers\\winehid.sys" 00fc:0108:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\drivers\\winehid.sys" at 0x3ba2a0000-0x3ba2ab000 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winehid.sys" section .text at 0x3ba2a1000 off 1000 size 1000 virt ff0 flags 60000020 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winehid.sys" section .data at 0x3ba2a2000 off 2000 size 1000 virt 40 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winehid.sys" section .rdata at 0x3ba2a3000 off 3000 size 1000 virt 1c0 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winehid.sys" section .pdata at 0x3ba2a4000 off 4000 size 1000 virt cc flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winehid.sys" section .xdata at 0x3ba2a5000 off 5000 size 1000 virt cc flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winehid.sys" section .bss at 0x3ba2a6000 off 0 size 0 virt 140 flags c0000080 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winehid.sys" section .edata at 0x3ba2a7000 off 6000 size 1000 virt fd flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winehid.sys" section .idata at 0x3ba2a8000 off 7000 size 1000 virt 424 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winehid.sys" section .rsrc at 0x3ba2a9000 off 8000 size 1000 virt 238 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\winehid.sys" section .reloc at 0x3ba2aa000 off 9000 size 1000 virt 10 flags 42000040 00fc:0108:trace:module:load_dll looking for L"hidclass.sys" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:get_load_order looking for L"C:\\windows\\system32\\drivers\\hidclass.sys" 00fc:0108:trace:module:get_load_order got hardcoded default for L"C:\\windows\\system32\\drivers\\hidclass.sys" 00fc:0108:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\drivers\\hidclass.sys" at 0x31df10000-0x31df24000 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidclass.sys" section .text at 0x31df11000 off 1000 size 4000 virt 3d30 flags 60000020 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidclass.sys" section .data at 0x31df15000 off 5000 size 1000 virt a0 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidclass.sys" section .rodata at 0x31df16000 off 6000 size 1000 virt 8 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidclass.sys" section .rdata at 0x31df17000 off 7000 size 3000 virt 2b70 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidclass.sys" section .pdata at 0x31df1a000 off a000 size 1000 virt 228 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidclass.sys" section .xdata at 0x31df1b000 off b000 size 1000 virt 284 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidclass.sys" section .bss at 0x31df1c000 off 0 size 0 virt 140 flags c0000080 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidclass.sys" section .edata at 0x31df1d000 off c000 size 4000 virt 3138 flags 40000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidclass.sys" section .idata at 0x31df21000 off 10000 size 1000 virt aa4 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidclass.sys" section .rsrc at 0x31df22000 off 11000 size 1000 virt 160 flags c0000040 00fc:0108:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\drivers\\hidclass.sys" section .reloc at 0x31df23000 off 12000 size 1000 virt 70 flags 42000040 00fc:0108:trace:module:load_dll looking for L"hidparse.sys" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\drivers\\hidparse.sys" for L"hidparse.sys" at 00000002ADF30000, count=2 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ntoskrnl.exe" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ntoskrnl.exe" for L"ntoskrnl.exe" at 00000002279A0000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"win32u.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006A360000, count=3 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\drivers\\hidclass.sys" 00000000004470A0 000000031DF10000 00fc:0108:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\drivers\\hidclass.sys" at 000000031DF10000: builtin 00fc:0108:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\drivers\\hidclass.sys" at 000000031DF10000 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ntoskrnl.exe" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ntoskrnl.exe" for L"ntoskrnl.exe" at 00000002279A0000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32\\drivers;C:\\windows\\system32;C:\\windows\\system32\\drivers;C:\\windows\\system32\\" 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 00fc:0108:trace:module:import_dll is not hybrid module 00fc:0108:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\drivers\\winehid.sys" 0000000000446DB0 00000003BA2A0000 00fc:0108:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\drivers\\winehid.sys" at 00000003BA2A0000: builtin 00fc:0108:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\drivers\\winehid.sys" at 00000003BA2A0000 00fc:0108:trace:module:process_attach (L"winehid.sys",0000000000000000) - START 00fc:0108:trace:module:process_attach (L"hidclass.sys",0000000000000000) - START 00fc:0108:trace:module:MODULE_InitDLL (000000031DF10000 L"hidclass.sys",PROCESS_ATTACH,0000000000000000) 000000031DF14220 - CALL 00fc:0108:trace:module:MODULE_InitDLL (000000031DF10000,PROCESS_ATTACH,0000000000000000) - RETURN 1 00fc:0108:trace:module:process_attach (L"hidclass.sys",0000000000000000) - END 00fc:0108:trace:module:process_attach (L"winehid.sys",0000000000000000) - END 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCDE40, base 0000000000FCDE38. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCD9D0, base 0000000000FCD9C8. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F298C, 0x00000000) 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCDCA0, base 0000000000FCDC98. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCD990, base 0000000000FCD988. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 0000000000FCD360, base 0000000000FCD358. 00fc:0108:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F29C4, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F2984, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (000000021A7E0000, 000000021A8175A0, 0000000000000000, 000000007B60C498, 000000021A847DB0, 0x00000000) 00fc:0108:trace:module:load_dll looking for L"user32.dll" in (null) 00fc:0108:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=6 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F29AC, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DA0, 0000000000000000, 000000007B60C498, 00000002279F28EC, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DA0, 0000000000000000, 000000007B60C498, 00000002279F28F4, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DA0, 0000000000000000, 000000007B60C498, 00000002279F2914, 0x00000000) 005c:0110:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 005c:0110:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0110:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 005c:0110:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0110:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 005c:0110:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0110:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",THREAD_ATTACH,0000000000000000) 000000023D8C5690 - CALL 005c:0110:trace:module:MODULE_InitDLL (000000023D820000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0110:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",THREAD_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 005c:0110:trace:module:MODULE_InitDLL (00000003AFD00000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DA0, 0000000000000000, 000000007B60C498, 00000002279F28FC, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DA0, 0000000000000000, 000000007B60C498, 00000002279F2924, 0x00000000) 005c:0114:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 005c:0114:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0114:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 005c:0114:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0114:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 005c:0114:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0114:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",THREAD_ATTACH,0000000000000000) 000000023D8C5690 - CALL 005c:0114:trace:module:MODULE_InitDLL (000000023D820000,THREAD_ATTACH,0000000000000000) - RETURN 1 005c:0114:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",THREAD_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 005c:0114:trace:module:MODULE_InitDLL (00000003AFD00000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DA0, 0000000000000000, 000000007B60C498, 00000002279F290C, 0x00000000) 00fc:0108:trace:module:LdrResolveDelayLoadedAPI (00000002279A0000, 00000002279C5DC0, 0000000000000000, 000000007B60C498, 00000002279F29CC, 0x00000000) 00fc:0118:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 00fc:0118:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0118:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 00fc:0118:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0118:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 00fc:0118:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0118:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",THREAD_ATTACH,0000000000000000) 000000023D8C5690 - CALL 00fc:0118:trace:module:MODULE_InitDLL (000000023D820000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0118:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",THREAD_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 00fc:0118:trace:module:MODULE_InitDLL (00000003AFD00000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0118:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",THREAD_ATTACH,0000000000000000) 00000003270465C0 - CALL 00fc:0118:trace:module:MODULE_InitDLL (0000000327020000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0118:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",THREAD_ATTACH,0000000000000000) 00000002E8FB74E0 - CALL 00fc:0118:trace:module:MODULE_InitDLL (00000002E8F10000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0108:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0xfc9ae8,0x00000008,0x0) 00fc:011c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 00fc:011c:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:011c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 00fc:011c:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:011c:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 00fc:011c:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:011c:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",THREAD_ATTACH,0000000000000000) 000000023D8C5690 - CALL 00fc:011c:trace:module:MODULE_InitDLL (000000023D820000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:011c:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",THREAD_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 00fc:011c:trace:module:MODULE_InitDLL (00000003AFD00000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:011c:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",THREAD_ATTACH,0000000000000000) 00000003270465C0 - CALL 00fc:011c:trace:module:MODULE_InitDLL (0000000327020000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:011c:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",THREAD_ATTACH,0000000000000000) 00000002E8FB74E0 - CALL 00fc:011c:trace:module:MODULE_InitDLL (00000002E8F10000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0120:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 00fc:0120:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0120:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 00fc:0120:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0120:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 00fc:0120:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0120:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",THREAD_ATTACH,0000000000000000) 000000023D8C5690 - CALL 00fc:0120:trace:module:MODULE_InitDLL (000000023D820000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0120:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",THREAD_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 00fc:0120:trace:module:MODULE_InitDLL (00000003AFD00000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0120:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",THREAD_ATTACH,0000000000000000) 00000003270465C0 - CALL 00fc:0120:trace:module:MODULE_InitDLL (0000000327020000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0120:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",THREAD_ATTACH,0000000000000000) 00000002E8FB74E0 - CALL 00fc:0120:trace:module:MODULE_InitDLL (00000002E8F10000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0124:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 00fc:0124:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0124:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 00fc:0124:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0124:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 00fc:0124:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0124:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",THREAD_ATTACH,0000000000000000) 000000023D8C5690 - CALL 00fc:0124:trace:module:MODULE_InitDLL (000000023D820000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0124:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",THREAD_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 00fc:0124:trace:module:MODULE_InitDLL (00000003AFD00000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0124:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",THREAD_ATTACH,0000000000000000) 00000003270465C0 - CALL 00fc:0124:trace:module:MODULE_InitDLL (0000000327020000,THREAD_ATTACH,0000000000000000) - RETURN 1 00fc:0124:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",THREAD_ATTACH,0000000000000000) 00000002E8FB74E0 - CALL 00fc:0124:trace:module:MODULE_InitDLL (00000002E8F10000,THREAD_ATTACH,0000000000000000) - RETURN 1 0028:002c:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266CC, 0x00000000) 0030:00f8:trace:module:LdrShutdownThread () 0030:00f8:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_DETACH,0000000000000000) 0000000231B26040 - CALL 0030:00f8:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:00f8:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_DETACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:00f8:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:00f8:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_DETACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:00f8:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_DETACH,0000000000000000) - RETURN 1 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004D20, 0000000000000000, 000000007B60C498, 0000000140015894, 0x00000000) 0028:002c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 0000000140004CC0, 0000000000000000, 000000007B60C498, 00000001400158E4, 0x00000000) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8ac,0x00000004,0x0) 0028:002c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8ac,0x00000004,0x0) 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EBE0, base 000000000031EBD8. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E8F0, base 000000000031E8E8. 0028:002c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) wine: configuration in L"/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test" has been updated. 0028:002c:trace:process:SetEnvironmentVariableW (L"WINEDLLOVERRIDES" L"advpack=b;atl=b;oleaut32=b;rpcrt4=b;shdocvw=b;*iexplore.exe=b") 0028:002c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FD50, base 000000000031FD48. 0028:002c:trace:module:LdrGetDllHandleEx L"mscoree" -> 0000000000000000 (load path (null)) 0028:002c:trace:module:LdrShutdownProcess () 0028:002c:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_DETACH,0000000000000001) 00000002F72424B0 - CALL 0028:002c:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (000000006FB10000 L"winemac.drv",PROCESS_DETACH,0000000000000001) 000000006FB28C10 - CALL 0028:002c:trace:module:MODULE_InitDLL (000000006FB10000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (0000000284810000 L"newdev.dll",PROCESS_DETACH,0000000000000001) 0000000284811DD0 - CALL 0028:002c:trace:module:MODULE_InitDLL (0000000284810000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (00000001C1EF0000 L"atl100.dll",PROCESS_DETACH,0000000000000001) 00000001C1EFB6D0 - CALL 0028:002c:trace:module:MODULE_InitDLL (00000001C1EF0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (00000002739C0000 L"oleaut32.dll",PROCESS_DETACH,0000000000000001) 0000000273A6A370 - CALL 0028:002c:trace:module:MODULE_InitDLL (00000002739C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (000000021A7E0000 L"setupapi.dll",PROCESS_DETACH,0000000000000001) 000000021A816860 - CALL 0028:002c:trace:module:MODULE_InitDLL (000000021A7E0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (00000001C69E0000 L"shell32.dll",PROCESS_DETACH,0000000000000001) 00000001C6A688D0 - CALL 0028:002c:trace:module:MODULE_InitDLL (00000001C69E0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_DETACH,0000000000000001) 00000002E355DE00 - CALL 0028:002c:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_DETACH,0000000000000001) 00000003126F8FD0 - CALL 0028:002c:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_DETACH,0000000000000001) 00000002E8FB74E0 - CALL 0028:002c:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_DETACH,0000000000000001) 00000003270465C0 - CALL 0028:002c:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_DETACH,0000000000000001) 0000000231B26040 - CALL 0028:002c:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 0028:002c:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 0028:002c:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 0028:002c:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (000000006AD60000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006AE09460 - CALL 0028:002c:trace:module:MODULE_InitDLL (000000006AD60000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 0028:002c:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (00000001EC2B0000 L"ws2_32.dll",PROCESS_DETACH,0000000000000001) 00000001EC2C27C0 - CALL 0028:002c:trace:module:MODULE_InitDLL (00000001EC2B0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 0028:002c:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 0028:002c:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 0028:002c:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 0028:002c:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 0028:002c:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 0028:002c:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0028:002c:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 0028:002c:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0020:0024:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0020:0024:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0020:0024:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0020:0024:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0020:0024:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" is a fake Wine dll 0020:0024:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0020:0024:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0020:0024:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0020:0024:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0020:0024:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x321000 0020:0024:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x21fa70,0x00000040,0x0) 0020:0024:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0000000000332F30 0000000068A70000 0020:0024:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" at 0000000068A70000: builtin 0020:0024:trace:module:load_dll looking for L"kernel32.dll" in (null) 0020:0024:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0020:0024:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0020:0024:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0020:0024:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0020:0024:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0020:0024:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0020:0024:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0020:0024:trace:module:load_dll looking for L"ntdll.dll" in (null) 0020:0024:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 00000000003337E0 000000007B000000 0020:0024:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000: builtin 0020:0024:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ntdll.dll" in (null) 0020:0024:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0000000000333370 000000007B600000 0020:0024:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000: builtin 0020:0024:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000 0020:0024:trace:module:load_dll looking for L"advapi32.dll" in (null) 0020:0024:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0020:0024:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0020:0024:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0020:0024:trace:module:load_dll looking for L"kernel32.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0020:0024:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0020:0024:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0020:0024:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0020:0024:trace:module:load_dll looking for L"kernel32.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ntdll.dll" in (null) 0020:0024:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 00000000003304E0 00000001C8DB0000 0020:0024:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000: builtin 0020:0024:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ntdll.dll" in (null) 0020:0024:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"sechost.dll" in (null) 0020:0024:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0020:0024:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0020:0024:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0020:0024:trace:module:load_dll looking for L"kernel32.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ntdll.dll" in (null) 0020:0024:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0020:0024:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0020:0024:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0020:0024:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0020:0024:trace:module:load_dll looking for L"kernel32.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ntdll.dll" in (null) 0020:0024:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0000000000330BC0 00000003AF670000 0020:0024:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000: builtin 0020:0024:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0000000000330950 000000032A700000 0020:0024:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000: builtin 0020:0024:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0000000000330380 0000000330260000 0020:0024:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000: builtin 0020:0024:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"crypt32.dll" in (null) 0020:0024:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" 0020:0024:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" 0020:0024:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 0x1dd3f0000-0x1dd4be000 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .text at 0x1dd3f1000 off 1000 size 63000 virt 62550 flags 60000060 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .data at 0x1dd454000 off 64000 size 3000 virt 2640 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rodata at 0x1dd457000 off 67000 size 1000 virt 74c flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rdata at 0x1dd458000 off 68000 size 12000 virt 11830 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .pdata at 0x1dd46a000 off 7a000 size 3000 virt 2958 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .xdata at 0x1dd46d000 off 7d000 size 4000 virt 3260 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .bss at 0x1dd471000 off 0 size 0 virt 32d0 flags c0000080 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .edata at 0x1dd475000 off 81000 size 5000 virt 4c9c flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .idata at 0x1dd47a000 off 86000 size 2000 virt 1650 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rsrc at 0x1dd47c000 off 88000 size 41000 virt 40f48 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .reloc at 0x1dd4bd000 off c9000 size 1000 virt 514 flags 42000040 0020:0024:trace:module:load_dll looking for L"advapi32.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"bcrypt.dll" in (null) 0020:0024:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 0020:0024:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 0020:0024:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 0x2d4d40000-0x2d4d57000 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .text at 0x2d4d41000 off 1000 size a000 virt 97c0 flags 60000020 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .data at 0x2d4d4b000 off b000 size 1000 virt 70 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rodata at 0x2d4d4c000 off c000 size 1000 virt 3b8 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rdata at 0x2d4d4d000 off d000 size 2000 virt 1c40 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .pdata at 0x2d4d4f000 off f000 size 1000 virt 420 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .xdata at 0x2d4d50000 off 10000 size 1000 virt 52c flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .bss at 0x2d4d51000 off 0 size 0 virt 170 flags c0000080 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .edata at 0x2d4d52000 off 11000 size 2000 virt 1317 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .idata at 0x2d4d54000 off 13000 size 1000 virt 6cc flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rsrc at 0x2d4d55000 off 14000 size 1000 virt 3c0 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .reloc at 0x2d4d56000 off 15000 size 1000 virt 44 flags 42000040 0020:0024:trace:module:load_dll looking for L"advapi32.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"kernel32.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ntdll.dll" in (null) 0020:0024:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 0000000000336990 00000002D4D40000 0020:0024:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 00000002D4D40000: builtin 0020:0024:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 00000002D4D40000 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"kernel32.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ntdll.dll" in (null) 0020:0024:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"user32.dll" in (null) 0020:0024:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0020:0024:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0020:0024:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 0020:0024:trace:module:load_dll looking for L"advapi32.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=4 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"gdi32.dll" in (null) 0020:0024:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0020:0024:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0020:0024:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 0020:0024:trace:module:load_dll looking for L"advapi32.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=5 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"kernel32.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ntdll.dll" in (null) 0020:0024:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"user32.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"win32u.dll" in (null) 0020:0024:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0020:0024:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0020:0024:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" is a fake Wine dll 0020:0024:trace:module:load_dll looking for L"kernel32.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ntdll.dll" in (null) 0020:0024:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 00000000003376D0 000000006B560000 0020:0024:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006B560000: builtin 0020:0024:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006B560000 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0000000000337270 000000026B4C0000 0020:0024:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000: builtin 0020:0024:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"kernel32.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ntdll.dll" in (null) 0020:0024:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"sechost.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"version.dll" in (null) 0020:0024:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0020:0024:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0020:0024:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 0020:0024:trace:module:load_dll looking for L"kernel32.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=11 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ntdll.dll" in (null) 0020:0024:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=13 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=6 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0000000000337B40 00000002F1FA0000 0020:0024:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000: builtin 0020:0024:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"win32u.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" for L"win32u.dll" at 000000006B560000, count=2 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0000000000336E00 000000023D820000 0020:0024:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000: builtin 0020:0024:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" 0000000000330DD0 00000001DD3F0000 0020:0024:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 00000001DD3F0000: builtin 0020:0024:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 00000001DD3F0000 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"kernel32.dll" in (null) 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=12 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ntdll.dll" in (null) 0020:0024:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=14 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:process_attach (L"ntdll.dll",000000000021FB00) - START 0020:0024:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000021FB00) 0000000170065B80 - CALL 0020:0024:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0020:0024:trace:module:process_attach (L"ntdll.dll",000000000021FB00) - END 0020:0024:trace:module:process_attach (L"kernel32.dll",000000000021FB00) - START 0020:0024:trace:module:process_attach (L"kernelbase.dll",000000000021FB00) - START 0020:0024:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000021FB00) 000000007B03CAD0 - CALL 0020:0024:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x21f618,0x00000008,0x0) 0020:0024:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000021F2A0 85) 0020:0024:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 0020:0024:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000334510 17) 0020:0024:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000339E50, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021EFE8. 0020:0024:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0020:0024:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0020:0024:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0020:0024:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0020:0024:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0020:0024:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0020:0024:trace:module:LoadResource 0000000010000002 00000000100077D8 0020:0024:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 0020:0024:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000337040 17) 0020:0024:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000339EB0, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021EFE8. 0020:0024:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0020:0024:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0020:0024:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0020:0024:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0020:0024:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0020:0024:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0020:0024:trace:module:LoadResource 0000000010000002 00000000100077D8 0020:0024:trace:process:CreateProcessInternalW app L"C:\\windows\\system32\\conhost.exe" cmdline L"\"C:\\windows\\system32\\conhost.exe\" --unix --width 80 --height 24 --server 0x30" 0020:0024:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\conhost.exe" image L"C:\\windows\\system32\\conhost.exe" cmdline L"\"C:\\windows\\system32\\conhost.exe\" --unix --width 80 --height 24 --server 0x30" parent 0x0 0020:0024:trace:process:send_to_cx_loader loader (null) wineserversocket 7 stdin_fd 12 stdout_fd 14 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 0020:0024:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0128:012c:trace:module:get_load_order looking for L"C:\\windows\\system32\\conhost.exe" 0128:012c:trace:module:get_load_order got hardcoded default for L"conhost.exe" 0128:012c:trace:module:get_load_order looking for L"C:\\windows\\system32\\conhost.exe" 0128:012c:trace:module:get_load_order got hardcoded default for L"conhost.exe" 0128:012c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\conhost.exe" at 0x140000000-0x14003b000 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .text at 0x140001000 off 1000 size 11000 virt 100d0 flags 60000060 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .data at 0x140012000 off 12000 size 1000 virt f0 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .rdata at 0x140013000 off 13000 size 2000 virt 18f0 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .pdata at 0x140015000 off 15000 size 1000 virt 5f4 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .xdata at 0x140016000 off 16000 size 1000 virt 69c flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .bss at 0x140017000 off 0 size 0 virt 1340 flags c0000080 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .idata at 0x140019000 off 17000 size 2000 virt 199c flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .rsrc at 0x14001b000 off 19000 size 1f000 virt 1eaf0 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .reloc at 0x14003a000 off 38000 size 1000 virt bc flags 42000040 0128:012c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0128:012c:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0020:0024:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\conhost.exe" pid 0128 tid 012c handles 0x40/0x44 0020:0024:trace:process:CreateProcessInternalW started process pid 0128 tid 012c 0020:0024:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0020:0024:trace:module:process_attach (L"kernelbase.dll",000000000021FB00) - END 0020:0024:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000021FB00) 000000007B631530 - CALL 0020:0024:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0020:0024:trace:module:process_attach (L"kernel32.dll",000000000021FB00) - END 0020:0024:trace:module:process_attach (L"advapi32.dll",000000000021FB00) - START 0020:0024:trace:module:process_attach (L"msvcrt.dll",000000000021FB00) - START 0020:0024:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000021FB00) 00000001C8E1AB00 - CALL 0128:012c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 0128:012c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\conhost.exe" 0000000000432A60 0000000140000000 0128:012c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\conhost.exe" at 0000000140000000: builtin 0128:012c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0128:012c:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernel32.dll" 0128:012c:trace:module:get_load_order got hardcoded default for L"kernel32.dll" 0128:012c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0020:0024:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F3B0. 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0020:0024:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0020:0024:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F400. 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0020:0024:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0020:0024:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0020:0024:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0020:0024:trace:module:process_attach (L"msvcrt.dll",000000000021FB00) - END 0020:0024:trace:module:process_attach (L"sechost.dll",000000000021FB00) - START 0020:0024:trace:module:process_attach (L"ucrtbase.dll",000000000021FB00) - START 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0020:0024:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000021FB00) 00000003AF6F1C30 - CALL 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0128:012c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0020:0024:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F320. 0020:0024:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0020:0024:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F370. 0020:0024:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0020:0024:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0020:0024:trace:module:process_attach (L"ucrtbase.dll",000000000021FB00) - END 0020:0024:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000021FB00) 000000032A716FC0 - CALL 0020:0024:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0020:0024:trace:module:process_attach (L"sechost.dll",000000000021FB00) - END 0020:0024:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000021FB00) 0000000330283EC0 - CALL 0020:0024:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0020:0024:trace:module:process_attach (L"advapi32.dll",000000000021FB00) - END 0020:0024:trace:module:process_attach (L"crypt32.dll",000000000021FB00) - START 0020:0024:trace:module:process_attach (L"bcrypt.dll",000000000021FB00) - START 0020:0024:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_ATTACH,000000000021FB00) 00000002D4D49C40 - CALL 0020:0024:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F570, base 000000000021F568. 0020:0024:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0128:012c:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernelbase.dll" 0128:012c:trace:module:get_load_order got hardcoded default for L"kernelbase.dll" 0128:012c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0128:012c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 0000000000433150 000000007B000000 0128:012c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 0128:012c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000432E60 000000007B600000 0128:012c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 0128:012c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 0020:0024:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0020:0024:trace:module:process_attach (L"bcrypt.dll",000000000021FB00) - END 0020:0024:trace:module:process_attach (L"user32.dll",000000000021FB00) - START 0020:0024:trace:module:process_attach (L"gdi32.dll",000000000021FB00) - START 0020:0024:trace:module:process_attach (L"win32u.dll",000000000021FB00) - START 0020:0024:trace:module:MODULE_InitDLL (000000006B560000 L"win32u.dll",PROCESS_ATTACH,000000000021FB00) 000000006B609460 - CALL 0128:012c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0128:012c:trace:module:get_load_order looking for L"C:\\windows\\system32\\advapi32.dll" 0128:012c:trace:module:get_load_order got hardcoded default for L"advapi32.dll" 0128:012c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0128:012c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0128:012c:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvcrt.dll" 0128:012c:trace:module:get_load_order got hardcoded default for L"msvcrt.dll" 0128:012c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0128:012c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 0000000000433660 00000001C8DB0000 0128:012c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 0128:012c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"sechost.dll" in (null) 0128:012c:trace:module:get_load_order looking for L"C:\\windows\\system32\\sechost.dll" 0128:012c:trace:module:get_load_order got hardcoded default for L"sechost.dll" 0128:012c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0128:012c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0128:012c:trace:module:get_load_order looking for L"C:\\windows\\system32\\ucrtbase.dll" 0128:012c:trace:module:get_load_order got hardcoded default for L"ucrtbase.dll" 0128:012c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0128:012c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 0000000000433C40 00000003AF670000 0128:012c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 0128:012c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 0000000000433930 000000032A700000 0128:012c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 0128:012c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 0000000000433450 0000000330260000 0128:012c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 0128:012c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0128:012c:trace:module:get_load_order looking for L"C:\\windows\\system32\\gdi32.dll" 0128:012c:trace:module:get_load_order got hardcoded default for L"gdi32.dll" 0128:012c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 0128:012c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"user32.dll" in (null) 0128:012c:trace:module:get_load_order looking for L"C:\\windows\\system32\\user32.dll" 0128:012c:trace:module:get_load_order got hardcoded default for L"user32.dll" 0128:012c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 0128:012c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"sechost.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"version.dll" in (null) 0128:012c:trace:module:get_load_order looking for L"C:\\windows\\system32\\version.dll" 0128:012c:trace:module:get_load_order got hardcoded default for L"version.dll" 0128:012c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 0128:012c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 00000000004345F0 00000002F1FA0000 0128:012c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 00000002F1FA0000: builtin 0128:012c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 00000002F1FA0000 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"win32u.dll" in (null) 0128:012c:trace:module:get_load_order looking for L"C:\\windows\\system32\\win32u.dll" 0128:012c:trace:module:get_load_order got hardcoded default for L"win32u.dll" 0128:012c:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\win32u.dll" is a fake Wine dll 0128:012c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\win32u.dll" 0000000000434940 000000006AC60000 0128:012c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\win32u.dll" at 000000006AC60000: builtin 0128:012c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\win32u.dll" at 000000006AC60000 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\user32.dll" 00000000004341E0 000000023D820000 0128:012c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\user32.dll" at 000000023D820000: builtin 0128:012c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\user32.dll" at 000000023D820000 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"win32u.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AC60000, count=2 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\gdi32.dll" 0000000000433F30 000000026B4C0000 0128:012c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000: builtin 0128:012c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"user32.dll" in (null) 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 0128:012c:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 0128:012c:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0128:012c:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 0128:012c:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 0128:012c:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 0128:012c:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 0128:012c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 0128:012c:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 0128:012c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 0128:012c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000436D70 17) 0128:012c:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000436E80, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0128:012c:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0128:012c:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0128:012c:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0128:012c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0128:012c:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0128:012c:trace:module:LoadResource 0000000010000002 00000000100077D8 0128:012c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 0128:012c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000436DC0 17) 0128:012c:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000436FA0, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0128:012c:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0128:012c:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0128:012c:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0128:012c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0128:012c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0128:012c:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0128:012c:trace:module:LoadResource 0000000010000002 00000000100077D8 0128:012c:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0128:012c:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 0128:012c:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 0128:012c:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0128:012c:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 0128:012c:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 0128:012c:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 0128:012c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 0128:012c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F3B0. 0128:012c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 0128:012c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F400. 0128:012c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 0128:012c:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0128:012c:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0128:012c:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 0128:012c:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 0128:012c:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 0128:012c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 0128:012c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 0128:012c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 0128:012c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 0128:012c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 0128:012c:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0128:012c:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 0128:012c:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 0128:012c:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0128:012c:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 0128:012c:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 0128:012c:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0128:012c:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 0128:012c:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - START 0128:012c:trace:module:process_attach (L"user32.dll",000000000031FB00) - START 0128:012c:trace:module:process_attach (L"version.dll",000000000031FB00) - START 0128:012c:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000031FB00) 00000002F1FA2510 - CALL 0128:012c:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0128:012c:trace:module:process_attach (L"version.dll",000000000031FB00) - END 0128:012c:trace:module:process_attach (L"win32u.dll",000000000031FB00) - START 0128:012c:trace:module:MODULE_InitDLL (000000006AC60000 L"win32u.dll",PROCESS_ATTACH,000000000031FB00) 000000006AD09460 - CALL 0020:0024:trace:module:MODULE_InitDLL (000000006B560000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0020:0024:trace:module:process_attach (L"win32u.dll",000000000021FB00) - END 0020:0024:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000021FB00) 000000026B509F00 - CALL 0020:0024:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0020:0024:trace:module:process_attach (L"gdi32.dll",000000000021FB00) - END 0020:0024:trace:module:process_attach (L"version.dll",000000000021FB00) - START 0020:0024:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000021FB00) 00000002F1FA2510 - CALL 0020:0024:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0020:0024:trace:module:process_attach (L"version.dll",000000000021FB00) - END 0020:0024:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000021FB00) 000000023D8C5690 - CALL 0020:0024:trace:module:load_dll looking for L"imm32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0020:0024:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0020:0024:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0020:0024:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 0020:0024:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 0020:0024:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0020:0024:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0020:0024:trace:module:import_dll is not hybrid module 0020:0024:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 00000000003429C0 00000003AFD00000 0020:0024:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000: builtin 0020:0024:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000 0020:0024:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 0020:0024:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 0020:0024:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021EBB0, base 000000000021EBA8. 0020:0024:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0020:0024:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021F048. 0020:0024:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 0020:0024:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021EB60, base 000000000021EB58. 0020:0024:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0020:0024:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0020:0024:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 0020:0024:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0020:0024:trace:module:process_attach (L"user32.dll",000000000021FB00) - END 0020:0024:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_ATTACH,000000000021FB00) 00000001DD4524D0 - CALL 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0020:0024:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0020:0024:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0020:0024:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F600, base 000000000021F5F8. 0020:0024:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0020:0024:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0020:0024:trace:module:process_attach (L"crypt32.dll",000000000021FB00) - END 0020:0024:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x21f8b8,0x00000008,0x0) 0020:0024:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F080, base 000000000021F078. 0020:0024:trace:module:LdrGetDllHandleEx L"kernel32" -> 000000007B600000 (load path (null)) 0020:0024:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0020:0024:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0128:012c:trace:module:MODULE_InitDLL (000000006AC60000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0128:012c:trace:module:process_attach (L"win32u.dll",000000000031FB00) - END 0128:012c:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000031FB00) 000000023D8C5690 - CALL 0128:012c:trace:module:load_dll looking for L"imm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0128:012c:trace:module:get_load_order looking for L"C:\\windows\\system32\\imm32.dll" 0128:012c:trace:module:get_load_order got hardcoded default for L"imm32.dll" 0128:012c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 0128:012c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 0128:012c:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0128:012c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0128:012c:trace:module:import_dll is not hybrid module 0128:012c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imm32.dll" 000000000043EF10 00000003AFD00000 0128:012c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imm32.dll" at 00000003AFD00000: builtin 0128:012c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imm32.dll" at 00000003AFD00000 0128:012c:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 0128:012c:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 0128:012c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EBB0, base 000000000031EBA8. 0128:012c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0128:012c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031F048. 0128:012c:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 0128:012c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EB60, base 000000000031EB58. 0128:012c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0128:012c:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0128:012c:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 0128:012c:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0128:012c:trace:module:process_attach (L"user32.dll",000000000031FB00) - END 0128:012c:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000031FB00) 000000026B509F00 - CALL 0128:012c:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0128:012c:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - END 0128:012c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 0128:012c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FA50, base 000000000031FA48. 0128:012c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0128:012c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F5E0, base 000000000031F5D8. 0128:012c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0020:0024:trace:process:CreateProcessInternalW app (null) cmdline L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe setupapi.dll,InstallHinfSection win10Install 128 Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\crossover\\bottle"... 0020:0024:trace:process:find_exe_file looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;.;C:\\windows\\system32;C:\\windows\\system;C:\\windows;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0020:0024:trace:process:NtCreateUserProcess L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" image L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" cmdline L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe setupapi.dll,InstallHinfSection win10Install 128 Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\crossover\\bottle"... parent 0x0 0020:0024:trace:process:send_to_cx_loader loader (null) wineserversocket 10 stdin_fd 0 stdout_fd 1 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 0020:0024:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0130:0134:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0130:0134:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" at 0x140000000-0x14000a000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" section .text at 0x140001000 off 1000 size 2000 virt 1bb0 flags 60000020 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" section .data at 0x140003000 off 3000 size 1000 virt 40 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" section .rdata at 0x140004000 off 4000 size 1000 virt 250 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" section .pdata at 0x140005000 off 5000 size 1000 virt d8 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" section .xdata at 0x140006000 off 6000 size 1000 virt e8 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" section .bss at 0x140007000 off 0 size 0 virt 140 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" section .idata at 0x140008000 off 7000 size 1000 virt 764 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" section .reloc at 0x140009000 off 8000 size 1000 virt 14 flags 42000040 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0130:0134:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0020:0024:trace:process:NtCreateUserProcess L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" pid 0130 tid 0134 handles 0x70/0x74 0020:0024:trace:process:CreateProcessInternalW started process pid 0130 tid 0134 0130:0134:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0000000000432EB0 0000000140000000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" at 0000000140000000: builtin 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in (null) 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0130:0134:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in (null) 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0000000000433760 000000007B000000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in (null) 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 00000000004332F0 000000007B600000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in (null) 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in (null) 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 00000000004338C0 00000003AF670000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"user32.dll" in (null) 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 0130:0134:trace:module:load_dll looking for L"advapi32.dll" in (null) 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in (null) 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 00000000004345C0 00000001C8DB0000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in (null) 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"sechost.dll" in (null) 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in (null) 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0000000000434A30 000000032A700000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0000000000434150 0000000330260000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"gdi32.dll" in (null) 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 0130:0134:trace:module:load_dll looking for L"advapi32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in (null) 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"user32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"win32u.dll" in (null) 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0130:0134:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" is a fake Wine dll 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in (null) 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0000000000434F90 000000006AC60000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006AC60000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006AC60000 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0000000000434CA0 000000026B4C0000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in (null) 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"sechost.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"version.dll" in (null) 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in (null) 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0000000000435400 00000002F1FA0000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"win32u.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" for L"win32u.dll" at 000000006AC60000, count=2 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0000000000433CE0 000000023D820000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 0130:0134:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 0130:0134:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0130:0134:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 0130:0134:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 0130:0134:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 0130:0134:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 0130:0134:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 0130:0134:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 0130:0134:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 0130:0134:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000433F70 17) 0130:0134:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000004377E0, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0130:0134:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0130:0134:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0130:0134:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0130:0134:trace:module:LoadResource 0000000010000002 00000000100077D8 0130:0134:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 0130:0134:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000433F70 17) 0130:0134:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000004378A0, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0130:0134:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0130:0134:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0130:0134:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0130:0134:trace:module:LoadResource 0000000010000002 00000000100077D8 0130:0134:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0130:0134:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 0130:0134:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 0130:0134:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0130:0134:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 0130:0134:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 0130:0134:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 0130:0134:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F440. 0130:0134:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0130:0134:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F490. 0130:0134:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0130:0134:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0130:0134:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 0130:0134:trace:module:process_attach (L"user32.dll",000000000031FB00) - START 0130:0134:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 0130:0134:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 0130:0134:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 0130:0134:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 0130:0134:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0130:0134:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 0130:0134:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0130:0134:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0130:0134:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0130:0134:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 0130:0134:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 0130:0134:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 0130:0134:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0130:0134:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 0130:0134:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 0130:0134:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0130:0134:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 0130:0134:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - START 0130:0134:trace:module:process_attach (L"win32u.dll",000000000031FB00) - START 0130:0134:trace:module:MODULE_InitDLL (000000006AC60000 L"win32u.dll",PROCESS_ATTACH,000000000031FB00) 000000006AD09460 - CALL 0130:0134:trace:module:MODULE_InitDLL (000000006AC60000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0130:0134:trace:module:process_attach (L"win32u.dll",000000000031FB00) - END 0130:0134:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000031FB00) 000000026B509F00 - CALL 0130:0134:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0130:0134:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - END 0130:0134:trace:module:process_attach (L"version.dll",000000000031FB00) - START 0130:0134:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000031FB00) 00000002F1FA2510 - CALL 0130:0134:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0130:0134:trace:module:process_attach (L"version.dll",000000000031FB00) - END 0130:0134:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000031FB00) 000000023D8C5690 - CALL 0130:0134:trace:module:load_dll looking for L"imm32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 0130:0134:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0000000000443490 00000003AFD00000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000 0130:0134:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 0130:0134:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EC40, base 000000000031EC38. 0130:0134:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F0E0, base 000000000031F0D8. 0130:0134:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EBF0, base 000000000031EBE8. 0130:0134:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0130:0134:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0130:0134:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 0130:0134:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0130:0134:trace:module:process_attach (L"user32.dll",000000000031FB00) - END 0130:0134:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F620, base 000000000031F618. 0130:0134:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0130:0134:trace:module:load_dll looking for L"winemac.drv" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" 0130:0134:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" is a fake Wine dll 0130:0134:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"gdi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"win32u.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" for L"win32u.dll" at 000000006AC60000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" 0000000000443830 000000006DD10000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" at 000000006DD10000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" at 000000006DD10000 0130:0134:trace:module:process_attach (L"winemac.drv",0000000000000000) - START 0130:0134:trace:module:MODULE_InitDLL (000000006DD10000 L"winemac.drv",PROCESS_ATTACH,0000000000000000) 000000006DD28C10 - CALL 0130:0134:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031BA60. 0130:0134:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0130:0134:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 0130:0134:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 0130:0134:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 0130:0134:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 0130:0134:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 0130:0134:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 0130:0134:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 0130:0134:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 0130:0134:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 0130:0134:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 0130:0134:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 0130:0134:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 0130:0134:trace:module:FindResourceExW 000000006DD10000 #0006 #0011 0000 0130:0134:trace:module:LoadResource 000000006DD10000 000000006DD8E9D8 0130:0134:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 0130:0134:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 0130:0134:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 0130:0134:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 0130:0134:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 0130:0134:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 0130:0134:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 0130:0134:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 0130:0134:trace:module:FindResourceExW 000000006DD10000 #0006 #0012 0000 0130:0134:trace:module:LoadResource 000000006DD10000 000000006DD8EBC8 0130:0134:trace:module:MODULE_InitDLL (000000006DD10000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0130:0134:trace:module:process_attach (L"winemac.drv",0000000000000000) - END 0130:0134:trace:module:EnumResourceNamesExW 0000000000000000 #000e 000000006DD1FB00 31d2f8 0130:0134:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0130:0134:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0130:0134:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0130:0134:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0130:0134:trace:module:LoadResource 000000023D820000 000000023D908880 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C310, base 000000000031C308. 0130:0134:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0130:0134:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C760. 0130:0134:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0130:0134:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0130:0134:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0130:0134:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0130:0134:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0130:0134:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0130:0134:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0130:0134:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0130:0134:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0130:0134:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0130:0134:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0130:0134:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0130:0134:trace:module:FindResourceExW 000000023D820000 #000c #7f01 0000 0130:0134:trace:module:LoadResource 000000023D820000 000000023D90A4C0 0130:0134:trace:module:FindResourceExW 000000023D820000 #0001 #0009 0000 0130:0134:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0130:0134:trace:module:LoadResource 000000023D820000 000000023D9088E0 0130:0134:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C760. 0130:0134:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0130:0134:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0130:0134:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0130:0134:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0130:0134:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0130:0134:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0130:0134:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0130:0134:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0130:0134:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0130:0134:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0130:0134:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0130:0134:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0130:0134:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0130:0134:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0130:0134:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0130:0134:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0130:0134:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0130:0134:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0130:0134:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0130:0134:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0130:0134:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0130:0134:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0130:0134:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0130:0134:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0130:0134:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0130:0134:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0130:0134:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0130:0134:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0130:0134:trace:module:load_dll looking for L"uxtheme.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:get_load_order looking for L"C:\\windows\\system32\\uxtheme.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"uxtheme.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 0x2f7230000-0x2f7265000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .text at 0x2f7231000 off 1000 size 13000 virt 123c0 flags 60000060 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .data at 0x2f7244000 off 14000 size 1000 virt 110 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rodata at 0x2f7245000 off 15000 size 1000 virt 430 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rdata at 0x2f7246000 off 16000 size 16000 virt 15a30 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .pdata at 0x2f725c000 off 2c000 size 1000 virt 87c flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .xdata at 0x2f725d000 off 2d000 size 1000 virt 97c flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .bss at 0x2f725e000 off 0 size 0 virt 4a0 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .edata at 0x2f725f000 off 2e000 size 2000 virt 1de0 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .idata at 0x2f7261000 off 30000 size 2000 virt 14ac flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rsrc at 0x2f7263000 off 32000 size 1000 virt 5f8 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .reloc at 0x2f7264000 off 33000 size 1000 virt bc flags 42000040 0130:0134:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"gdi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\uxtheme.dll" 0000000000443C10 00000002F7230000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\uxtheme.dll" at 00000002F7230000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\uxtheme.dll" at 00000002F7230000 0130:0134:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - START 0130:0134:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_ATTACH,0000000000000000) 00000002F72424B0 - CALL 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C950, base 000000000031C948. 0130:0134:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031CB00, base 000000000031CAF8. 0130:0134:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0130:0134:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000444080, dll_characteristics 0000000000000000, name 000000000031CD20, base 000000000031CCB8. 0130:0134:trace:module:LdrGetDllHandleEx L"C:\\windows\\resources\\themes\\light\\light.msstyles" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0130:0134:trace:module:FindResourceExW 0000000000F10001 L"PACKTHEM_VERSION" #0001 0000 0130:0134:trace:module:LoadResource 0000000000F10001 0000000000F15310 0130:0134:trace:module:FindResourceExW 0000000000F10001 L"COLORNAMES" #0001 0000 0130:0134:trace:module:LoadResource 0000000000F10001 0000000000F152F0 0130:0134:trace:module:FindResourceExW 0000000000F10001 L"SIZENAMES" #0001 0000 0130:0134:trace:module:LoadResource 0000000000F10001 0000000000F15320 0130:0134:trace:module:FindResourceExW 0000000000F10001 L"FILERESNAMES" #0001 0000 0130:0134:trace:module:LoadResource 0000000000F10001 0000000000F15300 0130:0134:trace:module:FindResourceExW 0000000000F10001 L"TEXTFILE" L"BLUE_INI" 0000 0130:0134:trace:module:LoadResource 0000000000F10001 0000000000F15330 0130:0134:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0130:0134:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - END 0130:0134:trace:module:load_dll looking for L"winemac.drv" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" for L"winemac.drv" at 000000006DD10000, count=2 0130:0134:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0130:0134:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0130:0134:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0130:0134:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031F280. 0130:0134:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F240. 0130:0134:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0130:0134:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000443270, dll_characteristics 0000000000000000, name 000000000031F1A0, base 000000000031F138. 0130:0134:trace:module:LdrAddRefDll (L"rundll32.exe") ldr.LoadCount: -1 0130:0134:trace:module:LdrGetDllHandleEx L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" -> 0000000140000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0130:0134:trace:module:FindResourceExW 0000000140000000 #0010 #0001 0000 0130:0134:trace:module:LdrUnloadDll (0000000140000000) 0130:0134:trace:module:LdrUnloadDll (L"rundll32.exe") - START 0130:0134:trace:module:LdrUnloadDll END 0130:0134:trace:module:FindResourceExW 000000023D820000 #0004 L"SYSMENU" 0000 0130:0134:trace:module:LoadResource 000000023D820000 000000023D909940 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EAA0, base 000000000031EA98. 0130:0134:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F630, base 000000000031F628. 0130:0134:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F320, base 000000000031F318. 0130:0134:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0130:0134:trace:module:CreateActCtxW 000000000031F910 00000008 0130:0134:trace:module:load_dll looking for L"setupapi.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" at 0x21a7e0000-0x21a856000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .text at 0x21a7e1000 off 1000 size 37000 virt 365e0 flags 60000060 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .data at 0x21a818000 off 38000 size 1000 virt 230 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rodata at 0x21a819000 off 39000 size 3000 virt 244c flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rdata at 0x21a81c000 off 3c000 size e000 virt d010 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .pdata at 0x21a82a000 off 4a000 size 2000 virt 1818 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .xdata at 0x21a82c000 off 4c000 size 2000 virt 1d24 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .bss at 0x21a82e000 off 0 size 0 virt 720 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .edata at 0x21a82f000 off 4e000 size 18000 virt 171c8 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .idata at 0x21a847000 off 66000 size 2000 virt 1f34 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .rsrc at 0x21a849000 off 68000 size c000 virt bf00 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" section .reloc at 0x21a855000 off 74000 size 1000 virt d8 flags 42000040 0130:0134:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernelbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"rpcrt4.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" 0130:0134:trace:module:get_load_order_value got environment b for L"rpcrt4" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0x231ae0000-0x231b62000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .text at 0x231ae1000 off 1000 size 47000 virt 46400 flags 60000060 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .data at 0x231b28000 off 48000 size 1000 virt 710 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rodata at 0x231b29000 off 49000 size 2000 virt 1b44 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rdata at 0x231b2b000 off 4b000 size 15000 virt 14b90 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .pdata at 0x231b40000 off 60000 size 3000 virt 2334 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .xdata at 0x231b43000 off 63000 size 3000 virt 289c flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .bss at 0x231b46000 off 0 size 0 virt 690 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .edata at 0x231b47000 off 66000 size 17000 virt 16730 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .idata at 0x231b5e000 off 7d000 size 2000 virt 19a8 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rsrc at 0x231b60000 off 7f000 size 1000 virt 3a8 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .reloc at 0x231b61000 off 80000 size 1000 virt 504 flags 42000040 0130:0134:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" 00000000004742B0 0000000231AE0000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0000000231AE0000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0000000231AE0000 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"version.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" for L"version.dll" at 00000002F1FA0000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" 0000000000473E40 000000021A7E0000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" at 000000021A7E0000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" at 000000021A7E0000 0130:0134:trace:module:process_attach (L"setupapi.dll",0000000000000000) - START 0130:0134:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - START 0130:0134:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_ATTACH,0000000000000000) 0000000231B26040 - CALL 0130:0134:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0130:0134:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - END 0130:0134:trace:module:MODULE_InitDLL (000000021A7E0000 L"setupapi.dll",PROCESS_ATTACH,0000000000000000) 000000021A816860 - CALL 0130:0134:trace:module:MODULE_InitDLL (000000021A7E0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0130:0134:trace:module:process_attach (L"setupapi.dll",0000000000000000) - END 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F340, base 000000000031F338. 0130:0134:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F030, base 000000000031F028. 0130:0134:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0130:0134:trace:module:LdrResolveDelayLoadedAPI (000000021A7E0000, 000000021A817560, 0000000000000000, 000000007B60C498, 000000021A847BB8, 0x00000000) 0130:0134:trace:module:load_dll looking for L"ole32.dll" in (null) 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" at 0x2e8f10000-0x2e902b000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .text at 0x2e8f11000 off 1000 size a8000 virt a76a0 flags 60000060 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .data at 0x2e8fb9000 off a9000 size 1000 virt 480 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rodata at 0x2e8fba000 off aa000 size 1000 virt 778 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rdata at 0x2e8fbb000 off ab000 size 1e000 virt 1d750 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .pdata at 0x2e8fd9000 off c9000 size 7000 virt 6b10 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .xdata at 0x2e8fe0000 off d0000 size 7000 virt 67c4 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .bss at 0x2e8fe7000 off 0 size 0 virt 210 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .edata at 0x2e8fe8000 off d7000 size 18000 virt 17412 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .idata at 0x2e9000000 off ef000 size 4000 virt 367c flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rsrc at 0x2e9004000 off f3000 size 25000 virt 24bc0 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .reloc at 0x2e9029000 off 118000 size 2000 virt 1804 flags 42000040 0130:0134:trace:module:load_dll looking for L"advapi32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"combase.dll" in (null) 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" at 0x327020000-0x327073000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .text at 0x327021000 off 1000 size 27000 virt 26590 flags 60000060 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .data at 0x327048000 off 28000 size 1000 virt 580 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rodata at 0x327049000 off 29000 size 2000 virt 16c0 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rdata at 0x32704b000 off 2b000 size d000 virt cf90 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .pdata at 0x327058000 off 38000 size 2000 virt 17a0 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .xdata at 0x32705a000 off 3a000 size 2000 virt 18e4 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .bss at 0x32705c000 off 0 size 0 virt 1a0 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .edata at 0x32705d000 off 3c000 size 13000 virt 12d6e flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .idata at 0x327070000 off 4f000 size 2000 virt 1804 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .reloc at 0x327072000 off 51000 size 1000 virt 23c flags 42000040 0130:0134:trace:module:load_dll looking for L"advapi32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"gdi32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in (null) 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ole32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=2 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"user32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" 000000000047D200 0000000327020000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" at 0000000327020000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" at 0000000327020000 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"gdi32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in (null) 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=3 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"user32.dll" in (null) 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" 000000000047CDA0 00000002E8F10000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" at 00000002E8F10000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" at 00000002E8F10000 0130:0134:trace:module:process_attach (L"ole32.dll",0000000000000000) - START 0130:0134:trace:module:process_attach (L"combase.dll",0000000000000000) - START 0130:0134:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_ATTACH,0000000000000000) 00000003270465C0 - CALL 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E930, base 000000000031E928. 0130:0134:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0130:0134:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0130:0134:trace:module:process_attach (L"combase.dll",0000000000000000) - END 0130:0134:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_ATTACH,0000000000000000) 00000002E8FB74E0 - CALL 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E9E0, base 000000000031E9D8. 0130:0134:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0130:0134:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0130:0134:trace:module:process_attach (L"ole32.dll",0000000000000000) - END 0130:0134:trace:module:load_dll looking for L"C:\\windows\\system32\\actxprxy.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:get_load_order looking for L"C:\\windows\\system32\\actxprxy.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"actxprxy.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\actxprxy.dll" at 0x1d0830000-0x1d0980000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .text at 0x1d0831000 off 1000 size f6000 virt f5510 flags 60000020 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .data at 0x1d0927000 off f7000 size 1000 virt cd0 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .rodata at 0x1d0928000 off f8000 size 1000 virt 1c flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .rdata at 0x1d0929000 off f9000 size 1b000 virt 1a730 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .pdata at 0x1d0944000 off 114000 size 9000 virt 89a0 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .xdata at 0x1d094d000 off 11d000 size 8000 virt 78c4 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .bss at 0x1d0955000 off 0 size 0 virt 190 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .edata at 0x1d0956000 off 125000 size 1d000 virt 1c918 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .idata at 0x1d0973000 off 142000 size 2000 virt 1738 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .rsrc at 0x1d0975000 off 144000 size 8000 virt 7310 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\actxprxy.dll" section .reloc at 0x1d097d000 off 14c000 size 3000 virt 2754 flags 42000040 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"oleaut32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:get_load_order looking for L"C:\\windows\\system32\\oleaut32.dll" 0130:0134:trace:module:get_load_order_value got environment b for L"oleaut32" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" at 0x2739c0000-0x273af6000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .text at 0x2739c1000 off 1000 size ab000 virt aa720 flags 60000060 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .data at 0x273a6c000 off ac000 size 2000 virt 1100 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rodata at 0x273a6e000 off ae000 size 1000 virt 984 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rdata at 0x273a6f000 off af000 size 1f000 virt 1e700 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .pdata at 0x273a8e000 off ce000 size 6000 virt 57e4 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .xdata at 0x273a94000 off d4000 size 6000 virt 50e4 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .bss at 0x273a9a000 off 0 size 0 virt 38230 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .edata at 0x273ad3000 off da000 size 19000 virt 18c59 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .idata at 0x273aec000 off f3000 size 3000 virt 2aa0 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rsrc at 0x273aef000 off f6000 size 5000 virt 4ee0 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .reloc at 0x273af4000 off fb000 size 2000 virt 14e4 flags 42000040 0130:0134:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=3 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"rpcrt4.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=4 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\oleaut32.dll" 000000000047DD50 00000002739C0000 0130:0134:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\oleaut32.dll" at 00000002739C0000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\oleaut32.dll" at 00000002739C0000 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"rpcrt4.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=5 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\actxprxy.dll" 000000000047DB10 00000001D0830000 0130:0134:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\actxprxy.dll" at 00000001D0830000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\actxprxy.dll" at 00000001D0830000 0130:0134:trace:module:process_attach (L"actxprxy.dll",0000000000000000) - START 0130:0134:trace:module:process_attach (L"oleaut32.dll",0000000000000000) - START 0130:0134:trace:module:MODULE_InitDLL (00000002739C0000 L"oleaut32.dll",PROCESS_ATTACH,0000000000000000) 0000000273A6A370 - CALL 0130:0134:trace:process:GetEnvironmentVariableW (L"oanocache" 0000000000000000 0) 0130:0134:trace:module:MODULE_InitDLL (00000002739C0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0130:0134:trace:module:process_attach (L"oleaut32.dll",0000000000000000) - END 0130:0134:trace:module:MODULE_InitDLL (00000001D0830000 L"actxprxy.dll",PROCESS_ATTACH,0000000000000000) 00000001D09254B0 - CALL 0130:0134:trace:module:MODULE_InitDLL (00000001D0830000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0130:0134:trace:module:process_attach (L"actxprxy.dll",0000000000000000) - END 0130:0134:trace:module:EnumResourceNamesExW 00000001D0830000 L"WINE_REGISTRY" 00000001D09260D0 31d090 0130:0134:trace:module:FindResourceExW 00000001D0830000 L"WINE_REGISTRY" L"ACTXPRXY_ACTIVSCP_R_RES" 0000 0130:0134:trace:module:LoadResource 00000001D0830000 00000001D09751C8 0130:0134:trace:module:load_dll looking for L"atl100.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" at 0x1c1ef0000-0x1c1f1c000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .text at 0x1c1ef1000 off 1000 size c000 virt b530 flags 60000020 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .data at 0x1c1efd000 off d000 size 1000 virt 90 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .rodata at 0x1c1efe000 off e000 size 1000 virt 1d0 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .rdata at 0x1c1eff000 off f000 size 9000 virt 8890 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .pdata at 0x1c1f08000 off 18000 size 1000 virt 7d4 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .xdata at 0x1c1f09000 off 19000 size 1000 virt 7b4 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .bss at 0x1c1f0a000 off 0 size 0 virt 170 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .edata at 0x1c1f0b000 off 1a000 size d000 virt cf5d flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .idata at 0x1c1f18000 off 27000 size 1000 virt eb8 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .rsrc at 0x1c1f19000 off 28000 size 2000 virt 1f90 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" section .reloc at 0x1c1f1b000 off 2a000 size 1000 virt 108 flags 42000040 0130:0134:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"gdi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ole32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=4 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"oleaut32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\oleaut32.dll" for L"oleaut32.dll" at 00000002739C0000, count=2 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"shlwapi.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" at 0x2e3540000-0x2e3591000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .text at 0x2e3541000 off 1000 size 1e000 virt 1dac0 flags 60000060 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .data at 0x2e355f000 off 1f000 size 1000 virt 210 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rodata at 0x2e3560000 off 20000 size 2000 virt 18fc flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rdata at 0x2e3562000 off 22000 size b000 virt a290 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .pdata at 0x2e356d000 off 2d000 size 2000 virt 11b8 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .xdata at 0x2e356f000 off 2f000 size 2000 virt 13a8 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .bss at 0x2e3571000 off 0 size 0 virt 1c0 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .edata at 0x2e3572000 off 31000 size 14000 virt 13ab5 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .idata at 0x2e3586000 off 45000 size 5000 virt 442c flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rsrc at 0x2e358b000 off 4a000 size 5000 virt 4ed0 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .reloc at 0x2e3590000 off 4f000 size 1000 virt e0 flags 42000040 0130:0134:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"gdi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernelbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"shcore.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" 0130:0134:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" 0130:0134:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" at 0x3126f0000-0x312709000 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .text at 0x3126f1000 off 1000 size 9000 virt 8b70 flags 60000020 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .data at 0x3126fa000 off a000 size 1000 virt b0 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rodata at 0x3126fb000 off b000 size 1000 virt fb4 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rdata at 0x3126fc000 off c000 size 3000 virt 2360 flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .pdata at 0x3126ff000 off f000 size 1000 virt 57c flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .xdata at 0x312700000 off 10000 size 1000 virt 61c flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .bss at 0x312701000 off 0 size 0 virt 160 flags c0000080 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .edata at 0x312702000 off 11000 size 5000 virt 480e flags 40000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .idata at 0x312707000 off 16000 size 1000 virt c74 flags c0000040 0130:0134:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .reloc at 0x312708000 off 17000 size 1000 virt a8 flags 42000040 0130:0134:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ole32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=5 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" 0000000000480CE0 00000003126F0000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" at 00000003126F0000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" at 00000003126F0000 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" 000000000047E7C0 00000002E3540000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" at 00000002E3540000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" at 00000002E3540000 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0130:0134:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0130:0134:trace:module:import_dll is not hybrid module 0130:0134:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" 000000000047E420 00000001C1EF0000 0130:0134:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" at 00000001C1EF0000: builtin 0130:0134:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\atl100.dll" at 00000001C1EF0000 0130:0134:trace:module:process_attach (L"atl100.dll",0000000000000000) - START 0130:0134:trace:module:process_attach (L"shlwapi.dll",0000000000000000) - START 0130:0134:trace:module:process_attach (L"shcore.dll",0000000000000000) - START 0130:0134:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_ATTACH,0000000000000000) 00000003126F8FD0 - CALL 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031BE90, base 000000000031BE88. 0130:0134:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0130:0134:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0130:0134:trace:module:process_attach (L"shcore.dll",0000000000000000) - END 0130:0134:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_ATTACH,0000000000000000) 00000002E355DE00 - CALL 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031BF20, base 000000000031BF18. 0130:0134:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0130:0134:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0130:0134:trace:module:process_attach (L"shlwapi.dll",0000000000000000) - END 0130:0134:trace:module:MODULE_InitDLL (00000001C1EF0000 L"atl100.dll",PROCESS_ATTACH,0000000000000000) 00000001C1EFB6D0 - CALL 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031BFB0, base 000000000031BFA8. 0130:0134:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0130:0134:trace:module:MODULE_InitDLL (00000001C1EF0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0130:0134:trace:module:process_attach (L"atl100.dll",0000000000000000) - END 0130:0134:trace:module:LdrGetDllFullName module 00000001D0830000, name 000000000031C9C0. 0130:0134:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\actxprxy.dll" 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C730, base 000000000031C728. 0130:0134:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0130:0134:trace:process:GetEnvironmentVariableW (L"SystemRoot" 000000000031CA20 260) 0130:0134:trace:module:FindResourceExW 00000001D0830000 L"WINE_REGISTRY" L"ACTXPRXY_COMCAT_R_RES" 0000 0130:0134:trace:module:LoadResource 00000001D0830000 00000001D09751D8 0130:0134:trace:module:FindResourceExW 00000001D0830000 L"WINE_REGISTRY" L"ACTXPRXY_DOCOBJ_R_RES" 0000 0130:0134:trace:module:LoadResource 00000001D0830000 00000001D09751E8 0130:0134:trace:module:FindResourceExW 00000001D0830000 L"WINE_REGISTRY" L"ACTXPRXY_HLINK_R_RES" 0000 0130:0134:trace:module:LoadResource 00000001D0830000 00000001D09751F8 0130:0134:trace:module:FindResourceExW 00000001D0830000 L"WINE_REGISTRY" L"ACTXPRXY_HTIFACE_R_RES" 0000 0130:0134:trace:module:LoadResource 00000001D0830000 00000001D0975208 0130:0134:trace:module:FindResourceExW 00000001D0830000 L"WINE_REGISTRY" L"ACTXPRXY_HTIFRAME_R_RES" 0000 0130:0134:trace:module:LoadResource 00000001D0830000 00000001D0975218 0130:0134:trace:module:FindResourceExW 00000001D0830000 L"WINE_REGISTRY" L"ACTXPRXY_MSHTML_R_RES" 0000 0130:0134:trace:module:LoadResource 00000001D0830000 00000001D0975228 0130:0134:trace:module:FindResourceExW 00000001D0830000 L"WINE_REGISTRY" L"ACTXPRXY_OBJSAFE_R_RES" 0000 0130:0134:trace:module:LoadResource 00000001D0830000 00000001D0975238 0130:0134:trace:module:FindResourceExW 00000001D0830000 L"WINE_REGISTRY" L"ACTXPRXY_OCMM_R_RES" 0000 0130:0134:trace:module:LoadResource 00000001D0830000 00000001D0975248 0130:0134:trace:module:FindResourceExW 00000001D0830000 L"WINE_REGISTRY" L"ACTXPRXY_SERVPROV_R_RES" 0000 0130:0134:trace:module:LoadResource 00000001D0830000 00000001D0975258 0130:0134:trace:module:FindResourceExW 00000001D0830000 L"WINE_REGISTRY" L"ACTXPRXY_SHLDISP_R_RES" 0000 0130:0134:trace:module:LoadResource 00000001D0830000 00000001D0975268 0130:0134:trace:module:FindResourceExW 00000001D0830000 L"WINE_REGISTRY" L"ACTXPRXY_SHOBJIDL_R_RES" 0000 0130:0134:trace:module:LoadResource 00000001D0830000 00000001D0975278 0130:0134:trace:module:FindResourceExW 00000001D0830000 L"WINE_REGISTRY" L"ACTXPRXY_URLHIST_R_RES" 0000 0130:0134:trace:module:LoadResource 00000001D0830000 00000001D0975288 0130:0134:trace:module:LdrUnloadDll (00000001D0830000) 0130:0134:trace:module:LdrUnloadDll (L"actxprxy.dll") - START 0130:0134:trace:module:MODULE_DecRefCount (L"actxprxy.dll") ldr.LoadCount: 0 0130:0134:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 4 0130:0134:trace:module:MODULE_DecRefCount (L"oleaut32.dll") ldr.LoadCount: 1 0130:0134:trace:module:MODULE_DecRefCount (L"rpcrt4.dll") ldr.LoadCount: 4 0130:0134:trace:module:MODULE_InitDLL (00000001D0830000 L"actxprxy.dll",PROCESS_DETACH,0000000000000000) 00000001D09254B0 - CALL 0130:0134:trace:module:MODULE_InitDLL (00000001D0830000,PROCESS_DETACH,0000000000000000) - RETURN 1 0130:0134:trace:module:free_modref unloading L"C:\\windows\\system32\\actxprxy.dll" 0130:0134:trace:module:LdrUnloadDll END 0130:0134:trace:module:LdrResolveDelayLoadedAPI (000000021A7E0000, 000000021A817560, 0000000000000000, 000000007B60C498, 000000021A847BC0, 0x00000000) 0130:0134:trace:module:LdrUnloadDll (000000021A7E0000) 0130:0134:trace:module:LdrUnloadDll (L"setupapi.dll") - START 0130:0134:trace:module:MODULE_DecRefCount (L"setupapi.dll") ldr.LoadCount: 0 0130:0134:trace:module:MODULE_DecRefCount (L"rpcrt4.dll") ldr.LoadCount: 3 0130:0134:trace:module:MODULE_InitDLL (000000021A7E0000 L"setupapi.dll",PROCESS_DETACH,0000000000000000) 000000021A816860 - CALL 0130:0134:trace:module:MODULE_InitDLL (000000021A7E0000,PROCESS_DETACH,0000000000000000) - RETURN 1 0130:0134:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\setupapi.dll" 0130:0134:trace:module:LdrUnloadDll END 0130:0134:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FD50, base 000000000031FD48. 0130:0134:trace:module:LdrGetDllHandleEx L"mscoree" -> 0000000000000000 (load path (null)) 0130:0134:trace:module:LdrShutdownProcess () 0130:0134:trace:module:MODULE_InitDLL (00000001C1EF0000 L"atl100.dll",PROCESS_DETACH,0000000000000001) 00000001C1EFB6D0 - CALL 0130:0134:trace:module:MODULE_InitDLL (00000001C1EF0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_DETACH,0000000000000001) 00000002E355DE00 - CALL 0130:0134:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_DETACH,0000000000000001) 00000003126F8FD0 - CALL 0130:0134:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (00000002739C0000 L"oleaut32.dll",PROCESS_DETACH,0000000000000001) 0000000273A6A370 - CALL 0130:0134:trace:module:MODULE_InitDLL (00000002739C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_DETACH,0000000000000001) 00000002E8FB74E0 - CALL 0130:0134:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_DETACH,0000000000000001) 00000003270465C0 - CALL 0130:0134:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_DETACH,0000000000000001) 0000000231B26040 - CALL 0130:0134:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_DETACH,0000000000000001) 00000002F72424B0 - CALL 0130:0134:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (000000006DD10000 L"winemac.drv",PROCESS_DETACH,0000000000000001) 000000006DD28C10 - CALL 0130:0134:trace:module:MODULE_InitDLL (000000006DD10000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 0130:0134:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 0130:0134:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 0130:0134:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 0130:0134:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (000000006AC60000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006AD09460 - CALL 0130:0134:trace:module:MODULE_InitDLL (000000006AC60000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 0130:0134:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 0130:0134:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 0130:0134:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 0130:0134:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 0130:0134:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 0130:0134:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0130:0134:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 0130:0134:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0020:0024:trace:process:NtQueryInformationProcess (0x70,0x00000000,0x21f1d0,0x00000030,0x0) 0020:0024:trace:module:LdrShutdownProcess () 0020:0024:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_DETACH,0000000000000001) 00000001DD4524D0 - CALL 0020:0024:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0020:0024:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 0020:0024:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 0020:0024:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 0020:0024:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 0020:0024:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 0020:0024:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0020:0024:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 0020:0024:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0020:0024:trace:module:MODULE_InitDLL (000000006B560000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006B609460 - CALL 0020:0024:trace:module:MODULE_InitDLL (000000006B560000,PROCESS_DETACH,0000000000000001) - RETURN 1 0020:0024:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_DETACH,0000000000000001) 00000002D4D49C40 - CALL 0020:0024:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_DETACH,0000000000000001) - RETURN 1 0020:0024:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 0020:0024:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 0020:0024:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 0020:0024:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 0020:0024:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 0020:0024:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 0020:0024:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 0020:0024:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0020:0024:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 0020:0024:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 0020:0024:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 0020:0024:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0020:0024:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 0020:0024:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0128:012c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FD50, base 000000000031FD48. 0128:012c:trace:module:LdrGetDllHandleEx L"mscoree" -> 0000000000000000 (load path (null)) 0128:012c:trace:module:LdrShutdownProcess () 0128:012c:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 0128:012c:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0128:012c:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 0128:012c:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 0128:012c:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 0128:012c:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 0128:012c:trace:module:MODULE_InitDLL (000000006AC60000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006AD09460 - CALL 0128:012c:trace:module:MODULE_InitDLL (000000006AC60000,PROCESS_DETACH,0000000000000001) - RETURN 1 0128:012c:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 0128:012c:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0128:012c:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 0128:012c:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 0128:012c:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 0128:012c:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 0128:012c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 0128:012c:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 0128:012c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 0128:012c:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0128:012c:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 0128:012c:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 0128:012c:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 0128:012c:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0128:012c:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 0128:012c:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 -> rc=0 (took 7.85020303726196 seconds) Running '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wine' '--wl32-app' 'rundll32.exe' '--no-quotes' '--scope' 'private' '--winver' 'win10' '--desktop' 'root' '--dll' 'advpack=b;atl=b;oleaut32=b;rpcrt4=b;shdocvw=b;*iexplore.exe=b' 'setupapi.dll,InstallHinfSection' 'win10Install' '128' '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/share/crossover/bottle_data/crossover.inf' ***** Sat Jan 21 17:38:01 2023 Starting: '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wine' '--wl32-app' 'rundll32.exe' '--no-quotes' '--scope' 'private' '--winver' 'win10' '--desktop' 'root' '--dll' 'advpack=b;atl=b;oleaut32=b;rpcrt4=b;shdocvw=b;*iexplore.exe=b' 'setupapi.dll,InstallHinfSection' 'win10Install' '128' '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/share/crossover/bottle_data/crossover.inf' CXConfig->read(/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/etc/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/CrossOver.conf) Product version=22.1.0.35656 CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) Mode = 'private' Environment: CX_ROOT = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver" CX_BOTTLE = "SteamAMDWin10Test" WINEPREFIX = "/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test" CX_WINDOWS_VERSION = "win10" PATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin:/usr/local/opt/docker-virtualbox/bin:/usr/local/sbin:/Users/hoshi/opt/local/bin:/usr/local/bin:/System/Cryptexes/App/usr/bin:/usr/bin:/bin:/usr/sbin:/sbin:/Applications/VMware Fusion.app/Contents/Public:/usr/local/share/dotnet:/opt/X11/bin:~/.dotnet/tools:/Library/Apple/usr/bin:/Library/Frameworks/Mono.framework/Versions/Current/Commands" DYLD_LIBRARY_PATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib64" WINEDLLPATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine" WINEDLLOVERRIDES = "advpack=b;atl=b;oleaut32=b;rpcrt4=b;shdocvw=b;*iexplore.exe=b" LD_PRELOAD = LD_ASSUME_KERNEL = WINELOADER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64" WINESERVER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineserver" WINEDEBUG = "+pid,+process,+module,+loaddll,+seh,+threadname" WINEWRAPPER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe" CX_LOG = "/Users/hoshi/crossover-beta-wine10-amd.cxlog" CX_DEBUGMSG = "+pid,+process,+module,+loaddll,+seh,+threadname" DISPLAY = "/private/tmp/com.apple.launchd.EjtXTmJGw9/org.xquartz:0" VKD3D_DEBUG = VKD3D_SHADER_DEBUG = Command: /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64 /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe --no-quotes --desktop root --run -- /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/i386-windows/rundll32.exe setupapi.dll,InstallHinfSection win10Install 128 /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/share/crossover/bottle_data/crossover.inf ** Sat Jan 21 17:38:01 2023 Starting '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64' '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe' '--no-quotes' '--desktop' 'root' '--run' '--' '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/i386-windows/rundll32.exe' 'setupapi.dll,InstallHinfSection' 'win10Install' '128' '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/share/crossover/bottle_data/crossover.inf' preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0138:013c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0138:013c:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0138:013c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0138:013c:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0138:013c:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" is a fake Wine dll 0138:013c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0138:013c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0138:013c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0138:013c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0138:013c:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x321000 0138:013c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x21fa70,0x00000040,0x0) 0138:013c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0000000000332F30 0000000068A70000 0138:013c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" at 0000000068A70000: builtin 0138:013c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0138:013c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0138:013c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0138:013c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0138:013c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0138:013c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0138:013c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0138:013c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0138:013c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0138:013c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 00000000003337E0 000000007B000000 0138:013c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000: builtin 0138:013c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0138:013c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0000000000333370 000000007B600000 0138:013c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000: builtin 0138:013c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000 0138:013c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0138:013c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0138:013c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0138:013c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0138:013c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0138:013c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0138:013c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0138:013c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0138:013c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0138:013c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 00000000003304E0 00000001C8DB0000 0138:013c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000: builtin 0138:013c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0138:013c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"sechost.dll" in (null) 0138:013c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0138:013c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0138:013c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0138:013c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0138:013c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0138:013c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0138:013c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0138:013c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0138:013c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0138:013c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0000000000330BC0 00000003AF670000 0138:013c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000: builtin 0138:013c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0000000000330950 000000032A700000 0138:013c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000: builtin 0138:013c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0000000000330380 0000000330260000 0138:013c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000: builtin 0138:013c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"crypt32.dll" in (null) 0138:013c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" 0138:013c:trace:module:get_load_order_value got app defaults b for L"crypt32" 0138:013c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 0x1dd3f0000-0x1dd4be000 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .text at 0x1dd3f1000 off 1000 size 63000 virt 62550 flags 60000060 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .data at 0x1dd454000 off 64000 size 3000 virt 2640 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rodata at 0x1dd457000 off 67000 size 1000 virt 74c flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rdata at 0x1dd458000 off 68000 size 12000 virt 11830 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .pdata at 0x1dd46a000 off 7a000 size 3000 virt 2958 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .xdata at 0x1dd46d000 off 7d000 size 4000 virt 3260 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .bss at 0x1dd471000 off 0 size 0 virt 32d0 flags c0000080 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .edata at 0x1dd475000 off 81000 size 5000 virt 4c9c flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .idata at 0x1dd47a000 off 86000 size 2000 virt 1650 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rsrc at 0x1dd47c000 off 88000 size 41000 virt 40f48 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .reloc at 0x1dd4bd000 off c9000 size 1000 virt 514 flags 42000040 0138:013c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"bcrypt.dll" in (null) 0138:013c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 0138:013c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 0138:013c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 0x2d4d40000-0x2d4d57000 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .text at 0x2d4d41000 off 1000 size a000 virt 97c0 flags 60000020 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .data at 0x2d4d4b000 off b000 size 1000 virt 70 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rodata at 0x2d4d4c000 off c000 size 1000 virt 3b8 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rdata at 0x2d4d4d000 off d000 size 2000 virt 1c40 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .pdata at 0x2d4d4f000 off f000 size 1000 virt 420 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .xdata at 0x2d4d50000 off 10000 size 1000 virt 52c flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .bss at 0x2d4d51000 off 0 size 0 virt 170 flags c0000080 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .edata at 0x2d4d52000 off 11000 size 2000 virt 1317 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .idata at 0x2d4d54000 off 13000 size 1000 virt 6cc flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rsrc at 0x2d4d55000 off 14000 size 1000 virt 3c0 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .reloc at 0x2d4d56000 off 15000 size 1000 virt 44 flags 42000040 0138:013c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0138:013c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 0000000000336990 00000002D4D40000 0138:013c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 00000002D4D40000: builtin 0138:013c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 00000002D4D40000 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0138:013c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"user32.dll" in (null) 0138:013c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0138:013c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0138:013c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 0138:013c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=4 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0138:013c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0138:013c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0138:013c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 0138:013c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=5 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0138:013c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"user32.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"win32u.dll" in (null) 0138:013c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0138:013c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0138:013c:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" is a fake Wine dll 0138:013c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0138:013c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 00000000003376D0 000000006AC60000 0138:013c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006AC60000: builtin 0138:013c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006AC60000 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0000000000337270 000000026B4C0000 0138:013c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000: builtin 0138:013c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0138:013c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"sechost.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"version.dll" in (null) 0138:013c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0138:013c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0138:013c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 0138:013c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=11 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0138:013c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=13 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=6 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0000000000337B40 00000002F1FA0000 0138:013c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000: builtin 0138:013c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"win32u.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" for L"win32u.dll" at 000000006AC60000, count=2 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0000000000336E00 000000023D820000 0138:013c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000: builtin 0138:013c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" 0000000000330DD0 00000001DD3F0000 0138:013c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 00000001DD3F0000: builtin 0138:013c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 00000001DD3F0000 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=12 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0138:013c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=14 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:process_attach (L"ntdll.dll",000000000021FB00) - START 0138:013c:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000021FB00) 0000000170065B80 - CALL 0138:013c:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0138:013c:trace:module:process_attach (L"ntdll.dll",000000000021FB00) - END 0138:013c:trace:module:process_attach (L"kernel32.dll",000000000021FB00) - START 0138:013c:trace:module:process_attach (L"kernelbase.dll",000000000021FB00) - START 0138:013c:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000021FB00) 000000007B03CAD0 - CALL 0138:013c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x21f618,0x00000008,0x0) 0138:013c:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000021F2A0 85) 0138:013c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 0138:013c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000334510 17) 0138:013c:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000339E50, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021EFE8. 0138:013c:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0138:013c:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0138:013c:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0138:013c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0138:013c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0138:013c:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0138:013c:trace:module:LoadResource 0000000010000002 00000000100077D8 0138:013c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 0138:013c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000337040 17) 0138:013c:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000339EB0, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021EFE8. 0138:013c:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0138:013c:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0138:013c:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0138:013c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0138:013c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0138:013c:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0138:013c:trace:module:LoadResource 0000000010000002 00000000100077D8 0138:013c:trace:process:CreateProcessInternalW app L"C:\\windows\\system32\\conhost.exe" cmdline L"\"C:\\windows\\system32\\conhost.exe\" --unix --width 80 --height 24 --server 0x34" 0138:013c:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\conhost.exe" image L"C:\\windows\\system32\\conhost.exe" cmdline L"\"C:\\windows\\system32\\conhost.exe\" --unix --width 80 --height 24 --server 0x34" parent 0x0 0138:013c:trace:process:send_to_cx_loader loader (null) wineserversocket 7 stdin_fd 12 stdout_fd 14 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 0138:013c:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0140:0144:trace:module:get_load_order looking for L"C:\\windows\\system32\\conhost.exe" 0140:0144:trace:module:get_load_order got hardcoded default for L"conhost.exe" 0140:0144:trace:module:get_load_order looking for L"C:\\windows\\system32\\conhost.exe" 0140:0144:trace:module:get_load_order got hardcoded default for L"conhost.exe" 0140:0144:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\conhost.exe" at 0x140000000-0x14003b000 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .text at 0x140001000 off 1000 size 11000 virt 100d0 flags 60000060 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .data at 0x140012000 off 12000 size 1000 virt f0 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .rdata at 0x140013000 off 13000 size 2000 virt 18f0 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .pdata at 0x140015000 off 15000 size 1000 virt 5f4 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .xdata at 0x140016000 off 16000 size 1000 virt 69c flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .bss at 0x140017000 off 0 size 0 virt 1340 flags c0000080 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .idata at 0x140019000 off 17000 size 2000 virt 199c flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .rsrc at 0x14001b000 off 19000 size 1f000 virt 1eaf0 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .reloc at 0x14003a000 off 38000 size 1000 virt bc flags 42000040 0140:0144:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0140:0144:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0138:013c:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\conhost.exe" pid 0140 tid 0144 handles 0x44/0x48 0138:013c:trace:process:CreateProcessInternalW started process pid 0140 tid 0144 0138:013c:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0138:013c:trace:module:process_attach (L"kernelbase.dll",000000000021FB00) - END 0138:013c:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000021FB00) 000000007B631530 - CALL 0138:013c:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0138:013c:trace:module:process_attach (L"kernel32.dll",000000000021FB00) - END 0138:013c:trace:module:process_attach (L"advapi32.dll",000000000021FB00) - START 0138:013c:trace:module:process_attach (L"msvcrt.dll",000000000021FB00) - START 0138:013c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000021FB00) 00000001C8E1AB00 - CALL 0140:0144:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 0140:0144:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\conhost.exe" 0000000000432A60 0000000140000000 0140:0144:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\conhost.exe" at 0000000140000000: builtin 0140:0144:trace:module:load_dll looking for L"kernel32.dll" in (null) 0140:0144:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernel32.dll" 0140:0144:trace:module:get_load_order got hardcoded default for L"kernel32.dll" 0138:013c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F3B0. 0138:013c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0138:013c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F400. 0140:0144:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0138:013c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0138:013c:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0138:013c:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0138:013c:trace:module:process_attach (L"msvcrt.dll",000000000021FB00) - END 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0138:013c:trace:module:process_attach (L"sechost.dll",000000000021FB00) - START 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0138:013c:trace:module:process_attach (L"ucrtbase.dll",000000000021FB00) - START 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0138:013c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000021FB00) 00000003AF6F1C30 - CALL 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0140:0144:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0138:013c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F320. 0138:013c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0138:013c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F370. 0138:013c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0138:013c:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0138:013c:trace:module:process_attach (L"ucrtbase.dll",000000000021FB00) - END 0138:013c:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000021FB00) 000000032A716FC0 - CALL 0138:013c:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0138:013c:trace:module:process_attach (L"sechost.dll",000000000021FB00) - END 0138:013c:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000021FB00) 0000000330283EC0 - CALL 0138:013c:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0138:013c:trace:module:process_attach (L"advapi32.dll",000000000021FB00) - END 0138:013c:trace:module:process_attach (L"crypt32.dll",000000000021FB00) - START 0138:013c:trace:module:process_attach (L"bcrypt.dll",000000000021FB00) - START 0138:013c:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_ATTACH,000000000021FB00) 00000002D4D49C40 - CALL 0138:013c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F570, base 000000000021F568. 0138:013c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0140:0144:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernelbase.dll" 0140:0144:trace:module:get_load_order got hardcoded default for L"kernelbase.dll" 0140:0144:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0140:0144:trace:module:load_dll looking for L"ntdll.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 0000000000433150 000000007B000000 0140:0144:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 0140:0144:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"ntdll.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000432E60 000000007B600000 0140:0144:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 0140:0144:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 0138:013c:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0138:013c:trace:module:process_attach (L"bcrypt.dll",000000000021FB00) - END 0138:013c:trace:module:process_attach (L"user32.dll",000000000021FB00) - START 0138:013c:trace:module:process_attach (L"gdi32.dll",000000000021FB00) - START 0138:013c:trace:module:process_attach (L"win32u.dll",000000000021FB00) - START 0138:013c:trace:module:MODULE_InitDLL (000000006AC60000 L"win32u.dll",PROCESS_ATTACH,000000000021FB00) 000000006AD09460 - CALL 0140:0144:trace:module:load_dll looking for L"advapi32.dll" in (null) 0140:0144:trace:module:get_load_order looking for L"C:\\windows\\system32\\advapi32.dll" 0140:0144:trace:module:get_load_order got hardcoded default for L"advapi32.dll" 0140:0144:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0140:0144:trace:module:load_dll looking for L"kernel32.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0140:0144:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvcrt.dll" 0140:0144:trace:module:get_load_order got hardcoded default for L"msvcrt.dll" 0140:0144:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0140:0144:trace:module:load_dll looking for L"kernel32.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"ntdll.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 0000000000433660 00000001C8DB0000 0140:0144:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 0140:0144:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"ntdll.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"sechost.dll" in (null) 0140:0144:trace:module:get_load_order looking for L"C:\\windows\\system32\\sechost.dll" 0140:0144:trace:module:get_load_order got hardcoded default for L"sechost.dll" 0140:0144:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0140:0144:trace:module:load_dll looking for L"kernel32.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"ntdll.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0140:0144:trace:module:get_load_order looking for L"C:\\windows\\system32\\ucrtbase.dll" 0140:0144:trace:module:get_load_order got hardcoded default for L"ucrtbase.dll" 0140:0144:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0140:0144:trace:module:load_dll looking for L"kernel32.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"ntdll.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 0000000000433C40 00000003AF670000 0140:0144:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 0140:0144:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 0000000000433930 000000032A700000 0140:0144:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 0140:0144:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 0000000000433450 0000000330260000 0140:0144:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 0140:0144:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"gdi32.dll" in (null) 0140:0144:trace:module:get_load_order looking for L"C:\\windows\\system32\\gdi32.dll" 0140:0144:trace:module:get_load_order got hardcoded default for L"gdi32.dll" 0140:0144:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 0140:0144:trace:module:load_dll looking for L"advapi32.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"kernel32.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"ntdll.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"user32.dll" in (null) 0140:0144:trace:module:get_load_order looking for L"C:\\windows\\system32\\user32.dll" 0140:0144:trace:module:get_load_order got hardcoded default for L"user32.dll" 0140:0144:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 0140:0144:trace:module:load_dll looking for L"advapi32.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"gdi32.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"kernel32.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"ntdll.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"sechost.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"version.dll" in (null) 0140:0144:trace:module:get_load_order looking for L"C:\\windows\\system32\\version.dll" 0140:0144:trace:module:get_load_order got hardcoded default for L"version.dll" 0140:0144:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 0140:0144:trace:module:load_dll looking for L"kernel32.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"ntdll.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 00000000004345F0 00000002F1FA0000 0140:0144:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 00000002F1FA0000: builtin 0140:0144:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 00000002F1FA0000 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"win32u.dll" in (null) 0140:0144:trace:module:get_load_order looking for L"C:\\windows\\system32\\win32u.dll" 0140:0144:trace:module:get_load_order got hardcoded default for L"win32u.dll" 0140:0144:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\win32u.dll" is a fake Wine dll 0140:0144:trace:module:load_dll looking for L"kernel32.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"ntdll.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\win32u.dll" 0000000000434940 000000006B360000 0140:0144:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\win32u.dll" at 000000006B360000: builtin 0140:0144:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\win32u.dll" at 000000006B360000 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\user32.dll" 00000000004341E0 000000023D820000 0140:0144:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\user32.dll" at 000000023D820000: builtin 0140:0144:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\user32.dll" at 000000023D820000 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"win32u.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006B360000, count=2 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\gdi32.dll" 0000000000433F30 000000026B4C0000 0140:0144:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000: builtin 0140:0144:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"kernel32.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"ntdll.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"user32.dll" in (null) 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 0140:0144:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 0140:0144:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0140:0144:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 0140:0144:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 0140:0144:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 0140:0144:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 0140:0144:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 0140:0144:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 0140:0144:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 0140:0144:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000436D70 17) 0140:0144:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000436E80, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0140:0144:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0140:0144:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0140:0144:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0140:0144:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0140:0144:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0140:0144:trace:module:LoadResource 0000000010000002 00000000100077D8 0140:0144:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 0140:0144:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000436DC0 17) 0140:0144:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000436FA0, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0140:0144:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0140:0144:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0140:0144:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0140:0144:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0140:0144:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0140:0144:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0140:0144:trace:module:LoadResource 0000000010000002 00000000100077D8 0140:0144:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0140:0144:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 0140:0144:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 0140:0144:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0140:0144:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 0140:0144:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 0140:0144:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 0140:0144:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 0140:0144:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F3B0. 0140:0144:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 0140:0144:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F400. 0140:0144:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 0140:0144:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0140:0144:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0140:0144:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 0140:0144:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 0140:0144:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 0140:0144:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 0140:0144:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 0140:0144:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 0140:0144:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 0140:0144:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 0140:0144:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0140:0144:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 0140:0144:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 0140:0144:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0140:0144:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 0140:0144:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 0140:0144:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0140:0144:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 0140:0144:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - START 0140:0144:trace:module:process_attach (L"user32.dll",000000000031FB00) - START 0140:0144:trace:module:process_attach (L"version.dll",000000000031FB00) - START 0140:0144:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000031FB00) 00000002F1FA2510 - CALL 0140:0144:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0140:0144:trace:module:process_attach (L"version.dll",000000000031FB00) - END 0140:0144:trace:module:process_attach (L"win32u.dll",000000000031FB00) - START 0140:0144:trace:module:MODULE_InitDLL (000000006B360000 L"win32u.dll",PROCESS_ATTACH,000000000031FB00) 000000006B409460 - CALL 00a8:00c8:trace:module:LdrShutdownThread () 00a8:00c8:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_DETACH,0000000000000000) 0000000231B26040 - CALL 00a8:00c8:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_DETACH,0000000000000000) - RETURN 1 00a8:00c8:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_DETACH,0000000000000000) 00000003AF6F1C30 - CALL 00a8:00c8:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_DETACH,0000000000000000) - RETURN 1 00a8:00c8:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_DETACH,0000000000000000) 00000001C8E1AB00 - CALL 00a8:00c8:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_DETACH,0000000000000000) - RETURN 1 0138:013c:trace:module:MODULE_InitDLL (000000006AC60000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0138:013c:trace:module:process_attach (L"win32u.dll",000000000021FB00) - END 0138:013c:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000021FB00) 000000026B509F00 - CALL 0138:013c:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0138:013c:trace:module:process_attach (L"gdi32.dll",000000000021FB00) - END 0138:013c:trace:module:process_attach (L"version.dll",000000000021FB00) - START 0138:013c:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000021FB00) 00000002F1FA2510 - CALL 0138:013c:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0138:013c:trace:module:process_attach (L"version.dll",000000000021FB00) - END 0138:013c:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000021FB00) 000000023D8C5690 - CALL 0138:013c:trace:module:load_dll looking for L"imm32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0138:013c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0138:013c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0138:013c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 0138:013c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 0138:013c:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0138:013c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0138:013c:trace:module:import_dll is not hybrid module 0138:013c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0000000000342980 00000003AFD00000 0138:013c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000: builtin 0138:013c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000 0138:013c:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 0138:013c:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 0138:013c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021EBB0, base 000000000021EBA8. 0138:013c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0138:013c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021F048. 0138:013c:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 0138:013c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021EB60, base 000000000021EB58. 0138:013c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0138:013c:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0138:013c:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 0138:013c:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0138:013c:trace:module:process_attach (L"user32.dll",000000000021FB00) - END 0138:013c:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_ATTACH,000000000021FB00) 00000001DD4524D0 - CALL 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0138:013c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0138:013c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0138:013c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F600, base 000000000021F5F8. 0138:013c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0138:013c:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0138:013c:trace:module:process_attach (L"crypt32.dll",000000000021FB00) - END 0138:013c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x21f8b8,0x00000008,0x0) 0138:013c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F080, base 000000000021F078. 0138:013c:trace:module:LdrGetDllHandleEx L"kernel32" -> 000000007B600000 (load path (null)) 0138:013c:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0138:013c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0140:0144:trace:module:MODULE_InitDLL (000000006B360000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0140:0144:trace:module:process_attach (L"win32u.dll",000000000031FB00) - END 0140:0144:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000031FB00) 000000023D8C5690 - CALL 0140:0144:trace:module:load_dll looking for L"imm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0140:0144:trace:module:get_load_order looking for L"C:\\windows\\system32\\imm32.dll" 0140:0144:trace:module:get_load_order got hardcoded default for L"imm32.dll" 0140:0144:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 0140:0144:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 0140:0144:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0140:0144:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0140:0144:trace:module:import_dll is not hybrid module 0140:0144:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imm32.dll" 000000000043EF10 00000003AFD00000 0140:0144:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imm32.dll" at 00000003AFD00000: builtin 0140:0144:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imm32.dll" at 00000003AFD00000 0140:0144:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 0140:0144:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 0140:0144:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EBB0, base 000000000031EBA8. 0140:0144:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0140:0144:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031F048. 0140:0144:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 0140:0144:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EB60, base 000000000031EB58. 0140:0144:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0140:0144:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0140:0144:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 0140:0144:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0140:0144:trace:module:process_attach (L"user32.dll",000000000031FB00) - END 0140:0144:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000031FB00) 000000026B509F00 - CALL 0140:0144:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0140:0144:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - END 0140:0144:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 0140:0144:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FA50, base 000000000031FA48. 0140:0144:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0140:0144:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F5E0, base 000000000031F5D8. 0140:0144:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0138:013c:trace:process:CreateProcessInternalW app (null) cmdline L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe setupapi.dll,InstallHinfSection win10Install 128 Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\crossover\\bottle_d"... 0138:013c:trace:process:find_exe_file looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;.;C:\\windows\\system32;C:\\windows\\system;C:\\windows;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0138:013c:trace:process:NtCreateUserProcess L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" image L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" cmdline L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe setupapi.dll,InstallHinfSection win10Install 128 Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\crossover\\bottle_d"... parent 0x0 0138:013c:trace:process:send_to_cx_loader loader (null) wineserversocket 10 stdin_fd 0 stdout_fd 1 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 0138:013c:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" 0148:014c:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" 0148:014c:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" at 0x400000-0x409000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" section .text at 0x401000 off 1000 size 3000 virt 2028 flags 60000020 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" section .data at 0x404000 off 4000 size 1000 virt 38 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" section .rdata at 0x405000 off 5000 size 1000 virt 234 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" section .bss at 0x406000 off 0 size 0 virt c0 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" section .idata at 0x407000 off 6000 size 1000 virt 5cc flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" section .reloc at 0x408000 off 7000 size 1000 virt 1c4 flags 42000040 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\syswow64\\ntdll.dll" at 0x7bc00000-0x7bc97000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .text at 0x7bc01000 off 1000 size 66000 virt 652b8 flags 60000020 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .data at 0x7bc67000 off 67000 size 1000 virt b60 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .rodata at 0x7bc68000 off 68000 size 2000 virt 1ff4 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .rdata at 0x7bc6a000 off 6a000 size 11000 virt 10568 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .bss at 0x7bc7b000 off 0 size 0 virt 24e4 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .edata at 0x7bc7e000 off 7b000 size 13000 virt 12769 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .idata at 0x7bc91000 off 8e000 size 1000 virt 14 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .rsrc at 0x7bc92000 off 8f000 size 1000 virt 3ac flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .reloc at 0x7bc93000 off 90000 size 4000 virt 3e18 flags 42000040 0148:014c:trace:module:load_wow64_ntdll loaded L"\\??\\C:\\windows\\syswow64\\ntdll.dll" at 0x7bc00000 0148:014c:fixme:module:dlopen_32on64_opengl32 loaded "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_32on64-unix/opengl32.dll.so" early @ 0x6a158000 0148:014c:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x131000 0138:013c:trace:process:NtCreateUserProcess L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" pid 0148 tid 014c handles 0x74/0x78 0138:013c:trace:process:CreateProcessInternalW started process pid 0148 tid 014c 0148:014c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x70f790,0x00000040,0x0) 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" 0000000000812EA0 0000000000400000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" at 0000000000400000: builtin 0148:014c:trace:module:load_dll looking for L"C:\\windows\\system32\\wow64.dll" in (null) 0148:014c:trace:module:get_load_order looking for L"C:\\windows\\system32\\wow64.dll" 0148:014c:trace:module:get_load_order got hardcoded default for L"wow64.dll" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\wow64.dll" at 0x6f000000-0x6f026000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .text at 0x6f001000 off 1000 size 12000 virt 11ab0 flags 60000020 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .data at 0x6f013000 off 13000 size 1000 virt 840 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .rodata at 0x6f014000 off 14000 size 1000 virt 2a8 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .rdata at 0x6f015000 off 15000 size 3000 virt 2c70 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .pdata at 0x6f018000 off 18000 size 1000 virt d68 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .xdata at 0x6f019000 off 19000 size 1000 virt d5c flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .bss at 0x6f01a000 off 0 size 0 virt 4160 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .edata at 0x6f01f000 off 1a000 size 3000 virt 2c2c flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .idata at 0x6f022000 off 1d000 size 3000 virt 2908 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .reloc at 0x6f025000 off 20000 size 1000 virt 3f8 flags 42000040 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wow64.dll" 0000000000813350 000000006F000000 0148:014c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wow64.dll" at 000000006F000000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wow64.dll" at 000000006F000000 0148:014c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000070F3C0, base 000000000070F3B0. 0148:014c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0148:014c:trace:module:load_dll looking for L"\\??\\C:\\windows\\system32\\wow64cpu.dll" in (null) 0148:014c:trace:module:get_load_order looking for L"C:\\windows\\system32\\wow64cpu.dll" 0148:014c:trace:module:get_load_order got hardcoded default for L"wow64cpu.dll" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\wow64cpu.dll" at 0x6f100000-0x6f10c000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .text at 0x6f101000 off 1000 size 1000 virt 7c0 flags 60000020 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .data at 0x6f102000 off 2000 size 1000 virt 40 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .rodata at 0x6f103000 off 3000 size 1000 virt 24 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .rdata at 0x6f104000 off 4000 size 1000 virt a0 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .pdata at 0x6f105000 off 5000 size 1000 virt 84 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .xdata at 0x6f106000 off 6000 size 1000 virt 5c flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .bss at 0x6f107000 off 0 size 0 virt 2000 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .edata at 0x6f109000 off 7000 size 1000 virt 21e flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .idata at 0x6f10a000 off 8000 size 1000 virt 21c flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .reloc at 0x6f10b000 off 9000 size 1000 virt 1c flags 42000040 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"wow64.dll" in (null) 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\wow64.dll" for L"wow64.dll" at 000000006F000000, count=2 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wow64cpu.dll" 0000000000813580 000000006F100000 0148:014c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wow64cpu.dll" at 000000006F100000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wow64cpu.dll" at 000000006F100000 0148:014c:trace:module:process_attach (L"wow64cpu.dll",0000000000000000) - START 0148:014c:trace:module:process_attach (L"wow64.dll",0000000000000000) - START 0148:014c:trace:module:MODULE_InitDLL (000000006F000000 L"wow64.dll",PROCESS_ATTACH,0000000000000000) 000000006F012780 - CALL 0148:014c:trace:module:MODULE_InitDLL (000000006F000000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0148:014c:trace:module:process_attach (L"wow64.dll",0000000000000000) - END 0148:014c:trace:module:MODULE_InitDLL (000000006F100000 L"wow64cpu.dll",PROCESS_ATTACH,0000000000000000) 000000006F101790 - CALL 0148:014c:trace:module:MODULE_InitDLL (000000006F100000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0148:014c:trace:module:process_attach (L"wow64cpu.dll",0000000000000000) - END 0148:014c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x70ef70,0x00000040,0x0) 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" 00922C28 00400000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" at 00400000: builtin 0148:014c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" 0148:014c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 30c10 flags 60000020 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 220 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 3000 virt 2050 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .rdata at 0x7b636000 off 36000 size 4000 virt 31a4 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .bss at 0x7b63a000 off 0 size 0 virt 180 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .edata at 0x7b63b000 off 3a000 size 10000 virt f594 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .idata at 0x7b64b000 off 4a000 size 8000 virt 7484 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .rsrc at 0x7b653000 off 52000 size 8000 virt 7dfc flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" section .reloc at 0x7b65b000 off 5a000 size 3000 virt 24c8 flags 42000040 0148:014c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" 0148:014c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" at 0x7b000000-0x7b24a000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 85000 virt 84860 flags 60000020 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .data at 0x7b086000 off 86000 size 2000 virt 1c6c flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .rodata at 0x7b088000 off 88000 size 2000 virt 1d88 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .rdata at 0x7b08a000 off 8a000 size 1e000 virt 1d218 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .bss at 0x7b0a8000 off 0 size 0 virt 1da0 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .edata at 0x7b0aa000 off a8000 size 20000 virt 1f88e flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .idata at 0x7b0ca000 off c8000 size 4000 virt 3700 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .rsrc at 0x7b0ce000 off cc000 size 176000 virt 1757f0 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" section .reloc at 0x7b244000 off 242000 size 6000 virt 5450 flags 42000040 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=2 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" 009231F0 7B000000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" at 7B000000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" at 7B000000 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=3 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" 00922EC0 7B600000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" at 7B600000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" at 7B600000 0148:014c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=2 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=4 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" 0148:014c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" at 0xa70000-0xb35000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .text at 0xa71000 off 1000 size 8c000 virt 8b1a0 flags 60000060 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .data at 0xafd000 off 8d000 size 2000 virt 11b8 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .rodata at 0xaff000 off 8f000 size 4000 virt 3ad4 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .rdata at 0xb03000 off 93000 size d000 virt c1e4 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .bss at 0xb10000 off 0 size 0 virt 16e0 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .edata at 0xb12000 off a0000 size 1a000 virt 19455 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .idata at 0xb2c000 off ba000 size 2000 virt 14cc flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .rsrc at 0xb2e000 off bc000 size 1000 virt 3c8 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" section .reloc at 0xb2f000 off bd000 size 6000 virt 5d7c flags 42000040 0148:014c:trace:module:perform_relocations relocating from 70B40000-70C05000 to 00A70000-00B35000 0148:014c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=3 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=5 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" 00923418 00A70000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" at 00A70000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" at 00A70000 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"user32.dll" in (null) 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" 0148:014c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" at 0x6ed00000-0x6eece000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .text at 0x6ed01000 off 1000 size b1000 virt b0720 flags 60000060 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .data at 0x6edb2000 off b2000 size 1000 virt 694 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .rodata at 0x6edb3000 off b3000 size 1000 virt eb8 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .rdata at 0x6edb4000 off b4000 size 17000 virt 16570 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .bss at 0x6edcb000 off 0 size 0 virt 244 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .edata at 0x6edcc000 off cb000 size 11000 virt 10fb1 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .idata at 0x6eddd000 off dc000 size 4000 virt 3e50 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .rsrc at 0x6ede1000 off e0000 size e5000 virt e4818 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" section .reloc at 0x6eec6000 off 1c5000 size 8000 virt 7140 flags 42000040 0148:014c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" 0148:014c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" at 0x61740000-0x6177d000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .text at 0x61741000 off 1000 size 25000 virt 24f34 flags 60000060 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .data at 0x61766000 off 26000 size 1000 virt 140 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .rodata at 0x61767000 off 27000 size 1000 virt e5c flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .rdata at 0x61768000 off 28000 size 6000 virt 51a0 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .bss at 0x6176e000 off 0 size 0 virt d00 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .edata at 0x6176f000 off 2e000 size 8000 virt 73da flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .idata at 0x61777000 off 36000 size 3000 virt 25d8 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .rsrc at 0x6177a000 off 39000 size 1000 virt 3c8 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" section .reloc at 0x6177b000 off 3a000 size 2000 virt 1be0 flags 42000040 0148:014c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=4 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" for L"kernelbase.dll" at 7B000000, count=2 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" 0148:014c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" at 0xb40000-0xbdb000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .text at 0xb41000 off 1000 size 73000 virt 72cc0 flags 60000060 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .data at 0xbb4000 off 74000 size 2000 virt 1094 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .rodata at 0xbb6000 off 76000 size 2000 virt 1554 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .rdata at 0xbb8000 off 78000 size b000 virt a244 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .bss at 0xbc3000 off 0 size 0 virt 14a0 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .edata at 0xbc5000 off 83000 size e000 virt d915 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .idata at 0xbd3000 off 91000 size 2000 virt 1310 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .rsrc at 0xbd5000 off 93000 size 1000 virt 398 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" section .reloc at 0xbd6000 off 94000 size 5000 virt 4710 flags 42000040 0148:014c:trace:module:perform_relocations relocating from 6A280000-6A31B000 to 00B40000-00BDB000 0148:014c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=5 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=6 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" 00923B58 00B40000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" at 00B40000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\msvcrt.dll" at 00B40000 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=7 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"sechost.dll" in (null) 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" 0148:014c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" at 0x6bc00000-0x6bc28000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" section .text at 0x6bc01000 off 1000 size 18000 virt 17578 flags 60000060 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" section .data at 0x6bc19000 off 19000 size 1000 virt 104 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" section .rodata at 0x6bc1a000 off 1a000 size 1000 virt f0c flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" section .rdata at 0x6bc1b000 off 1b000 size 4000 virt 34a0 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" section .bss at 0x6bc1f000 off 0 size 0 virt c0 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" section .edata at 0x6bc20000 off 1f000 size 5000 virt 46ad flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" section .idata at 0x6bc25000 off 24000 size 1000 virt e78 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" section .reloc at 0x6bc26000 off 25000 size 2000 virt 1018 flags 42000040 0148:014c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=6 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" for L"kernelbase.dll" at 7B000000, count=3 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=8 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00A70000, count=2 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" 00923D98 6BC00000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" at 6BC00000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" at 6BC00000 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" 00923828 61740000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" at 61740000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" at 61740000 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" 0148:014c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" at 0x6c9c0000-0x6ca3b000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .text at 0x6c9c1000 off 1000 size 4e000 virt 4d580 flags 60000060 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .data at 0x6ca0f000 off 4f000 size 1000 virt 6ec flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .rodata at 0x6ca10000 off 50000 size 1000 virt d8c flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .rdata at 0x6ca11000 off 51000 size 14000 virt 13018 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .bss at 0x6ca25000 off 0 size 0 virt e0 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .edata at 0x6ca26000 off 65000 size 9000 virt 8564 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .idata at 0x6ca2f000 off 6e000 size 3000 virt 20f0 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .rsrc at 0x6ca32000 off 71000 size 5000 virt 422c flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" section .reloc at 0x6ca37000 off 76000 size 4000 virt 32e8 flags 42000040 0148:014c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" for L"advapi32.dll" at 61740000, count=2 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=7 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=9 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00A70000, count=3 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"user32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" for L"user32.dll" at 6ED00000, count=2 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"win32u.dll" in (null) 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\win32u.dll" 0148:014c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\win32u.dll" 0148:014c:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\win32u.dll" is a fake Wine dll 0148:014c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=8 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=10 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\win32u.dll" 009242C0 6A580000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\win32u.dll" at 6A580000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\win32u.dll" at 6A580000 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" 00924100 6C9C0000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" at 6C9C0000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" at 6C9C0000 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=9 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" for L"kernelbase.dll" at 7B000000, count=4 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=11 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"sechost.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\sechost.dll" for L"sechost.dll" at 6BC00000, count=2 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00A70000, count=4 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"version.dll" in (null) 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" 0148:014c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" at 0x63480000-0x6348b000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .text at 0x63481000 off 1000 size 2000 virt 1ff8 flags 60000020 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .data at 0x63483000 off 3000 size 1000 virt 50 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .rodata at 0x63484000 off 4000 size 1000 virt 84 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .rdata at 0x63485000 off 5000 size 1000 virt 210 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .bss at 0x63486000 off 0 size 0 virt a0 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .edata at 0x63487000 off 6000 size 1000 virt 327 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .idata at 0x63488000 off 7000 size 1000 virt 604 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .rsrc at 0x63489000 off 8000 size 1000 virt 3b4 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" section .reloc at 0x6348a000 off 9000 size 1000 virt 1b8 flags 42000040 0148:014c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=10 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" for L"kernelbase.dll" at 7B000000, count=5 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=12 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00A70000, count=5 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" 009244E0 63480000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" at 63480000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" at 63480000 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"win32u.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\win32u.dll" for L"win32u.dll" at 6A580000, count=2 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" 00923620 6ED00000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" at 6ED00000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" at 6ED00000 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:process_attach (L"ntdll.dll",0060FD24) - START 0148:014c:trace:module:MODULE_InitDLL (7BC00000 L"ntdll.dll",PROCESS_ATTACH,0060FD24) 7BC658D0 - CALL 0148:014c:trace:module:MODULE_InitDLL (7BC00000,PROCESS_ATTACH,0060FD24) - RETURN 1 0148:014c:trace:module:process_attach (L"ntdll.dll",0060FD24) - END 0148:014c:trace:module:process_attach (L"kernel32.dll",0060FD24) - START 0148:014c:trace:module:process_attach (L"kernelbase.dll",0060FD24) - START 0148:014c:trace:module:MODULE_InitDLL (7B000000 L"kernelbase.dll",PROCESS_ATTACH,0060FD24) 7B03CDC0 - CALL 0148:014c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x70ef70,0x00000008,0x0) 0148:014c:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 0060F65A 85) 0148:014c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 00000000 0) 0148:014c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 00923178 17) 0148:014c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 00000000 0) 0148:014c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 00923178 17) 0148:014c:trace:module:MODULE_InitDLL (7B000000,PROCESS_ATTACH,0060FD24) - RETURN 1 0148:014c:trace:module:process_attach (L"kernelbase.dll",0060FD24) - END 0148:014c:trace:module:MODULE_InitDLL (7B600000 L"kernel32.dll",PROCESS_ATTACH,0060FD24) 7B631790 - CALL 0148:014c:trace:process:set_entry_point setting FT_Thunk at 7B63B634 to 00000000 0148:014c:trace:module:MODULE_InitDLL (7B600000,PROCESS_ATTACH,0060FD24) - RETURN 1 0148:014c:trace:module:process_attach (L"kernel32.dll",0060FD24) - END 0148:014c:trace:module:process_attach (L"ucrtbase.dll",0060FD24) - START 0148:014c:trace:module:MODULE_InitDLL (00A70000 L"ucrtbase.dll",PROCESS_ATTACH,0060FD24) 00AFB780 - CALL 0148:014c:trace:module:LdrGetDllFullName module 00000000, name 0060F7D8. 0148:014c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" 0148:014c:trace:module:LdrGetDllFullName module 00000000, name 0060F828. 0148:014c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" 0148:014c:trace:module:MODULE_InitDLL (00A70000,PROCESS_ATTACH,0060FD24) - RETURN 1 0148:014c:trace:module:process_attach (L"ucrtbase.dll",0060FD24) - END 0148:014c:trace:module:process_attach (L"user32.dll",0060FD24) - START 0148:014c:trace:module:process_attach (L"advapi32.dll",0060FD24) - START 0148:014c:trace:module:process_attach (L"msvcrt.dll",0060FD24) - START 0148:014c:trace:module:MODULE_InitDLL (00B40000 L"msvcrt.dll",PROCESS_ATTACH,0060FD24) 00BB34A0 - CALL 0148:014c:trace:module:LdrGetDllFullName module 00000000, name 0060F718. 0148:014c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" 0148:014c:trace:module:LdrGetDllFullName module 00000000, name 0060F768. 0148:014c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" 0148:014c:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0148:014c:trace:module:MODULE_InitDLL (00B40000,PROCESS_ATTACH,0060FD24) - RETURN 1 0148:014c:trace:module:process_attach (L"msvcrt.dll",0060FD24) - END 0148:014c:trace:module:process_attach (L"sechost.dll",0060FD24) - START 0148:014c:trace:module:MODULE_InitDLL (6BC00000 L"sechost.dll",PROCESS_ATTACH,0060FD24) 6BC17830 - CALL 0148:014c:trace:module:MODULE_InitDLL (6BC00000,PROCESS_ATTACH,0060FD24) - RETURN 1 0148:014c:trace:module:process_attach (L"sechost.dll",0060FD24) - END 0148:014c:trace:module:MODULE_InitDLL (61740000 L"advapi32.dll",PROCESS_ATTACH,0060FD24) 61765190 - CALL 0148:014c:trace:module:MODULE_InitDLL (61740000,PROCESS_ATTACH,0060FD24) - RETURN 1 0148:014c:trace:module:process_attach (L"advapi32.dll",0060FD24) - END 0148:014c:trace:module:process_attach (L"gdi32.dll",0060FD24) - START 0148:014c:trace:module:process_attach (L"win32u.dll",0060FD24) - START 0148:014c:trace:module:MODULE_InitDLL (6A580000 L"win32u.dll",PROCESS_ATTACH,0060FD24) 6A637E90 - CALL 0148:014c:trace:module:MODULE_InitDLL (6A580000,PROCESS_ATTACH,0060FD24) - RETURN 1 0148:014c:trace:module:process_attach (L"win32u.dll",0060FD24) - END 0148:014c:trace:module:MODULE_InitDLL (6C9C0000 L"gdi32.dll",PROCESS_ATTACH,0060FD24) 6CA0D950 - CALL 0148:014c:trace:module:MODULE_InitDLL (6C9C0000,PROCESS_ATTACH,0060FD24) - RETURN 1 0148:014c:trace:module:process_attach (L"gdi32.dll",0060FD24) - END 0148:014c:trace:module:process_attach (L"version.dll",0060FD24) - START 0148:014c:trace:module:MODULE_InitDLL (63480000 L"version.dll",PROCESS_ATTACH,0060FD24) 634825E0 - CALL 0148:014c:trace:module:MODULE_InitDLL (63480000,PROCESS_ATTACH,0060FD24) - RETURN 1 0148:014c:trace:module:process_attach (L"version.dll",0060FD24) - END 0148:014c:trace:module:MODULE_InitDLL (6ED00000 L"user32.dll",PROCESS_ATTACH,0060FD24) 6EDB0710 - CALL 0148:014c:trace:module:load_dll looking for L"imm32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\imm32.dll" 0148:014c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\imm32.dll" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\imm32.dll" at 0x1400000-0x1419000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\imm32.dll" section .text at 0x1401000 off 1000 size d000 virt c620 flags 60000060 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\imm32.dll" section .data at 0x140e000 off e000 size 1000 virt ac flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\imm32.dll" section .rodata at 0x140f000 off f000 size 1000 virt 3ec flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\imm32.dll" section .rdata at 0x1410000 off 10000 size 2000 virt 1994 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\imm32.dll" section .bss at 0x1412000 off 0 size 0 virt c0 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\imm32.dll" section .edata at 0x1413000 off 12000 size 3000 virt 2b28 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\imm32.dll" section .idata at 0x1416000 off 15000 size 1000 virt a08 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\imm32.dll" section .rsrc at 0x1417000 off 16000 size 1000 virt 3a4 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\imm32.dll" section .reloc at 0x1418000 off 17000 size 1000 virt a9c flags 42000040 0148:014c:trace:module:perform_relocations relocating from 71200000-71219000 to 01400000-01419000 0148:014c:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" for L"advapi32.dll" at 61740000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00A70000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" for L"user32.dll" at 6ED00000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\imm32.dll" 0097F438 01400000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\imm32.dll" at 01400000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\imm32.dll" at 01400000 0148:014c:trace:module:process_attach (L"imm32.dll",00000000) - START 0148:014c:trace:module:MODULE_InitDLL (01400000 L"imm32.dll",PROCESS_ATTACH,00000000) 0140CB90 - CALL 0148:014c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 00000000, dll_characteristics 00000000, name 0060F188, base 0060F184. 0148:014c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 7BC00000 (load path (null)) 0148:014c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 00000000, dll_characteristics 00000000, name 0060F5C8, base 0060F5C4. 0148:014c:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 01400000 (load path (null)) 0148:014c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 00000000, dll_characteristics 00000000, name 0060F138, base 0060F134. 0148:014c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 7BC00000 (load path (null)) 0148:014c:trace:module:MODULE_InitDLL (01400000,PROCESS_ATTACH,00000000) - RETURN 1 0148:014c:trace:module:process_attach (L"imm32.dll",00000000) - END 0148:014c:trace:module:MODULE_InitDLL (6ED00000,PROCESS_ATTACH,0060FD24) - RETURN 1 0148:014c:trace:module:process_attach (L"user32.dll",0060FD24) - END 0148:014c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x70ef70,0x00000008,0x0) 0148:014c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 00000000, dll_characteristics 00000000, name 0060F6A8, base 0060F6A4. 0148:014c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 7BC00000 (load path (null)) 0148:014c:trace:module:load_dll looking for L"winemac.drv" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\winemac.drv" 0148:014c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\winemac.drv" 0148:014c:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\winemac.drv" is a fake Wine dll 0148:014c:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" for L"advapi32.dll" at 61740000, count=-1 0148:014c:trace:module:load_dll looking for L"gdi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" for L"gdi32.dll" at 6C9C0000, count=-1 0148:014c:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=-1 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=-1 0148:014c:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" for L"user32.dll" at 6ED00000, count=-1 0148:014c:trace:module:load_dll looking for L"win32u.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\win32u.dll" for L"win32u.dll" at 6A580000, count=-1 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\winemac.drv" 0097F658 6B8C0000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\winemac.drv" at 6B8C0000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\winemac.drv" at 6B8C0000 0148:014c:trace:module:process_attach (L"winemac.drv",00000000) - START 0148:014c:trace:module:MODULE_InitDLL (6B8C0000 L"winemac.drv",PROCESS_ATTACH,00000000) 6B8F00D0 - CALL 0148:014c:trace:module:LdrGetDllFullName module 00000000, name 0060D028. 0148:014c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" 0148:014c:trace:module:FindResourceExW 6B8C0000 #0006 #0011 0000 0148:014c:trace:module:LoadResource 6B8C0000 6B959C78 0148:014c:trace:module:FindResourceExW 6B8C0000 #0006 #0011 0000 0148:014c:trace:module:LoadResource 6B8C0000 6B959C78 0148:014c:trace:module:FindResourceExW 6B8C0000 #0006 #0011 0000 0148:014c:trace:module:LoadResource 6B8C0000 6B959C78 0148:014c:trace:module:FindResourceExW 6B8C0000 #0006 #0011 0000 0148:014c:trace:module:LoadResource 6B8C0000 6B959C78 0148:014c:trace:module:FindResourceExW 6B8C0000 #0006 #0011 0000 0148:014c:trace:module:LoadResource 6B8C0000 6B959C78 0148:014c:trace:module:FindResourceExW 6B8C0000 #0006 #0011 0000 0148:014c:trace:module:LoadResource 6B8C0000 6B959C78 0148:014c:trace:module:FindResourceExW 6B8C0000 #0006 #0011 0000 0148:014c:trace:module:LoadResource 6B8C0000 6B959C78 0148:014c:trace:module:FindResourceExW 6B8C0000 #0006 #0012 0000 0148:014c:trace:module:LoadResource 6B8C0000 6B959E68 0148:014c:trace:module:FindResourceExW 6B8C0000 #0006 #0012 0000 0148:014c:trace:module:LoadResource 6B8C0000 6B959E68 0148:014c:trace:module:FindResourceExW 6B8C0000 #0006 #0012 0000 0148:014c:trace:module:LoadResource 6B8C0000 6B959E68 0148:014c:trace:module:FindResourceExW 6B8C0000 #0006 #0012 0000 0148:014c:trace:module:LoadResource 6B8C0000 6B959E68 0148:014c:trace:module:FindResourceExW 6B8C0000 #0006 #0012 0000 0148:014c:trace:module:LoadResource 6B8C0000 6B959E68 0148:014c:trace:module:MODULE_InitDLL (6B8C0000,PROCESS_ATTACH,00000000) - RETURN 1 0148:014c:trace:module:process_attach (L"winemac.drv",00000000) - END 0148:014c:trace:module:EnumResourceNamesExW 00000000 #000e 6B8E5230 60e888 0148:014c:trace:module:FindResourceExW 6ED00000 #000c #7f00 0000 0148:014c:trace:module:LoadResource 6ED00000 6EDE54B0 0148:014c:trace:module:FindResourceExW 6ED00000 #0001 #0003 0000 0148:014c:trace:module:LdrGetDllFullName module 6ED00000, name 0060E268. 0148:014c:trace:module:LoadResource 6ED00000 6EDE3880 0148:014c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 00000000, dll_characteristics 00000000, name 0060DB78, base 0060DB74. 0148:014c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 7BC00000 (load path (null)) 0148:014c:trace:module:LdrGetDllFullName module 6ED00000, name 0060DF38. 0148:014c:trace:module:FindResourceExW 6ED00000 #000c #7f00 0000 0148:014c:trace:module:LoadResource 6ED00000 6EDE54B0 0148:014c:trace:module:FindResourceExW 6ED00000 #0001 #0003 0000 0148:014c:trace:module:LdrGetDllFullName module 6ED00000, name 0060E268. 0148:014c:trace:module:FindResourceExW 6ED00000 #000c #7f00 0000 0148:014c:trace:module:LoadResource 6ED00000 6EDE54B0 0148:014c:trace:module:FindResourceExW 6ED00000 #0001 #0003 0000 0148:014c:trace:module:LdrGetDllFullName module 6ED00000, name 0060E268. 0148:014c:trace:module:FindResourceExW 6ED00000 #000c #7f00 0000 0148:014c:trace:module:LoadResource 6ED00000 6EDE54B0 0148:014c:trace:module:FindResourceExW 6ED00000 #0001 #0003 0000 0148:014c:trace:module:LdrGetDllFullName module 6ED00000, name 0060E268. 0148:014c:trace:module:FindResourceExW 6ED00000 #000c #7f01 0000 0148:014c:trace:module:LoadResource 6ED00000 6EDE54C0 0148:014c:trace:module:FindResourceExW 6ED00000 #0001 #0009 0000 0148:014c:trace:module:LdrGetDllFullName module 6ED00000, name 0060E268. 0148:014c:trace:module:LoadResource 6ED00000 6EDE38E0 0148:014c:trace:module:LdrGetDllFullName module 6ED00000, name 0060DF38. 0148:014c:trace:module:FindResourceExW 6ED00000 #000c #7f00 0000 0148:014c:trace:module:LoadResource 6ED00000 6EDE54B0 0148:014c:trace:module:FindResourceExW 6ED00000 #0001 #0003 0000 0148:014c:trace:module:LdrGetDllFullName module 6ED00000, name 0060E268. 0148:014c:trace:module:FindResourceExW 6ED00000 #000c #7f00 0000 0148:014c:trace:module:LoadResource 6ED00000 6EDE54B0 0148:014c:trace:module:FindResourceExW 6ED00000 #0001 #0003 0000 0148:014c:trace:module:LdrGetDllFullName module 6ED00000, name 0060E268. 0148:014c:trace:module:FindResourceExW 6ED00000 #000c #7f00 0000 0148:014c:trace:module:LoadResource 6ED00000 6EDE54B0 0148:014c:trace:module:FindResourceExW 6ED00000 #0001 #0003 0000 0148:014c:trace:module:LdrGetDllFullName module 6ED00000, name 0060E268. 0148:014c:trace:module:FindResourceExW 6ED00000 #000c #7f00 0000 0148:014c:trace:module:LoadResource 6ED00000 6EDE54B0 0148:014c:trace:module:FindResourceExW 6ED00000 #0001 #0003 0000 0148:014c:trace:module:LdrGetDllFullName module 6ED00000, name 0060E268. 0148:014c:trace:module:FindResourceExW 6ED00000 #000c #7f00 0000 0148:014c:trace:module:LoadResource 6ED00000 6EDE54B0 0148:014c:trace:module:FindResourceExW 6ED00000 #0001 #0003 0000 0148:014c:trace:module:LdrGetDllFullName module 6ED00000, name 0060E268. 0148:014c:trace:module:FindResourceExW 6ED00000 #000c #7f00 0000 0148:014c:trace:module:LoadResource 6ED00000 6EDE54B0 0148:014c:trace:module:FindResourceExW 6ED00000 #0001 #0003 0000 0148:014c:trace:module:LdrGetDllFullName module 6ED00000, name 0060E268. 0148:014c:trace:module:FindResourceExW 6ED00000 #000c #7f00 0000 0148:014c:trace:module:LoadResource 6ED00000 6EDE54B0 0148:014c:trace:module:FindResourceExW 6ED00000 #0001 #0003 0000 0148:014c:trace:module:LdrGetDllFullName module 6ED00000, name 0060E268. 0148:014c:trace:module:load_dll looking for L"uxtheme.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\uxtheme.dll" 0148:014c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\uxtheme.dll" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\uxtheme.dll" at 0x1440000-0x1473000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\uxtheme.dll" section .text at 0x1441000 off 1000 size 14000 virt 1325c flags 60000060 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\uxtheme.dll" section .data at 0x1455000 off 15000 size 1000 virt d8 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\uxtheme.dll" section .rodata at 0x1456000 off 16000 size 1000 virt 43c flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\uxtheme.dll" section .rdata at 0x1457000 off 17000 size 16000 virt 15580 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\uxtheme.dll" section .bss at 0x146d000 off 0 size 0 virt 400 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\uxtheme.dll" section .edata at 0x146e000 off 2d000 size 2000 virt 1ddf flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\uxtheme.dll" section .idata at 0x1470000 off 2f000 size 1000 virt fec flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\uxtheme.dll" section .rsrc at 0x1471000 off 30000 size 1000 virt 5f4 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\uxtheme.dll" section .reloc at 0x1472000 off 31000 size 1000 virt c78 flags 42000040 0148:014c:trace:module:perform_relocations relocating from 68700000-68733000 to 01440000-01473000 0148:014c:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" for L"advapi32.dll" at 61740000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"gdi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" for L"gdi32.dll" at 6C9C0000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00A70000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" for L"user32.dll" at 6ED00000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\uxtheme.dll" 00985B78 01440000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\uxtheme.dll" at 01440000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\uxtheme.dll" at 01440000 0148:014c:trace:module:process_attach (L"uxtheme.dll",00000000) - START 0148:014c:trace:module:MODULE_InitDLL (01440000 L"uxtheme.dll",PROCESS_ATTACH,00000000) 01453540 - CALL 0148:014c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 00000000, dll_characteristics 00000000, name 0060E0A8, base 0060E0A4. 0148:014c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 7BC00000 (load path (null)) 0148:014c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 00000000, dll_characteristics 00000000, name 0060E2B8, base 0060E2B4. 0148:014c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 7BC00000 (load path (null)) 0148:014c:trace:module:LdrGetDllHandleEx flags 0, load_path 009869B8, dll_characteristics 00000000, name 0060E4B8, base 0060E464. 0148:014c:trace:module:open_dll_file L"\\??\\C:\\windows\\resources\\themes\\light\\light.msstyles" is for arch 8664, continuing search 0148:014c:trace:module:LdrGetDllHandleEx L"C:\\windows\\resources\\themes\\light\\light.msstyles" -> 00000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0148:014c:trace:module:FindResourceExW 01480001 L"PACKTHEM_VERSION" #0001 0000 0148:014c:trace:module:LoadResource 01480001 01485310 0148:014c:trace:module:FindResourceExW 01480001 L"COLORNAMES" #0001 0000 0148:014c:trace:module:LoadResource 01480001 014852F0 0148:014c:trace:module:FindResourceExW 01480001 L"SIZENAMES" #0001 0000 0148:014c:trace:module:LoadResource 01480001 01485320 0148:014c:trace:module:FindResourceExW 01480001 L"FILERESNAMES" #0001 0000 0148:014c:trace:module:LoadResource 01480001 01485300 0148:014c:trace:module:FindResourceExW 01480001 L"TEXTFILE" L"BLUE_INI" 0000 0148:014c:trace:module:LoadResource 01480001 01485330 0148:014c:trace:module:MODULE_InitDLL (01440000,PROCESS_ATTACH,00000000) - RETURN 1 0148:014c:trace:module:process_attach (L"uxtheme.dll",00000000) - END 0148:014c:trace:module:load_dll looking for L"winemac.drv" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\winemac.drv" for L"winemac.drv" at 6B8C0000, count=2 0148:014c:trace:module:FindResourceExW 6ED00000 #000c #7f00 0000 0148:014c:trace:module:LoadResource 6ED00000 6EDE54B0 0148:014c:trace:module:FindResourceExW 6ED00000 #0001 #0003 0000 0148:014c:trace:module:LdrGetDllFullName module 6ED00000, name 0060F4A8. 0148:014c:trace:module:LdrGetDllFullName module 00000000, name 0060F4E8. 0148:014c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" 0148:014c:trace:module:LdrGetDllHandleEx flags 0, load_path 00984118, dll_characteristics 00000000, name 0060F458, base 0060F404. 0148:014c:trace:module:LdrAddRefDll (L"rundll32.exe") ldr.LoadCount: -1 0148:014c:trace:module:LdrGetDllHandleEx L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rundll32.exe" -> 00400000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0148:014c:trace:module:FindResourceExW 00400000 #0010 #0001 0000 0148:014c:trace:module:LdrUnloadDll (00400000) 0148:014c:trace:module:LdrUnloadDll (L"rundll32.exe") - START 0148:014c:trace:module:LdrUnloadDll END 0148:014c:trace:module:FindResourceExW 6ED00000 #0004 L"SYSMENU" 0000 0148:014c:trace:module:LoadResource 6ED00000 6EDE4940 0148:014c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 00000000, dll_characteristics 00000000, name 0060EF48, base 0060EF44. 0148:014c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 7BC00000 (load path (null)) 0148:014c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 00000000, dll_characteristics 00000000, name 0060F7F8, base 0060F7F4. 0148:014c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 7BC00000 (load path (null)) 0148:014c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 00000000, dll_characteristics 00000000, name 0060F528, base 0060F524. 0148:014c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 7BC00000 (load path (null)) 0148:014c:trace:module:CreateActCtxW 0060FAA8 00000008 0148:014c:trace:module:load_dll looking for L"setupapi.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\setupapi.dll" 0148:014c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\setupapi.dll" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\setupapi.dll" at 0x1bc0000-0x1c37000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\setupapi.dll" section .text at 0x1bc1000 off 1000 size 3b000 virt 3ae2c flags 60000060 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\setupapi.dll" section .data at 0x1bfc000 off 3c000 size 1000 virt 180 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\setupapi.dll" section .rodata at 0x1bfd000 off 3d000 size 3000 virt 2460 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\setupapi.dll" section .rdata at 0x1c00000 off 40000 size d000 virt c510 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\setupapi.dll" section .bss at 0x1c0d000 off 0 size 0 virt 480 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\setupapi.dll" section .edata at 0x1c0e000 off 4d000 size 18000 virt 171c2 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\setupapi.dll" section .idata at 0x1c26000 off 65000 size 2000 virt 1848 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\setupapi.dll" section .rsrc at 0x1c28000 off 67000 size c000 virt bf00 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\setupapi.dll" section .reloc at 0x1c34000 off 73000 size 3000 virt 294c flags 42000040 0148:014c:trace:module:perform_relocations relocating from 6BCC0000-6BD37000 to 01BC0000-01C37000 0148:014c:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" for L"advapi32.dll" at 61740000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"kernelbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" for L"kernelbase.dll" at 7B000000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"rpcrt4.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rpcrt4.dll" 0148:014c:trace:module:get_load_order_value got environment b for L"rpcrt4" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rpcrt4.dll" at 0x62fc0000-0x63042000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rpcrt4.dll" section .text at 0x62fc1000 off 1000 size 4a000 virt 49e1c flags 60000060 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rpcrt4.dll" section .data at 0x6300b000 off 4b000 size 1000 virt 4a4 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rpcrt4.dll" section .rodata at 0x6300c000 off 4c000 size 2000 virt 1b40 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rpcrt4.dll" section .rdata at 0x6300e000 off 4e000 size 13000 virt 12be4 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rpcrt4.dll" section .bss at 0x63021000 off 0 size 0 virt 384 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rpcrt4.dll" section .edata at 0x63022000 off 61000 size 17000 virt 166d6 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rpcrt4.dll" section .idata at 0x63039000 off 78000 size 2000 virt 13f8 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rpcrt4.dll" section .rsrc at 0x6303b000 off 7a000 size 1000 virt 3a8 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rpcrt4.dll" section .reloc at 0x6303c000 off 7b000 size 6000 virt 52c0 flags 42000040 0148:014c:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" for L"advapi32.dll" at 61740000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00A70000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rpcrt4.dll" 009A1F08 62FC0000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rpcrt4.dll" at 62FC0000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rpcrt4.dll" at 62FC0000 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00A70000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"version.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\version.dll" for L"version.dll" at 63480000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\setupapi.dll" 009A1BB8 01BC0000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\setupapi.dll" at 01BC0000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\setupapi.dll" at 01BC0000 0148:014c:trace:module:process_attach (L"setupapi.dll",00000000) - START 0148:014c:trace:module:process_attach (L"rpcrt4.dll",00000000) - START 0148:014c:trace:module:MODULE_InitDLL (62FC0000 L"rpcrt4.dll",PROCESS_ATTACH,00000000) 63009C70 - CALL 0148:014c:trace:module:MODULE_InitDLL (62FC0000,PROCESS_ATTACH,00000000) - RETURN 1 0148:014c:trace:module:process_attach (L"rpcrt4.dll",00000000) - END 0148:014c:trace:module:MODULE_InitDLL (01BC0000 L"setupapi.dll",PROCESS_ATTACH,00000000) 01BFB2A0 - CALL 0148:014c:trace:module:MODULE_InitDLL (01BC0000,PROCESS_ATTACH,00000000) - RETURN 1 0148:014c:trace:module:process_attach (L"setupapi.dll",00000000) - END 0148:014c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 00000000, dll_characteristics 00000000, name 0060F518, base 0060F514. 0148:014c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 7BC00000 (load path (null)) 0148:014c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 00000000, dll_characteristics 00000000, name 0060F248, base 0060F244. 0148:014c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 7BC00000 (load path (null)) 0148:014c:trace:module:LdrGetDllHandleEx flags 0, load_path 009BA4E8, dll_characteristics 00000000, name 0060EC78, base 0060EC24. 0148:014c:trace:module:LdrGetDllHandleEx L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\crossover\\bottle_data\\Notify.wav" -> 00000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0148:014c:trace:module:LdrGetDllHandleEx flags 0, load_path 009BA4E8, dll_characteristics 00000000, name 0060EC78, base 0060EC24. 0148:014c:trace:module:LdrGetDllHandleEx L"C:\\windows\\\\Media\\Notify.wav" -> 00000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0148:014c:trace:module:LdrGetDllHandleEx flags 0, load_path 009BA598, dll_characteristics 00000000, name 0060EC78, base 0060EC24. 0148:014c:trace:module:LdrGetDllHandleEx L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\crossover\\bottle_data\\oem0.cat" -> 00000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0148:014c:trace:module:LdrGetDllHandleEx flags 0, load_path 009BA598, dll_characteristics 00000000, name 0060EC78, base 0060EC24. 0148:014c:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\\\catroot\\{f750e6c3-38ee-11d1-85e5-00c04fc295ee}\\oem0.cat" -> 00000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0148:014c:trace:module:LdrResolveDelayLoadedAPI (01BC0000, 01BFBDBC, 00000000, 7B60B074, 01C2662C, 0x00000000) 0148:014c:trace:module:load_dll looking for L"ole32.dll" in (null) 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ole32.dll" 0148:014c:trace:module:get_load_order_value got standard key b for L"ole32" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ole32.dll" at 0x1c40000-0x1d54000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ole32.dll" section .text at 0x1c41000 off 1000 size af000 virt ae950 flags 60000060 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ole32.dll" section .data at 0x1cf0000 off b0000 size 1000 virt 37c flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ole32.dll" section .rodata at 0x1cf1000 off b1000 size 1000 virt 778 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ole32.dll" section .rdata at 0x1cf2000 off b2000 size 19000 virt 189e0 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ole32.dll" section .bss at 0x1d0b000 off 0 size 0 virt 104 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ole32.dll" section .edata at 0x1d0c000 off cb000 size 18000 virt 17435 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ole32.dll" section .idata at 0x1d24000 off e3000 size 3000 virt 2b78 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ole32.dll" section .rsrc at 0x1d27000 off e6000 size 25000 virt 24bc0 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ole32.dll" section .reloc at 0x1d4c000 off 10b000 size 8000 virt 7b68 flags 42000040 0148:014c:trace:module:perform_relocations relocating from 6A400000-6A514000 to 01C40000-01D54000 0148:014c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" for L"advapi32.dll" at 61740000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"combase.dll" in (null) 0148:014c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\combase.dll" 0148:014c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\combase.dll" 0148:014c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\combase.dll" at 0x1d60000-0x1db4000 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\combase.dll" section .text at 0x1d61000 off 1000 size 2a000 virt 29714 flags 60000060 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\combase.dll" section .data at 0x1d8b000 off 2b000 size 1000 virt 344 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\combase.dll" section .rodata at 0x1d8c000 off 2c000 size 2000 virt 15d0 flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\combase.dll" section .rdata at 0x1d8e000 off 2e000 size d000 virt c104 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\combase.dll" section .bss at 0x1d9b000 off 0 size 0 virt e0 flags c0000080 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\combase.dll" section .edata at 0x1d9c000 off 3b000 size 13000 virt 12ab5 flags 40000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\combase.dll" section .idata at 0x1daf000 off 4e000 size 2000 virt 132c flags c0000040 0148:014c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\combase.dll" section .reloc at 0x1db1000 off 50000 size 3000 virt 27d8 flags 42000040 0148:014c:trace:module:perform_relocations relocating from 68500000-68554000 to 01D60000-01DB4000 0148:014c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\advapi32.dll" for L"advapi32.dll" at 61740000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" for L"gdi32.dll" at 6C9C0000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ole32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ole32.dll" for L"ole32.dll" at 01C40000, count=2 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rpcrt4.dll" for L"rpcrt4.dll" at 62FC0000, count=2 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00A70000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"user32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" for L"user32.dll" at 6ED00000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\combase.dll" 009BA2B8 01D60000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\combase.dll" at 01D60000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\combase.dll" at 01D60000 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\gdi32.dll" for L"gdi32.dll" at 6C9C0000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernel32.dll" for L"kernel32.dll" at 7B600000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\kernelbase.dll" for L"kernelbase.dll" at 7B000000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0148:014c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 7BC00000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\rpcrt4.dll" for L"rpcrt4.dll" at 62FC0000, count=3 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00A70000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:load_dll looking for L"user32.dll" in (null) 0148:014c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\user32.dll" for L"user32.dll" at 6ED00000, count=-1 0148:014c:trace:module:import_dll is not hybrid module 0148:014c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ole32.dll" 009B9F98 01C40000 0148:014c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ole32.dll" at 01C40000: builtin 0148:014c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\ole32.dll" at 01C40000 0148:014c:trace:module:process_attach (L"ole32.dll",00000000) - START 0148:014c:trace:module:process_attach (L"combase.dll",00000000) - START 0148:014c:trace:module:MODULE_InitDLL (01D60000 L"combase.dll",PROCESS_ATTACH,00000000) 01D89A00 - CALL 0148:014c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 00000000, dll_characteristics 00000000, name 0060ED98, base 0060ED94. 0148:014c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 7BC00000 (load path (null)) 0148:014c:trace:module:MODULE_InitDLL (01D60000,PROCESS_ATTACH,00000000) - RETURN 1 0148:014c:trace:module:process_attach (L"combase.dll",00000000) - END 0148:014c:trace:module:MODULE_InitDLL (01C40000 L"ole32.dll",PROCESS_ATTACH,00000000) 01CEE6A0 - CALL 0148:014c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 00000000, dll_characteristics 00000000, name 0060EE28, base 0060EE24. 0148:014c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 7BC00000 (load path (null)) 0148:014c:trace:module:MODULE_InitDLL (01C40000,PROCESS_ATTACH,00000000) - RETURN 1 0148:014c:trace:module:process_attach (L"ole32.dll",00000000) - END 0148:014c:trace:module:load_dll looking for L"C:\\windows\\system32\\actxprxy.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0148:014c:warn:module:load_dll Failed to load module L"C:\\windows\\system32\\actxprxy.dll"; status=c0000135 0148:014c:trace:module:LdrResolveDelayLoadedAPI (01BC0000, 01BFBDBC, 00000000, 7B60B074, 01C26630, 0x00000000) 0148:014c:trace:module:LdrUnloadDll (01BC0000) 0148:014c:trace:module:LdrUnloadDll (L"setupapi.dll") - START 0148:014c:trace:module:MODULE_DecRefCount (L"setupapi.dll") ldr.LoadCount: 0 0148:014c:trace:module:MODULE_DecRefCount (L"rpcrt4.dll") ldr.LoadCount: 2 0148:014c:trace:module:MODULE_InitDLL (01BC0000 L"setupapi.dll",PROCESS_DETACH,00000000) 01BFB2A0 - CALL 0148:014c:trace:module:MODULE_InitDLL (01BC0000,PROCESS_DETACH,00000000) - RETURN 1 0148:014c:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\i386-windows\\setupapi.dll" 0148:014c:trace:module:LdrUnloadDll END 0148:014c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 00000000, dll_characteristics 00000000, name 0060FE58, base 0060FE54. 0148:014c:trace:module:LdrGetDllHandleEx L"mscoree" -> 00000000 (load path (null)) 0148:014c:trace:module:LdrShutdownProcess () 0148:014c:trace:module:MODULE_InitDLL (01C40000 L"ole32.dll",PROCESS_DETACH,00000001) 01CEE6A0 - CALL 0148:014c:trace:module:MODULE_InitDLL (01C40000,PROCESS_DETACH,00000001) - RETURN 1 0148:014c:trace:module:MODULE_InitDLL (01D60000 L"combase.dll",PROCESS_DETACH,00000001) 01D89A00 - CALL 0148:014c:trace:module:MODULE_InitDLL (01D60000,PROCESS_DETACH,00000001) - RETURN 1 0148:014c:trace:module:MODULE_InitDLL (62FC0000 L"rpcrt4.dll",PROCESS_DETACH,00000001) 63009C70 - CALL 0148:014c:trace:module:MODULE_InitDLL (62FC0000,PROCESS_DETACH,00000001) - RETURN 1 0148:014c:trace:module:MODULE_InitDLL (01440000 L"uxtheme.dll",PROCESS_DETACH,00000001) 01453540 - CALL 0148:014c:trace:module:MODULE_InitDLL (01440000,PROCESS_DETACH,00000001) - RETURN 1 0148:014c:trace:module:MODULE_InitDLL (6B8C0000 L"winemac.drv",PROCESS_DETACH,00000001) 6B8F00D0 - CALL 0148:014c:trace:module:MODULE_InitDLL (6B8C0000,PROCESS_DETACH,00000001) - RETURN 1 0148:014c:trace:module:MODULE_InitDLL (01400000 L"imm32.dll",PROCESS_DETACH,00000001) 0140CB90 - CALL 0148:014c:trace:module:MODULE_InitDLL (01400000,PROCESS_DETACH,00000001) - RETURN 1 0148:014c:trace:module:MODULE_InitDLL (6ED00000 L"user32.dll",PROCESS_DETACH,00000001) 6EDB0710 - CALL 0148:014c:trace:module:MODULE_InitDLL (6ED00000,PROCESS_DETACH,00000001) - RETURN 1 0148:014c:trace:module:MODULE_InitDLL (63480000 L"version.dll",PROCESS_DETACH,00000001) 634825E0 - CALL 0148:014c:trace:module:MODULE_InitDLL (63480000,PROCESS_DETACH,00000001) - RETURN 1 0148:014c:trace:module:MODULE_InitDLL (6C9C0000 L"gdi32.dll",PROCESS_DETACH,00000001) 6CA0D950 - CALL 0148:014c:trace:module:MODULE_InitDLL (6C9C0000,PROCESS_DETACH,00000001) - RETURN 1 0148:014c:trace:module:MODULE_InitDLL (6A580000 L"win32u.dll",PROCESS_DETACH,00000001) 6A637E90 - CALL 0148:014c:trace:module:MODULE_InitDLL (6A580000,PROCESS_DETACH,00000001) - RETURN 1 0148:014c:trace:module:MODULE_InitDLL (61740000 L"advapi32.dll",PROCESS_DETACH,00000001) 61765190 - CALL 0148:014c:trace:module:MODULE_InitDLL (61740000,PROCESS_DETACH,00000001) - RETURN 1 0148:014c:trace:module:MODULE_InitDLL (6BC00000 L"sechost.dll",PROCESS_DETACH,00000001) 6BC17830 - CALL 0148:014c:trace:module:MODULE_InitDLL (6BC00000,PROCESS_DETACH,00000001) - RETURN 1 0148:014c:trace:module:MODULE_InitDLL (00B40000 L"msvcrt.dll",PROCESS_DETACH,00000001) 00BB34A0 - CALL 0148:014c:trace:module:MODULE_InitDLL (00B40000,PROCESS_DETACH,00000001) - RETURN 1 0148:014c:trace:module:MODULE_InitDLL (00A70000 L"ucrtbase.dll",PROCESS_DETACH,00000001) 00AFB780 - CALL 0148:014c:trace:module:MODULE_InitDLL (00A70000,PROCESS_DETACH,00000001) - RETURN 1 0148:014c:trace:module:MODULE_InitDLL (7B600000 L"kernel32.dll",PROCESS_DETACH,00000001) 7B631790 - CALL 0148:014c:trace:module:MODULE_InitDLL (7B600000,PROCESS_DETACH,00000001) - RETURN 1 0148:014c:trace:module:MODULE_InitDLL (7B000000 L"kernelbase.dll",PROCESS_DETACH,00000001) 7B03CDC0 - CALL 0148:014c:trace:module:MODULE_InitDLL (7B000000,PROCESS_DETACH,00000001) - RETURN 1 0148:014c:trace:module:MODULE_InitDLL (7BC00000 L"ntdll.dll",PROCESS_DETACH,00000001) 7BC658D0 - CALL 0148:014c:trace:module:MODULE_InitDLL (7BC00000,PROCESS_DETACH,00000001) - RETURN 1 0138:013c:trace:process:NtQueryInformationProcess (0x74,0x00000000,0x21f1d0,0x00000030,0x0) 0138:013c:trace:module:LdrShutdownProcess () 0138:013c:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_DETACH,0000000000000001) 00000001DD4524D0 - CALL 0138:013c:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0138:013c:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 0138:013c:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 0138:013c:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 0138:013c:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 0138:013c:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 0138:013c:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0138:013c:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 0138:013c:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0138:013c:trace:module:MODULE_InitDLL (000000006AC60000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006AD09460 - CALL 0138:013c:trace:module:MODULE_InitDLL (000000006AC60000,PROCESS_DETACH,0000000000000001) - RETURN 1 0138:013c:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_DETACH,0000000000000001) 00000002D4D49C40 - CALL 0138:013c:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_DETACH,0000000000000001) - RETURN 1 0138:013c:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 0138:013c:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 0138:013c:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 0138:013c:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 0138:013c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 0138:013c:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 0138:013c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 0138:013c:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0138:013c:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 0138:013c:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 0138:013c:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 0138:013c:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0138:013c:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 0138:013c:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0140:0144:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FD50, base 000000000031FD48. 0140:0144:trace:module:LdrGetDllHandleEx L"mscoree" -> 0000000000000000 (load path (null)) 0140:0144:trace:module:LdrShutdownProcess () 0140:0144:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 0140:0144:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0140:0144:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 0140:0144:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 0140:0144:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 0140:0144:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 0140:0144:trace:module:MODULE_InitDLL (000000006B360000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006B409460 - CALL 0140:0144:trace:module:MODULE_InitDLL (000000006B360000,PROCESS_DETACH,0000000000000001) - RETURN 1 0140:0144:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 0140:0144:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0140:0144:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 0140:0144:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 0140:0144:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 0140:0144:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 0140:0144:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 0140:0144:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 0140:0144:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 0140:0144:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0140:0144:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 0140:0144:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 0140:0144:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 0140:0144:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0140:0144:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 0140:0144:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 -> rc=0 (took 0.574717044830322 seconds) Running '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wine' '--wl-app' 'rundll32.exe' '--no-quotes' '--scope' 'private' '--winver' 'win10' '--desktop' 'root' 'mscoree.dll,wine_install_mono' ***** Sat Jan 21 17:38:02 2023 Starting: '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wine' '--wl-app' 'rundll32.exe' '--no-quotes' '--scope' 'private' '--winver' 'win10' '--desktop' 'root' 'mscoree.dll,wine_install_mono' CXConfig->read(/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/etc/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/CrossOver.conf) Product version=22.1.0.35656 CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) Mode = 'private' Environment: CX_ROOT = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver" CX_BOTTLE = "SteamAMDWin10Test" WINEPREFIX = "/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test" CX_WINDOWS_VERSION = "win10" PATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin:/usr/local/opt/docker-virtualbox/bin:/usr/local/sbin:/Users/hoshi/opt/local/bin:/usr/local/bin:/System/Cryptexes/App/usr/bin:/usr/bin:/bin:/usr/sbin:/sbin:/Applications/VMware Fusion.app/Contents/Public:/usr/local/share/dotnet:/opt/X11/bin:~/.dotnet/tools:/Library/Apple/usr/bin:/Library/Frameworks/Mono.framework/Versions/Current/Commands" DYLD_LIBRARY_PATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib64" WINEDLLPATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine" WINEDLLOVERRIDES = LD_PRELOAD = LD_ASSUME_KERNEL = WINELOADER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64" WINESERVER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineserver" WINEDEBUG = "+pid,+process,+module,+loaddll,+seh,+threadname" WINEWRAPPER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe" CX_LOG = "/Users/hoshi/crossover-beta-wine10-amd.cxlog" CX_DEBUGMSG = "+pid,+process,+module,+loaddll,+seh,+threadname" DISPLAY = "/private/tmp/com.apple.launchd.EjtXTmJGw9/org.xquartz:0" VKD3D_DEBUG = VKD3D_SHADER_DEBUG = CXConfig->read(/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/etc/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) Command: /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64 /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe --no-quotes --desktop root --run -- /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/rundll32.exe mscoree.dll,wine_install_mono ** Sat Jan 21 17:38:02 2023 Starting '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64' '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe' '--no-quotes' '--desktop' 'root' '--run' '--' '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/rundll32.exe' 'mscoree.dll,wine_install_mono' preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0150:0154:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0150:0154:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0150:0154:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0150:0154:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0150:0154:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" is a fake Wine dll 0150:0154:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0150:0154:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0150:0154:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0150:0154:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0150:0154:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x321000 0150:0154:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x21fa70,0x00000040,0x0) 0150:0154:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0000000000332D90 0000000068A70000 0150:0154:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" at 0000000068A70000: builtin 0150:0154:trace:module:load_dll looking for L"kernel32.dll" in (null) 0150:0154:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0150:0154:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0150:0154:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0150:0154:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0150:0154:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0150:0154:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0150:0154:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0150:0154:trace:module:load_dll looking for L"ntdll.dll" in (null) 0150:0154:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0000000000333640 000000007B000000 0150:0154:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000: builtin 0150:0154:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ntdll.dll" in (null) 0150:0154:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 00000000003331D0 000000007B600000 0150:0154:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000: builtin 0150:0154:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000 0150:0154:trace:module:load_dll looking for L"advapi32.dll" in (null) 0150:0154:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0150:0154:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0150:0154:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0150:0154:trace:module:load_dll looking for L"kernel32.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0150:0154:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0150:0154:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0150:0154:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0150:0154:trace:module:load_dll looking for L"kernel32.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ntdll.dll" in (null) 0150:0154:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0000000000330380 00000001C8DB0000 0150:0154:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000: builtin 0150:0154:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ntdll.dll" in (null) 0150:0154:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"sechost.dll" in (null) 0150:0154:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0150:0154:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0150:0154:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0150:0154:trace:module:load_dll looking for L"kernel32.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ntdll.dll" in (null) 0150:0154:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0150:0154:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0150:0154:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0150:0154:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0150:0154:trace:module:load_dll looking for L"kernel32.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ntdll.dll" in (null) 0150:0154:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0000000000330A60 00000003AF670000 0150:0154:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000: builtin 0150:0154:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 00000000003307F0 000000032A700000 0150:0154:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000: builtin 0150:0154:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0000000000331500 0000000330260000 0150:0154:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000: builtin 0150:0154:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"crypt32.dll" in (null) 0150:0154:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" 0150:0154:trace:module:get_load_order_value got app defaults b for L"crypt32" 0150:0154:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 0x1dd3f0000-0x1dd4be000 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .text at 0x1dd3f1000 off 1000 size 63000 virt 62550 flags 60000060 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .data at 0x1dd454000 off 64000 size 3000 virt 2640 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rodata at 0x1dd457000 off 67000 size 1000 virt 74c flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rdata at 0x1dd458000 off 68000 size 12000 virt 11830 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .pdata at 0x1dd46a000 off 7a000 size 3000 virt 2958 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .xdata at 0x1dd46d000 off 7d000 size 4000 virt 3260 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .bss at 0x1dd471000 off 0 size 0 virt 32d0 flags c0000080 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .edata at 0x1dd475000 off 81000 size 5000 virt 4c9c flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .idata at 0x1dd47a000 off 86000 size 2000 virt 1650 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rsrc at 0x1dd47c000 off 88000 size 41000 virt 40f48 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .reloc at 0x1dd4bd000 off c9000 size 1000 virt 514 flags 42000040 0150:0154:trace:module:load_dll looking for L"advapi32.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"bcrypt.dll" in (null) 0150:0154:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 0150:0154:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 0150:0154:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 0x2d4d40000-0x2d4d57000 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .text at 0x2d4d41000 off 1000 size a000 virt 97c0 flags 60000020 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .data at 0x2d4d4b000 off b000 size 1000 virt 70 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rodata at 0x2d4d4c000 off c000 size 1000 virt 3b8 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rdata at 0x2d4d4d000 off d000 size 2000 virt 1c40 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .pdata at 0x2d4d4f000 off f000 size 1000 virt 420 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .xdata at 0x2d4d50000 off 10000 size 1000 virt 52c flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .bss at 0x2d4d51000 off 0 size 0 virt 170 flags c0000080 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .edata at 0x2d4d52000 off 11000 size 2000 virt 1317 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .idata at 0x2d4d54000 off 13000 size 1000 virt 6cc flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rsrc at 0x2d4d55000 off 14000 size 1000 virt 3c0 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .reloc at 0x2d4d56000 off 15000 size 1000 virt 44 flags 42000040 0150:0154:trace:module:load_dll looking for L"advapi32.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"kernel32.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ntdll.dll" in (null) 0150:0154:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 00000000003318D0 00000002D4D40000 0150:0154:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 00000002D4D40000: builtin 0150:0154:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 00000002D4D40000 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"kernel32.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ntdll.dll" in (null) 0150:0154:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"user32.dll" in (null) 0150:0154:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0150:0154:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0150:0154:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 0150:0154:trace:module:load_dll looking for L"advapi32.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=4 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"gdi32.dll" in (null) 0150:0154:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0150:0154:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0150:0154:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 0150:0154:trace:module:load_dll looking for L"advapi32.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=5 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"kernel32.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ntdll.dll" in (null) 0150:0154:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"user32.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"win32u.dll" in (null) 0150:0154:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0150:0154:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0150:0154:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" is a fake Wine dll 0150:0154:trace:module:load_dll looking for L"kernel32.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ntdll.dll" in (null) 0150:0154:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0000000000337460 000000006B360000 0150:0154:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006B360000: builtin 0150:0154:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006B360000 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0000000000336F80 000000026B4C0000 0150:0154:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000: builtin 0150:0154:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"kernel32.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ntdll.dll" in (null) 0150:0154:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"sechost.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"version.dll" in (null) 0150:0154:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0150:0154:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0150:0154:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 0150:0154:trace:module:load_dll looking for L"kernel32.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=11 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ntdll.dll" in (null) 0150:0154:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=13 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=6 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 00000000003378D0 00000002F1FA0000 0150:0154:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000: builtin 0150:0154:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"win32u.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" for L"win32u.dll" at 000000006B360000, count=2 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0000000000331D40 000000023D820000 0150:0154:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000: builtin 0150:0154:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" 0000000000330C30 00000001DD3F0000 0150:0154:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 00000001DD3F0000: builtin 0150:0154:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 00000001DD3F0000 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"kernel32.dll" in (null) 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=12 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ntdll.dll" in (null) 0150:0154:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=14 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:process_attach (L"ntdll.dll",000000000021FB00) - START 0150:0154:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000021FB00) 0000000170065B80 - CALL 0150:0154:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0150:0154:trace:module:process_attach (L"ntdll.dll",000000000021FB00) - END 0150:0154:trace:module:process_attach (L"kernel32.dll",000000000021FB00) - START 0150:0154:trace:module:process_attach (L"kernelbase.dll",000000000021FB00) - START 0150:0154:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000021FB00) 000000007B03CAD0 - CALL 0150:0154:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x21f618,0x00000008,0x0) 0150:0154:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000021F2A0 85) 0150:0154:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 0150:0154:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000334320 17) 0150:0154:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000339C50, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021EFE8. 0150:0154:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0150:0154:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0150:0154:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0150:0154:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0150:0154:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0150:0154:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0150:0154:trace:module:LoadResource 0000000010000002 00000000100077D8 0150:0154:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 0150:0154:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000334320 17) 0150:0154:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000339C50, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021EFE8. 0150:0154:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0150:0154:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0150:0154:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0150:0154:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0150:0154:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0150:0154:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0150:0154:trace:module:LoadResource 0000000010000002 00000000100077D8 0150:0154:trace:process:CreateProcessInternalW app L"C:\\windows\\system32\\conhost.exe" cmdline L"\"C:\\windows\\system32\\conhost.exe\" --unix --width 80 --height 24 --server 0x34" 0150:0154:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\conhost.exe" image L"C:\\windows\\system32\\conhost.exe" cmdline L"\"C:\\windows\\system32\\conhost.exe\" --unix --width 80 --height 24 --server 0x34" parent 0x0 0150:0154:trace:process:send_to_cx_loader loader (null) wineserversocket 7 stdin_fd 12 stdout_fd 14 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 0150:0154:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0158:015c:trace:module:get_load_order looking for L"C:\\windows\\system32\\conhost.exe" 0158:015c:trace:module:get_load_order got hardcoded default for L"conhost.exe" 0158:015c:trace:module:get_load_order looking for L"C:\\windows\\system32\\conhost.exe" 0158:015c:trace:module:get_load_order got hardcoded default for L"conhost.exe" 0158:015c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\conhost.exe" at 0x140000000-0x14003b000 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .text at 0x140001000 off 1000 size 11000 virt 100d0 flags 60000060 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .data at 0x140012000 off 12000 size 1000 virt f0 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .rdata at 0x140013000 off 13000 size 2000 virt 18f0 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .pdata at 0x140015000 off 15000 size 1000 virt 5f4 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .xdata at 0x140016000 off 16000 size 1000 virt 69c flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .bss at 0x140017000 off 0 size 0 virt 1340 flags c0000080 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .idata at 0x140019000 off 17000 size 2000 virt 199c flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .rsrc at 0x14001b000 off 19000 size 1f000 virt 1eaf0 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .reloc at 0x14003a000 off 38000 size 1000 virt bc flags 42000040 0158:015c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0158:015c:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0150:0154:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\conhost.exe" pid 0158 tid 015c handles 0x44/0x48 0150:0154:trace:process:CreateProcessInternalW started process pid 0158 tid 015c 0150:0154:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0150:0154:trace:module:process_attach (L"kernelbase.dll",000000000021FB00) - END 0150:0154:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000021FB00) 000000007B631530 - CALL 0150:0154:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0150:0154:trace:module:process_attach (L"kernel32.dll",000000000021FB00) - END 0150:0154:trace:module:process_attach (L"advapi32.dll",000000000021FB00) - START 0150:0154:trace:module:process_attach (L"msvcrt.dll",000000000021FB00) - START 0150:0154:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000021FB00) 00000001C8E1AB00 - CALL 0158:015c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 0158:015c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\conhost.exe" 00000000004329C0 0000000140000000 0158:015c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\conhost.exe" at 0000000140000000: builtin 0158:015c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0158:015c:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernel32.dll" 0158:015c:trace:module:get_load_order got hardcoded default for L"kernel32.dll" 0158:015c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0150:0154:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F3B0. 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0150:0154:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0150:0154:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F400. 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0150:0154:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0150:0154:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0150:0154:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0150:0154:trace:module:process_attach (L"msvcrt.dll",000000000021FB00) - END 0150:0154:trace:module:process_attach (L"sechost.dll",000000000021FB00) - START 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0150:0154:trace:module:process_attach (L"ucrtbase.dll",000000000021FB00) - START 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0150:0154:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000021FB00) 00000003AF6F1C30 - CALL 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0158:015c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0150:0154:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F320. 0150:0154:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0150:0154:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F370. 0150:0154:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0150:0154:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0150:0154:trace:module:process_attach (L"ucrtbase.dll",000000000021FB00) - END 0150:0154:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000021FB00) 000000032A716FC0 - CALL 0150:0154:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0150:0154:trace:module:process_attach (L"sechost.dll",000000000021FB00) - END 0150:0154:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000021FB00) 0000000330283EC0 - CALL 0150:0154:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0150:0154:trace:module:process_attach (L"advapi32.dll",000000000021FB00) - END 0150:0154:trace:module:process_attach (L"crypt32.dll",000000000021FB00) - START 0150:0154:trace:module:process_attach (L"bcrypt.dll",000000000021FB00) - START 0150:0154:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_ATTACH,000000000021FB00) 00000002D4D49C40 - CALL 0150:0154:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F570, base 000000000021F568. 0150:0154:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0158:015c:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernelbase.dll" 0158:015c:trace:module:get_load_order got hardcoded default for L"kernelbase.dll" 0158:015c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0158:015c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 00000000004330B0 000000007B000000 0158:015c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 0158:015c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000432DC0 000000007B600000 0158:015c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 0158:015c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 0150:0154:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0150:0154:trace:module:process_attach (L"bcrypt.dll",000000000021FB00) - END 0150:0154:trace:module:process_attach (L"user32.dll",000000000021FB00) - START 0150:0154:trace:module:process_attach (L"gdi32.dll",000000000021FB00) - START 0150:0154:trace:module:process_attach (L"win32u.dll",000000000021FB00) - START 0150:0154:trace:module:MODULE_InitDLL (000000006B360000 L"win32u.dll",PROCESS_ATTACH,000000000021FB00) 000000006B409460 - CALL 0158:015c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0158:015c:trace:module:get_load_order looking for L"C:\\windows\\system32\\advapi32.dll" 0158:015c:trace:module:get_load_order got hardcoded default for L"advapi32.dll" 0158:015c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0158:015c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0158:015c:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvcrt.dll" 0158:015c:trace:module:get_load_order got hardcoded default for L"msvcrt.dll" 0158:015c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0158:015c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 00000000004335C0 00000001C8DB0000 0158:015c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 0158:015c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"sechost.dll" in (null) 0158:015c:trace:module:get_load_order looking for L"C:\\windows\\system32\\sechost.dll" 0158:015c:trace:module:get_load_order got hardcoded default for L"sechost.dll" 0158:015c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0158:015c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0158:015c:trace:module:get_load_order looking for L"C:\\windows\\system32\\ucrtbase.dll" 0158:015c:trace:module:get_load_order got hardcoded default for L"ucrtbase.dll" 0158:015c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0158:015c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 0000000000433BA0 00000003AF670000 0158:015c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 0158:015c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 0000000000433890 000000032A700000 0158:015c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 0158:015c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 00000000004333B0 0000000330260000 0158:015c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 0158:015c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0158:015c:trace:module:get_load_order looking for L"C:\\windows\\system32\\gdi32.dll" 0158:015c:trace:module:get_load_order got hardcoded default for L"gdi32.dll" 0158:015c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 0158:015c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"user32.dll" in (null) 0158:015c:trace:module:get_load_order looking for L"C:\\windows\\system32\\user32.dll" 0158:015c:trace:module:get_load_order got hardcoded default for L"user32.dll" 0158:015c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 0158:015c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"sechost.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"version.dll" in (null) 0158:015c:trace:module:get_load_order looking for L"C:\\windows\\system32\\version.dll" 0158:015c:trace:module:get_load_order got hardcoded default for L"version.dll" 0158:015c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 0158:015c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 0000000000434550 00000002F1FA0000 0158:015c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 00000002F1FA0000: builtin 0158:015c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 00000002F1FA0000 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"win32u.dll" in (null) 0158:015c:trace:module:get_load_order looking for L"C:\\windows\\system32\\win32u.dll" 0158:015c:trace:module:get_load_order got hardcoded default for L"win32u.dll" 0158:015c:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\win32u.dll" is a fake Wine dll 0158:015c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\win32u.dll" 00000000004348A0 000000006AB60000 0158:015c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\win32u.dll" at 000000006AB60000: builtin 0158:015c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\win32u.dll" at 000000006AB60000 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\user32.dll" 0000000000434140 000000023D820000 0158:015c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\user32.dll" at 000000023D820000: builtin 0158:015c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\user32.dll" at 000000023D820000 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"win32u.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AB60000, count=2 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\gdi32.dll" 0000000000433E90 000000026B4C0000 0158:015c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000: builtin 0158:015c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"user32.dll" in (null) 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 0158:015c:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 0158:015c:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0158:015c:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 0158:015c:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 0158:015c:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 0158:015c:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 0158:015c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 0158:015c:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 0158:015c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 0158:015c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000436CD0 17) 0158:015c:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000436DE0, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0158:015c:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0158:015c:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0158:015c:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0158:015c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0158:015c:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0158:015c:trace:module:LoadResource 0000000010000002 00000000100077D8 0158:015c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 0158:015c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000436D20 17) 0158:015c:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000436F00, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0158:015c:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0158:015c:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0158:015c:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0158:015c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0158:015c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0158:015c:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0158:015c:trace:module:LoadResource 0000000010000002 00000000100077D8 0158:015c:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0158:015c:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 0158:015c:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 0158:015c:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0158:015c:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 0158:015c:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 0158:015c:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 0158:015c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 0158:015c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F3B0. 0158:015c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 0158:015c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F400. 0158:015c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 0158:015c:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0158:015c:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0158:015c:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 0158:015c:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 0158:015c:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 0158:015c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 0158:015c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 0158:015c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 0158:015c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 0158:015c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 0158:015c:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0158:015c:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 0158:015c:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 0158:015c:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0158:015c:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 0158:015c:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 0158:015c:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0158:015c:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 0158:015c:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - START 0158:015c:trace:module:process_attach (L"user32.dll",000000000031FB00) - START 0158:015c:trace:module:process_attach (L"version.dll",000000000031FB00) - START 0158:015c:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000031FB00) 00000002F1FA2510 - CALL 0158:015c:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0158:015c:trace:module:process_attach (L"version.dll",000000000031FB00) - END 0158:015c:trace:module:process_attach (L"win32u.dll",000000000031FB00) - START 0158:015c:trace:module:MODULE_InitDLL (000000006AB60000 L"win32u.dll",PROCESS_ATTACH,000000000031FB00) 000000006AC09460 - CALL 0150:0154:trace:module:MODULE_InitDLL (000000006B360000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0150:0154:trace:module:process_attach (L"win32u.dll",000000000021FB00) - END 0150:0154:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000021FB00) 000000026B509F00 - CALL 0150:0154:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0150:0154:trace:module:process_attach (L"gdi32.dll",000000000021FB00) - END 0150:0154:trace:module:process_attach (L"version.dll",000000000021FB00) - START 0150:0154:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000021FB00) 00000002F1FA2510 - CALL 0150:0154:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0150:0154:trace:module:process_attach (L"version.dll",000000000021FB00) - END 0150:0154:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000021FB00) 000000023D8C5690 - CALL 0150:0154:trace:module:load_dll looking for L"imm32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0150:0154:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0150:0154:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0150:0154:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 0150:0154:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 0150:0154:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0150:0154:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0150:0154:trace:module:import_dll is not hybrid module 0150:0154:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 00000000003421F0 00000003AFD00000 0150:0154:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000: builtin 0150:0154:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000 0150:0154:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 0150:0154:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 0150:0154:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021EBB0, base 000000000021EBA8. 0150:0154:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0150:0154:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021F048. 0150:0154:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 0150:0154:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021EB60, base 000000000021EB58. 0150:0154:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0150:0154:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0150:0154:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 0150:0154:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0150:0154:trace:module:process_attach (L"user32.dll",000000000021FB00) - END 0150:0154:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_ATTACH,000000000021FB00) 00000001DD4524D0 - CALL 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0150:0154:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0150:0154:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0150:0154:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F600, base 000000000021F5F8. 0150:0154:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0150:0154:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0150:0154:trace:module:process_attach (L"crypt32.dll",000000000021FB00) - END 0150:0154:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x21f8b8,0x00000008,0x0) 0150:0154:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F080, base 000000000021F078. 0150:0154:trace:module:LdrGetDllHandleEx L"kernel32" -> 000000007B600000 (load path (null)) 0150:0154:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0150:0154:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0158:015c:trace:module:MODULE_InitDLL (000000006AB60000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0158:015c:trace:module:process_attach (L"win32u.dll",000000000031FB00) - END 0158:015c:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000031FB00) 000000023D8C5690 - CALL 0158:015c:trace:module:load_dll looking for L"imm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0158:015c:trace:module:get_load_order looking for L"C:\\windows\\system32\\imm32.dll" 0158:015c:trace:module:get_load_order got hardcoded default for L"imm32.dll" 0158:015c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 0158:015c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 0158:015c:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0158:015c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0158:015c:trace:module:import_dll is not hybrid module 0158:015c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imm32.dll" 000000000043EC40 00000003AFD00000 0158:015c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imm32.dll" at 00000003AFD00000: builtin 0158:015c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imm32.dll" at 00000003AFD00000 0158:015c:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 0158:015c:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 0158:015c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EBB0, base 000000000031EBA8. 0158:015c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0158:015c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031F048. 0158:015c:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 0158:015c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EB60, base 000000000031EB58. 0158:015c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0158:015c:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0158:015c:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 0158:015c:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0158:015c:trace:module:process_attach (L"user32.dll",000000000031FB00) - END 0158:015c:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000031FB00) 000000026B509F00 - CALL 0158:015c:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0158:015c:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - END 0158:015c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 0158:015c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FA50, base 000000000031FA48. 0158:015c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0158:015c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F5E0, base 000000000031F5D8. 0158:015c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0150:0154:trace:process:CreateProcessInternalW app (null) cmdline L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe mscoree.dll,wine_install_mono" 0150:0154:trace:process:find_exe_file looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;.;C:\\windows\\system32;C:\\windows\\system;C:\\windows;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0150:0154:trace:process:NtCreateUserProcess L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" image L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" cmdline L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe mscoree.dll,wine_install_mono" parent 0x0 0150:0154:trace:process:send_to_cx_loader loader (null) wineserversocket 10 stdin_fd 0 stdout_fd 1 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 0150:0154:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0160:0164:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0160:0164:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" at 0x140000000-0x14000a000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" section .text at 0x140001000 off 1000 size 2000 virt 1bb0 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" section .data at 0x140003000 off 3000 size 1000 virt 40 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" section .rdata at 0x140004000 off 4000 size 1000 virt 250 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" section .pdata at 0x140005000 off 5000 size 1000 virt d8 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" section .xdata at 0x140006000 off 6000 size 1000 virt e8 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" section .bss at 0x140007000 off 0 size 0 virt 140 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" section .idata at 0x140008000 off 7000 size 1000 virt 764 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" section .reloc at 0x140009000 off 8000 size 1000 virt 14 flags 42000040 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0160:0164:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0150:0154:trace:process:NtCreateUserProcess L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" pid 0160 tid 0164 handles 0x74/0x78 0150:0154:trace:process:CreateProcessInternalW started process pid 0160 tid 0164 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0000000000432CF0 0000000140000000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" at 0000000140000000: builtin 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in (null) 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0160:0164:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in (null) 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 00000000004335A0 000000007B000000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in (null) 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0000000000433130 000000007B600000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in (null) 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in (null) 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0000000000433700 00000003AF670000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in (null) 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in (null) 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in (null) 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0000000000434400 00000001C8DB0000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in (null) 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"sechost.dll" in (null) 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in (null) 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0000000000434870 000000032A700000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0000000000433F90 0000000330260000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"gdi32.dll" in (null) 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in (null) 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"win32u.dll" in (null) 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0160:0164:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" is a fake Wine dll 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in (null) 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0000000000434DD0 000000006A460000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006A460000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006A460000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0000000000434AE0 000000026B4C0000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in (null) 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"sechost.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"version.dll" in (null) 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in (null) 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0000000000435240 00000002F1FA0000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"win32u.dll" in (null) 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" for L"win32u.dll" at 000000006A460000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0000000000433B20 000000023D820000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 0160:0164:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 0160:0164:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0160:0164:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 0160:0164:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 0160:0164:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 0160:0164:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 0160:0164:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 0160:0164:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 0160:0164:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000433DB0 17) 0160:0164:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000437620, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0160:0164:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0160:0164:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0160:0164:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0160:0164:trace:module:LoadResource 0000000010000002 00000000100077D8 0160:0164:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 0160:0164:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000433DB0 17) 0160:0164:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000004376E0, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0160:0164:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0160:0164:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0160:0164:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0160:0164:trace:module:LoadResource 0000000010000002 00000000100077D8 0160:0164:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0160:0164:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 0160:0164:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 0160:0164:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0160:0164:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 0160:0164:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 0160:0164:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 0160:0164:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F440. 0160:0164:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0160:0164:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F490. 0160:0164:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0160:0164:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0160:0164:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 0160:0164:trace:module:process_attach (L"user32.dll",000000000031FB00) - START 0160:0164:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 0160:0164:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 0160:0164:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 0160:0164:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 0160:0164:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0160:0164:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 0160:0164:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0160:0164:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0160:0164:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0160:0164:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 0160:0164:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 0160:0164:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 0160:0164:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0160:0164:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 0160:0164:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 0160:0164:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0160:0164:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 0160:0164:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - START 0160:0164:trace:module:process_attach (L"win32u.dll",000000000031FB00) - START 0160:0164:trace:module:MODULE_InitDLL (000000006A460000 L"win32u.dll",PROCESS_ATTACH,000000000031FB00) 000000006A509460 - CALL 0160:0164:trace:module:MODULE_InitDLL (000000006A460000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0160:0164:trace:module:process_attach (L"win32u.dll",000000000031FB00) - END 0160:0164:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000031FB00) 000000026B509F00 - CALL 0160:0164:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0160:0164:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - END 0160:0164:trace:module:process_attach (L"version.dll",000000000031FB00) - START 0160:0164:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000031FB00) 00000002F1FA2510 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0160:0164:trace:module:process_attach (L"version.dll",000000000031FB00) - END 0160:0164:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000031FB00) 000000023D8C5690 - CALL 0160:0164:trace:module:load_dll looking for L"imm32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0000000000442CD0 00000003AFD00000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000 0160:0164:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EC40, base 000000000031EC38. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F0E0, base 000000000031F0D8. 0160:0164:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EBF0, base 000000000031EBE8. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 0160:0164:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0160:0164:trace:module:process_attach (L"user32.dll",000000000031FB00) - END 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F620, base 000000000031F618. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:load_dll looking for L"winemac.drv" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" 0160:0164:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" is a fake Wine dll 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"gdi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"win32u.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" for L"win32u.dll" at 000000006A460000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" 00000000004431B0 000000006CD10000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" at 000000006CD10000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" at 000000006CD10000 0160:0164:trace:module:process_attach (L"winemac.drv",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (000000006CD10000 L"winemac.drv",PROCESS_ATTACH,0000000000000000) 000000006CD28C10 - CALL 0160:0164:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031BA60. 0160:0164:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0160:0164:trace:module:FindResourceExW 000000006CD10000 #0006 #0011 0000 0160:0164:trace:module:LoadResource 000000006CD10000 000000006CD8E9D8 0160:0164:trace:module:FindResourceExW 000000006CD10000 #0006 #0011 0000 0160:0164:trace:module:LoadResource 000000006CD10000 000000006CD8E9D8 0160:0164:trace:module:FindResourceExW 000000006CD10000 #0006 #0011 0000 0160:0164:trace:module:LoadResource 000000006CD10000 000000006CD8E9D8 0160:0164:trace:module:FindResourceExW 000000006CD10000 #0006 #0011 0000 0160:0164:trace:module:LoadResource 000000006CD10000 000000006CD8E9D8 0160:0164:trace:module:FindResourceExW 000000006CD10000 #0006 #0011 0000 0160:0164:trace:module:LoadResource 000000006CD10000 000000006CD8E9D8 0160:0164:trace:module:FindResourceExW 000000006CD10000 #0006 #0011 0000 0160:0164:trace:module:LoadResource 000000006CD10000 000000006CD8E9D8 0160:0164:trace:module:FindResourceExW 000000006CD10000 #0006 #0011 0000 0160:0164:trace:module:LoadResource 000000006CD10000 000000006CD8E9D8 0160:0164:trace:module:FindResourceExW 000000006CD10000 #0006 #0012 0000 0160:0164:trace:module:LoadResource 000000006CD10000 000000006CD8EBC8 0160:0164:trace:module:FindResourceExW 000000006CD10000 #0006 #0012 0000 0160:0164:trace:module:LoadResource 000000006CD10000 000000006CD8EBC8 0160:0164:trace:module:FindResourceExW 000000006CD10000 #0006 #0012 0000 0160:0164:trace:module:LoadResource 000000006CD10000 000000006CD8EBC8 0160:0164:trace:module:FindResourceExW 000000006CD10000 #0006 #0012 0000 0160:0164:trace:module:LoadResource 000000006CD10000 000000006CD8EBC8 0160:0164:trace:module:FindResourceExW 000000006CD10000 #0006 #0012 0000 0160:0164:trace:module:LoadResource 000000006CD10000 000000006CD8EBC8 0160:0164:trace:module:MODULE_InitDLL (000000006CD10000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"winemac.drv",0000000000000000) - END 0160:0164:trace:module:EnumResourceNamesExW 0000000000000000 #000e 000000006CD1FB00 31d2f8 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0160:0164:trace:module:LoadResource 000000023D820000 000000023D908880 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C310, base 000000000031C308. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C760. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f01 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4C0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0009 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0160:0164:trace:module:LoadResource 000000023D820000 000000023D9088E0 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C760. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031CB20. 0160:0164:trace:module:load_dll looking for L"uxtheme.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"C:\\windows\\system32\\uxtheme.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"uxtheme.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 0x2f7230000-0x2f7265000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .text at 0x2f7231000 off 1000 size 13000 virt 123c0 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .data at 0x2f7244000 off 14000 size 1000 virt 110 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rodata at 0x2f7245000 off 15000 size 1000 virt 430 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rdata at 0x2f7246000 off 16000 size 16000 virt 15a30 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .pdata at 0x2f725c000 off 2c000 size 1000 virt 87c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .xdata at 0x2f725d000 off 2d000 size 1000 virt 97c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .bss at 0x2f725e000 off 0 size 0 virt 4a0 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .edata at 0x2f725f000 off 2e000 size 2000 virt 1de0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .idata at 0x2f7261000 off 30000 size 2000 virt 14ac flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rsrc at 0x2f7263000 off 32000 size 1000 virt 5f8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .reloc at 0x2f7264000 off 33000 size 1000 virt bc flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"gdi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\uxtheme.dll" 0000000000443590 00000002F7230000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\uxtheme.dll" at 00000002F7230000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\uxtheme.dll" at 00000002F7230000 0160:0164:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_ATTACH,0000000000000000) 00000002F72424B0 - CALL 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C950, base 000000000031C948. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031CB00, base 000000000031CAF8. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000443A00, dll_characteristics 0000000000000000, name 000000000031CD20, base 000000000031CCB8. 0160:0164:trace:module:LdrGetDllHandleEx L"C:\\windows\\resources\\themes\\light\\light.msstyles" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0160:0164:trace:module:FindResourceExW 0000000000F10001 L"PACKTHEM_VERSION" #0001 0000 0160:0164:trace:module:LoadResource 0000000000F10001 0000000000F15310 0160:0164:trace:module:FindResourceExW 0000000000F10001 L"COLORNAMES" #0001 0000 0160:0164:trace:module:LoadResource 0000000000F10001 0000000000F152F0 0160:0164:trace:module:FindResourceExW 0000000000F10001 L"SIZENAMES" #0001 0000 0160:0164:trace:module:LoadResource 0000000000F10001 0000000000F15320 0160:0164:trace:module:FindResourceExW 0000000000F10001 L"FILERESNAMES" #0001 0000 0160:0164:trace:module:LoadResource 0000000000F10001 0000000000F15300 0160:0164:trace:module:FindResourceExW 0000000000F10001 L"TEXTFILE" L"BLUE_INI" 0000 0160:0164:trace:module:LoadResource 0000000000F10001 0000000000F15330 0160:0164:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - END 0160:0164:trace:module:load_dll looking for L"winemac.drv" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" for L"winemac.drv" at 000000006CD10000, count=2 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031F280. 0160:0164:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F240. 0160:0164:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" 0160:0164:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000442AB0, dll_characteristics 0000000000000000, name 000000000031F1A0, base 000000000031F138. 0160:0164:trace:module:LdrAddRefDll (L"rundll32.exe") ldr.LoadCount: -1 0160:0164:trace:module:LdrGetDllHandleEx L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rundll32.exe" -> 0000000140000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0160:0164:trace:module:FindResourceExW 0000000140000000 #0010 #0001 0000 0160:0164:trace:module:LdrUnloadDll (0000000140000000) 0160:0164:trace:module:LdrUnloadDll (L"rundll32.exe") - START 0160:0164:trace:module:LdrUnloadDll END 0160:0164:trace:module:FindResourceExW 000000023D820000 #0004 L"SYSMENU" 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D909940 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EAA0, base 000000000031EA98. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F630, base 000000000031F628. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F320, base 000000000031F318. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:CreateActCtxW 000000000031F910 00000008 0160:0164:trace:module:load_dll looking for L"mscoree.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" at 0x356770000-0x3567aa000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .text at 0x356771000 off 1000 size 14000 virt 13c10 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .data at 0x356785000 off 15000 size 1000 virt 2c0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .rodata at 0x356786000 off 16000 size 1000 virt 820 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .rdata at 0x356787000 off 17000 size c000 virt bbc0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .pdata at 0x356793000 off 23000 size 1000 virt f30 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .xdata at 0x356794000 off 24000 size 1000 virt e3c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .bss at 0x356795000 off 0 size 0 virt 330 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .edata at 0x356796000 off 25000 size 10000 virt ff5a flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .idata at 0x3567a6000 off 35000 size 2000 virt 1018 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .rsrc at 0x3567a8000 off 37000 size 1000 virt e78 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .reloc at 0x3567a9000 off 38000 size 1000 virt 238 flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"dbghelp.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" at 0x3be590000-0x3be604000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .text at 0x3be591000 off 1000 size 4d000 virt 4c1d0 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .data at 0x3be5de000 off 4e000 size 1000 virt 460 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .rodata at 0x3be5df000 off 4f000 size 1000 virt 89c flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .rdata at 0x3be5e0000 off 50000 size d000 virt ccb0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .pdata at 0x3be5ed000 off 5d000 size 2000 virt 1db8 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .xdata at 0x3be5ef000 off 5f000 size 3000 virt 232c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .bss at 0x3be5f2000 off 0 size 0 virt 8ea0 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .edata at 0x3be5fb000 off 62000 size 5000 virt 430d flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .idata at 0x3be600000 off 67000 size 2000 virt 1050 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .rsrc at 0x3be602000 off 69000 size 1000 virt 3c0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .reloc at 0x3be603000 off 6a000 size 1000 virt 144 flags 42000040 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" 0000000000473620 00000003BE590000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" at 00000003BE590000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" at 00000003BE590000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ole32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" 0160:0164:trace:module:get_load_order_value got standard key b for L"ole32" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" at 0x2e8f10000-0x2e902b000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .text at 0x2e8f11000 off 1000 size a8000 virt a76a0 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .data at 0x2e8fb9000 off a9000 size 1000 virt 480 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rodata at 0x2e8fba000 off aa000 size 1000 virt 778 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rdata at 0x2e8fbb000 off ab000 size 1e000 virt 1d750 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .pdata at 0x2e8fd9000 off c9000 size 7000 virt 6b10 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .xdata at 0x2e8fe0000 off d0000 size 7000 virt 67c4 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .bss at 0x2e8fe7000 off 0 size 0 virt 210 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .edata at 0x2e8fe8000 off d7000 size 18000 virt 17412 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .idata at 0x2e9000000 off ef000 size 4000 virt 367c flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rsrc at 0x2e9004000 off f3000 size 25000 virt 24bc0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .reloc at 0x2e9029000 off 118000 size 2000 virt 1804 flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"combase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" at 0x327020000-0x327073000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .text at 0x327021000 off 1000 size 27000 virt 26590 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .data at 0x327048000 off 28000 size 1000 virt 580 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rodata at 0x327049000 off 29000 size 2000 virt 16c0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rdata at 0x32704b000 off 2b000 size d000 virt cf90 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .pdata at 0x327058000 off 38000 size 2000 virt 17a0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .xdata at 0x32705a000 off 3a000 size 2000 virt 18e4 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .bss at 0x32705c000 off 0 size 0 virt 1a0 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .edata at 0x32705d000 off 3c000 size 13000 virt 12d6e flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .idata at 0x327070000 off 4f000 size 2000 virt 1804 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .reloc at 0x327072000 off 51000 size 1000 virt 23c flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"gdi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ole32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"rpcrt4.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" 0160:0164:trace:module:get_load_order_value got standard key b for L"rpcrt4" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0x231ae0000-0x231b62000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .text at 0x231ae1000 off 1000 size 47000 virt 46400 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .data at 0x231b28000 off 48000 size 1000 virt 710 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rodata at 0x231b29000 off 49000 size 2000 virt 1b44 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rdata at 0x231b2b000 off 4b000 size 15000 virt 14b90 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .pdata at 0x231b40000 off 60000 size 3000 virt 2334 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .xdata at 0x231b43000 off 63000 size 3000 virt 289c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .bss at 0x231b46000 off 0 size 0 virt 690 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .edata at 0x231b47000 off 66000 size 17000 virt 16730 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .idata at 0x231b5e000 off 7d000 size 2000 virt 19a8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rsrc at 0x231b60000 off 7f000 size 1000 virt 3a8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .reloc at 0x231b61000 off 80000 size 1000 virt 504 flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" 0000000000474260 0000000231AE0000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0000000231AE0000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0000000231AE0000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" 0000000000473D70 0000000327020000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" at 0000000327020000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" at 0000000327020000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"gdi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernelbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"rpcrt4.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" 0000000000473A90 00000002E8F10000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" at 00000002E8F10000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" at 00000002E8F10000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"shell32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" at 0x1c69e0000-0x1c72fe000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .text at 0x1c69e1000 off 1000 size 89000 virt 88c60 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .data at 0x1c6a6a000 off 8a000 size 2000 virt 13e0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rodata at 0x1c6a6c000 off 8c000 size 2000 virt 18ec flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rdata at 0x1c6a6e000 off 8e000 size 29000 virt 28e90 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .pdata at 0x1c6a97000 off b7000 size 6000 virt 5748 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .xdata at 0x1c6a9d000 off bd000 size 6000 virt 5c20 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .bss at 0x1c6aa3000 off 0 size 0 virt 570 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .edata at 0x1c6aa4000 off c3000 size 15000 virt 14070 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .idata at 0x1c6ab9000 off d8000 size 5000 virt 4aa0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rsrc at 0x1c6abe000 off dd000 size 83e000 virt 83d918 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .reloc at 0x1c72fc000 off 91b000 size 2000 virt 1264 flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"gdi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"shlwapi.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" at 0x2e3540000-0x2e3591000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .text at 0x2e3541000 off 1000 size 1e000 virt 1dac0 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .data at 0x2e355f000 off 1f000 size 1000 virt 210 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rodata at 0x2e3560000 off 20000 size 2000 virt 18fc flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rdata at 0x2e3562000 off 22000 size b000 virt a290 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .pdata at 0x2e356d000 off 2d000 size 2000 virt 11b8 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .xdata at 0x2e356f000 off 2f000 size 2000 virt 13a8 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .bss at 0x2e3571000 off 0 size 0 virt 1c0 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .edata at 0x2e3572000 off 31000 size 14000 virt 13ab5 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .idata at 0x2e3586000 off 45000 size 5000 virt 442c flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rsrc at 0x2e358b000 off 4a000 size 5000 virt 4ed0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .reloc at 0x2e3590000 off 4f000 size 1000 virt e0 flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"gdi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernelbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"shcore.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" at 0x3126f0000-0x312709000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .text at 0x3126f1000 off 1000 size 9000 virt 8b70 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .data at 0x3126fa000 off a000 size 1000 virt b0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rodata at 0x3126fb000 off b000 size 1000 virt fb4 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rdata at 0x3126fc000 off c000 size 3000 virt 2360 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .pdata at 0x3126ff000 off f000 size 1000 virt 57c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .xdata at 0x312700000 off 10000 size 1000 virt 61c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .bss at 0x312701000 off 0 size 0 virt 160 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .edata at 0x312702000 off 11000 size 5000 virt 480e flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .idata at 0x312707000 off 16000 size 1000 virt c74 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .reloc at 0x312708000 off 17000 size 1000 virt a8 flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ole32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" 0000000000475030 00000003126F0000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" at 00000003126F0000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" at 00000003126F0000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" 0000000000474BC0 00000002E3540000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" at 00000002E3540000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" at 00000002E3540000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" 0000000000474750 00000001C69E0000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" at 00000001C69E0000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" at 00000001C69E0000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"shlwapi.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" 00000000004731B0 0000000356770000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" at 0000000356770000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" at 0000000356770000 0160:0164:trace:module:process_attach (L"mscoree.dll",0000000000000000) - START 0160:0164:trace:module:process_attach (L"dbghelp.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (00000003BE590000 L"dbghelp.dll",PROCESS_ATTACH,0000000000000000) 00000003BE5DC0A0 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000003BE590000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"dbghelp.dll",0000000000000000) - END 0160:0164:trace:module:process_attach (L"ole32.dll",0000000000000000) - START 0160:0164:trace:module:process_attach (L"combase.dll",0000000000000000) - START 0160:0164:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_ATTACH,0000000000000000) 0000000231B26040 - CALL 0160:0164:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - END 0160:0164:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_ATTACH,0000000000000000) 00000003270465C0 - CALL 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031ECF0, base 000000000031ECE8. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"combase.dll",0000000000000000) - END 0160:0164:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_ATTACH,0000000000000000) 00000002E8FB74E0 - CALL 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EDA0, base 000000000031ED98. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"ole32.dll",0000000000000000) - END 0160:0164:trace:module:process_attach (L"shell32.dll",0000000000000000) - START 0160:0164:trace:module:process_attach (L"shlwapi.dll",0000000000000000) - START 0160:0164:trace:module:process_attach (L"shcore.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_ATTACH,0000000000000000) 00000003126F8FD0 - CALL 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EC80, base 000000000031EC78. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"shcore.dll",0000000000000000) - END 0160:0164:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_ATTACH,0000000000000000) 00000002E355DE00 - CALL 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031ED10, base 000000000031ED08. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"shlwapi.dll",0000000000000000) - END 0160:0164:trace:module:MODULE_InitDLL (00000001C69E0000 L"shell32.dll",PROCESS_ATTACH,0000000000000000) 00000001C6A688D0 - CALL 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EDA0, base 000000000031ED98. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:LdrGetDllFullName module 00000001C69E0000, name 000000000031F2C0. 0160:0164:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" 0160:0164:trace:module:MODULE_InitDLL (00000001C69E0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"shell32.dll",0000000000000000) - END 0160:0164:trace:module:MODULE_InitDLL (0000000356770000 L"mscoree.dll",PROCESS_ATTACH,0000000000000000) 0000000356783CA0 - CALL 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EE30, base 000000000031EE28. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:MODULE_InitDLL (0000000356770000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"mscoree.dll",0000000000000000) - END 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f7c8,0x00000008,0x0) 0160:0164:trace:module:load_dll looking for L"msi.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" 0160:0164:trace:module:get_load_order_value got standard key b for L"msi" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" at 0x1f3bb0000-0x1f3cfe000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .text at 0x1f3bb1000 off 1000 size b2000 virt b1210 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .data at 0x1f3c63000 off b3000 size 1000 virt 710 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .rodata at 0x1f3c64000 off b4000 size 1000 virt 908 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .rdata at 0x1f3c65000 off b5000 size 24000 virt 23970 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .pdata at 0x1f3c89000 off d9000 size 5000 virt 46ec flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .xdata at 0x1f3c8e000 off de000 size 6000 virt 59b0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .bss at 0x1f3c94000 off 0 size 0 virt 290 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .edata at 0x1f3c95000 off e4000 size 16000 virt 150f2 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .idata at 0x1f3cab000 off fa000 size 4000 virt 3758 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .rsrc at 0x1f3caf000 off fe000 size 4e000 virt 4d508 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .reloc at 0x1f3cfd000 off 14c000 size 1000 virt 604 flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"cabinet.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" at 0x1dc080000-0x1dc09e000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .text at 0x1dc081000 off 1000 size 12000 virt 115d0 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .data at 0x1dc093000 off 13000 size 1000 virt 90 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .rodata at 0x1dc094000 off 14000 size 1000 virt a4 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .rdata at 0x1dc095000 off 15000 size 2000 virt 1c10 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .pdata at 0x1dc097000 off 17000 size 1000 virt 5b8 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .xdata at 0x1dc098000 off 18000 size 1000 virt 628 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .bss at 0x1dc099000 off 0 size 0 virt 140 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .edata at 0x1dc09a000 off 19000 size 1000 virt 76a flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .idata at 0x1dc09b000 off 1a000 size 1000 virt 5e8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .rsrc at 0x1dc09c000 off 1b000 size 1000 virt 3a8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .reloc at 0x1dc09d000 off 1c000 size 1000 virt 64 flags 42000040 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" 0000000000475870 00000001DC080000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" at 00000001DC080000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" at 00000001DC080000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"comctl32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" at 0x2bb750000-0x2bb88f000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .text at 0x2bb751000 off 1000 size ae000 virt ad9d0 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .data at 0x2bb7ff000 off af000 size 1000 virt 300 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .rodata at 0x2bb800000 off b0000 size 1000 virt 734 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .rdata at 0x2bb801000 off b1000 size 1f000 virt 1ef80 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .pdata at 0x2bb820000 off d0000 size 4000 virt 3198 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .xdata at 0x2bb824000 off d4000 size 5000 virt 40a8 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .bss at 0x2bb829000 off 0 size 0 virt 1720 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .edata at 0x2bb82b000 off d9000 size f000 virt eff3 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .idata at 0x2bb83a000 off e8000 size 4000 virt 3b2c flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .rsrc at 0x2bb83e000 off ec000 size 50000 virt 4fad8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .reloc at 0x2bb88e000 off 13c000 size 1000 virt 1d4 flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"gdi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"imm32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" for L"imm32.dll" at 00000003AFD00000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernelbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" 0000000000475CE0 00000002BB750000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" at 00000002BB750000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" at 00000002BB750000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"crypt32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" 0160:0164:trace:module:get_load_order_value got standard key n,b for L"crypt32" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 0x1dd3f0000-0x1dd4be000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .text at 0x1dd3f1000 off 1000 size 63000 virt 62550 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .data at 0x1dd454000 off 64000 size 3000 virt 2640 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rodata at 0x1dd457000 off 67000 size 1000 virt 74c flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rdata at 0x1dd458000 off 68000 size 12000 virt 11830 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .pdata at 0x1dd46a000 off 7a000 size 3000 virt 2958 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .xdata at 0x1dd46d000 off 7d000 size 4000 virt 3260 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .bss at 0x1dd471000 off 0 size 0 virt 32d0 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .edata at 0x1dd475000 off 81000 size 5000 virt 4c9c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .idata at 0x1dd47a000 off 86000 size 2000 virt 1650 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rsrc at 0x1dd47c000 off 88000 size 41000 virt 40f48 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .reloc at 0x1dd4bd000 off c9000 size 1000 virt 514 flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"bcrypt.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 0x2d4d40000-0x2d4d57000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .text at 0x2d4d41000 off 1000 size a000 virt 97c0 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .data at 0x2d4d4b000 off b000 size 1000 virt 70 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rodata at 0x2d4d4c000 off c000 size 1000 virt 3b8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rdata at 0x2d4d4d000 off d000 size 2000 virt 1c40 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .pdata at 0x2d4d4f000 off f000 size 1000 virt 420 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .xdata at 0x2d4d50000 off 10000 size 1000 virt 52c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .bss at 0x2d4d51000 off 0 size 0 virt 170 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .edata at 0x2d4d52000 off 11000 size 2000 virt 1317 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .idata at 0x2d4d54000 off 13000 size 1000 virt 6cc flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rsrc at 0x2d4d55000 off 14000 size 1000 virt 3c0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .reloc at 0x2d4d56000 off 15000 size 1000 virt 44 flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 0000000000476640 00000002D4D40000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 00000002D4D40000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 00000002D4D40000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" 00000000004761D0 00000001DD3F0000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 00000001DD3F0000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 00000001DD3F0000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"gdi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"imagehlp.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" at 0x2bc640000-0x2bc650000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .text at 0x2bc641000 off 1000 size 5000 virt 40d0 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .data at 0x2bc646000 off 6000 size 1000 virt a0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .rodata at 0x2bc647000 off 7000 size 1000 virt 2ac flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .rdata at 0x2bc648000 off 8000 size 1000 virt 980 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .pdata at 0x2bc649000 off 9000 size 1000 virt 264 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .xdata at 0x2bc64a000 off a000 size 1000 virt 2f0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .bss at 0x2bc64b000 off 0 size 0 virt 140 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .edata at 0x2bc64c000 off b000 size 2000 virt 195b flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .idata at 0x2bc64e000 off d000 size 1000 virt 6d0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .reloc at 0x2bc64f000 off e000 size 1000 virt 24 flags 42000040 0160:0164:trace:module:load_dll looking for L"dbghelp.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" for L"dbghelp.dll" at 00000003BE590000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" 0000000000476AB0 00000002BC640000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" at 00000002BC640000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" at 00000002BC640000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"mspatcha.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" at 0x30fbd0000-0x30fbe1000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .text at 0x30fbd1000 off 1000 size 6000 virt 51c0 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .data at 0x30fbd7000 off 7000 size 1000 virt 90 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .rodata at 0x30fbd8000 off 8000 size 1000 virt 7c flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .rdata at 0x30fbd9000 off 9000 size 1000 virt aa0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .pdata at 0x30fbda000 off a000 size 1000 virt 270 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .xdata at 0x30fbdb000 off b000 size 1000 virt 288 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .bss at 0x30fbdc000 off 0 size 0 virt 140 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .edata at 0x30fbdd000 off c000 size 1000 virt 613 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .idata at 0x30fbde000 off d000 size 1000 virt 650 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .rsrc at 0x30fbdf000 off e000 size 1000 virt 3c8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .reloc at 0x30fbe0000 off f000 size 1000 virt 20 flags 42000040 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" 0000000000476DD0 000000030FBD0000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" at 000000030FBD0000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" at 000000030FBD0000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"odbccp32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" 0160:0164:trace:module:get_load_order_value got standard key n,b for L"odbccp32" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" at 0x381900000-0x381913000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .text at 0x381901000 off 1000 size 8000 virt 7180 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .data at 0x381909000 off 9000 size 1000 virt 80 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .rodata at 0x38190a000 off a000 size 1000 virt 4a8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .rdata at 0x38190b000 off b000 size 1000 virt fe0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .pdata at 0x38190c000 off c000 size 1000 virt 3a8 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .xdata at 0x38190d000 off d000 size 1000 virt 498 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .bss at 0x38190e000 off 0 size 0 virt 1e0 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .edata at 0x38190f000 off e000 size 2000 virt 117c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .idata at 0x381911000 off 10000 size 1000 virt 784 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .reloc at 0x381912000 off 11000 size 1000 virt 20 flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" 00000000004791D0 0000000381900000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" at 0000000381900000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" at 0000000381900000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ole32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=3 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"oleaut32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" 0160:0164:trace:module:get_load_order_value got standard key b for L"oleaut32" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" at 0x2739c0000-0x273af6000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .text at 0x2739c1000 off 1000 size ab000 virt aa720 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .data at 0x273a6c000 off ac000 size 2000 virt 1100 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rodata at 0x273a6e000 off ae000 size 1000 virt 984 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rdata at 0x273a6f000 off af000 size 1f000 virt 1e700 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .pdata at 0x273a8e000 off ce000 size 6000 virt 57e4 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .xdata at 0x273a94000 off d4000 size 6000 virt 50e4 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .bss at 0x273a9a000 off 0 size 0 virt 38230 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .edata at 0x273ad3000 off da000 size 19000 virt 18c59 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .idata at 0x273aec000 off f3000 size 3000 virt 2aa0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rsrc at 0x273aef000 off f6000 size 5000 virt 4ee0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .reloc at 0x273af4000 off fb000 size 2000 virt 14e4 flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"gdi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ole32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=4 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"rpcrt4.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=3 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" 00000000004794C0 00000002739C0000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" at 00000002739C0000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" at 00000002739C0000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"rpcrt4.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=4 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"shell32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"shlwapi.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=3 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"sxs.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" at 0x3543d0000-0x3543e2000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .text at 0x3543d1000 off 1000 size 5000 virt 4a80 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .data at 0x3543d6000 off 6000 size 1000 virt 90 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .rodata at 0x3543d7000 off 7000 size 1000 virt 1c flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .rdata at 0x3543d8000 off 8000 size 2000 virt 1cc0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .pdata at 0x3543da000 off a000 size 1000 virt 2d0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .xdata at 0x3543db000 off b000 size 1000 virt 340 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .bss at 0x3543dc000 off 0 size 0 virt 140 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .edata at 0x3543dd000 off c000 size 3000 virt 201f flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .idata at 0x3543e0000 off f000 size 1000 virt 878 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .reloc at 0x3543e1000 off 10000 size 1000 virt 54 flags 42000040 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ole32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=5 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"oleaut32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" for L"oleaut32.dll" at 00000002739C0000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" 00000000004799F0 00000003543D0000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" at 00000003543D0000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" at 00000003543D0000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"urlmon.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" 0160:0164:trace:module:get_load_order_value got standard key n,b for L"urlmon" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" at 0x3422e0000-0x34237c000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .text at 0x3422e1000 off 1000 size 55000 virt 54af0 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .data at 0x342336000 off 56000 size 1000 virt 760 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .rodata at 0x342337000 off 57000 size 1000 virt 948 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .rdata at 0x342338000 off 58000 size 17000 virt 164e0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .pdata at 0x34234f000 off 6f000 size 4000 virt 34ec flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .xdata at 0x342353000 off 73000 size 4000 virt 3484 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .bss at 0x342357000 off 0 size 0 virt 1f0 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .edata at 0x342358000 off 77000 size 11000 virt 1037c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .idata at 0x342369000 off 88000 size 3000 virt 27ec flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .rsrc at 0x34236c000 off 8b000 size f000 virt e468 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .reloc at 0x34237b000 off 9a000 size 1000 virt acc flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ole32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=6 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"oleaut32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" for L"oleaut32.dll" at 00000002739C0000, count=3 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"rpcrt4.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=5 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"shell32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=3 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"shlwapi.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=4 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"wininet.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" 0160:0164:trace:module:get_load_order_value got standard key b for L"wininet" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" at 0x3a0440000-0x3a04c3000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .text at 0x3a0441000 off 1000 size 47000 virt 46520 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .data at 0x3a0488000 off 48000 size 1000 virt 450 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .rodata at 0x3a0489000 off 49000 size 1000 virt 854 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .rdata at 0x3a048a000 off 4a000 size c000 virt b330 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .pdata at 0x3a0496000 off 56000 size 2000 virt 19b0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .xdata at 0x3a0498000 off 58000 size 2000 virt 1ebc flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .bss at 0x3a049a000 off 0 size 0 virt 1e0 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .edata at 0x3a049b000 off 5a000 size 5000 virt 49b6 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .idata at 0x3a04a0000 off 5f000 size 2000 virt 1ec8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .rsrc at 0x3a04a2000 off 61000 size 20000 virt 1f3e8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .reloc at 0x3a04c2000 off 81000 size 1000 virt 300 flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"mpr.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" at 0x24f470000-0x24f48f000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .text at 0x24f471000 off 1000 size b000 virt a4a0 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .data at 0x24f47c000 off c000 size 1000 virt c0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .rodata at 0x24f47d000 off d000 size 1000 virt 31c flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .rdata at 0x24f47e000 off e000 size 2000 virt 14a0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .pdata at 0x24f480000 off 10000 size 1000 virt 654 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .xdata at 0x24f481000 off 11000 size 1000 virt 6d4 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .bss at 0x24f482000 off 0 size 0 virt 160 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .edata at 0x24f483000 off 12000 size 2000 virt 19e3 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .idata at 0x24f485000 off 14000 size 1000 virt a00 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .rsrc at 0x24f486000 off 15000 size 8000 virt 77c0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .reloc at 0x24f48e000 off 1d000 size 1000 virt 20 flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" 000000000047A8D0 000000024F470000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" at 000000024F470000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" at 000000024F470000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"shell32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=4 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"shlwapi.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=5 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ws2_32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" at 0x1ec2b0000-0x1ec2d6000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .text at 0x1ec2b1000 off 1000 size 13000 virt 12500 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .data at 0x1ec2c4000 off 14000 size 1000 virt 1b0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rodata at 0x1ec2c5000 off 15000 size 1000 virt 85c flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rdata at 0x1ec2c6000 off 16000 size 5000 virt 4990 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .pdata at 0x1ec2cb000 off 1b000 size 1000 virt 954 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .xdata at 0x1ec2cc000 off 1c000 size 1000 virt a3c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .bss at 0x1ec2cd000 off 0 size 0 virt 170 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .edata at 0x1ec2ce000 off 1d000 size 3000 virt 23c6 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .idata at 0x1ec2d1000 off 20000 size 1000 virt c14 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rsrc at 0x1ec2d2000 off 21000 size 3000 virt 29b8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .reloc at 0x1ec2d5000 off 24000 size 1000 virt 70 flags 42000040 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" 000000000047ADD0 00000001EC2B0000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" at 00000001EC2B0000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" at 00000001EC2B0000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" 000000000047A460 00000003A0440000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" at 00000003A0440000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" at 00000003A0440000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" 0000000000479EB0 00000003422E0000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" at 00000003422E0000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" at 00000003422E0000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"version.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" for L"version.dll" at 00000002F1FA0000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"wininet.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" for L"wininet.dll" at 00000003A0440000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"wintrust.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" 0160:0164:trace:module:get_load_order_value got standard key n,b for L"wintrust" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" at 0x1fdfd0000-0x1fdff8000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .text at 0x1fdfd1000 off 1000 size 17000 virt 16330 flags 60000060 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .data at 0x1fdfe8000 off 18000 size 1000 virt 410 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .rodata at 0x1fdfe9000 off 19000 size 1000 virt 604 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .rdata at 0x1fdfea000 off 1a000 size 4000 virt 34e0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .pdata at 0x1fdfee000 off 1e000 size 1000 virt 9cc flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .xdata at 0x1fdfef000 off 1f000 size 1000 virt a8c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .bss at 0x1fdff0000 off 0 size 0 virt 400 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .edata at 0x1fdff1000 off 20000 size 3000 virt 281e flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .idata at 0x1fdff4000 off 23000 size 2000 virt 1240 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .rsrc at 0x1fdff6000 off 25000 size 1000 virt 3b8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .reloc at 0x1fdff7000 off 26000 size 1000 virt 54 flags 42000040 0160:0164:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"crypt32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" for L"crypt32.dll" at 00000001DD3F0000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" 000000000047B240 00000001FDFD0000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" at 00000001FDFD0000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" at 00000001FDFD0000 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" 0000000000475560 00000001F3BB0000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" at 00000001F3BB0000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" at 00000001F3BB0000 0160:0164:trace:module:process_attach (L"msi.dll",0000000000000000) - START 0160:0164:trace:module:process_attach (L"cabinet.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (00000001DC080000 L"cabinet.dll",PROCESS_ATTACH,0000000000000000) 00000001DC091A80 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000001DC080000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"cabinet.dll",0000000000000000) - END 0160:0164:trace:module:process_attach (L"comctl32.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (00000002BB750000 L"comctl32.dll",PROCESS_ATTACH,0000000000000000) 00000002BB7FDA80 - CALL 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E840, base 000000000031E838. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f01 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4C0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0009 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E700. 0160:0164:trace:module:FindResourceExW 00000002BB750000 #000e #0016 0000 0160:0164:trace:module:LoadResource 00000002BB750000 00000002BB8406B0 0160:0164:trace:module:FindResourceExW 00000002BB750000 #0003 #0002 0000 0160:0164:trace:module:LoadResource 00000002BB750000 00000002BB83F310 0160:0164:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031E390. 0160:0164:trace:module:FindResourceExW 00000002BB750000 #000e #0019 0000 0160:0164:trace:module:LoadResource 00000002BB750000 00000002BB8406C0 0160:0164:trace:module:FindResourceExW 00000002BB750000 #0003 #0003 0000 0160:0164:trace:module:LoadResource 00000002BB750000 00000002BB83F320 0160:0164:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031E390. 0160:0164:trace:module:FindResourceExW 00000002BB750000 #000e #001c 0000 0160:0164:trace:module:LoadResource 00000002BB750000 00000002BB8406D0 0160:0164:trace:module:FindResourceExW 00000002BB750000 #0003 #0004 0000 0160:0164:trace:module:LoadResource 00000002BB750000 00000002BB83F330 0160:0164:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031E390. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0160:0164:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0160:0164:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0160:0164:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031E710. 0160:0164:trace:module:MODULE_InitDLL (00000002BB750000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"comctl32.dll",0000000000000000) - END 0160:0164:trace:module:process_attach (L"crypt32.dll",0000000000000000) - START 0160:0164:trace:module:process_attach (L"bcrypt.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_ATTACH,0000000000000000) 00000002D4D49C40 - CALL 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EC90, base 000000000031EC88. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"bcrypt.dll",0000000000000000) - END 0160:0164:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_ATTACH,0000000000000000) 00000001DD4524D0 - CALL 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0160:0164:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031ED20, base 000000000031ED18. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"crypt32.dll",0000000000000000) - END 0160:0164:trace:module:process_attach (L"imagehlp.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (00000002BC640000 L"imagehlp.dll",PROCESS_ATTACH,0000000000000000) 00000002BC644570 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000002BC640000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"imagehlp.dll",0000000000000000) - END 0160:0164:trace:module:process_attach (L"mspatcha.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (000000030FBD0000 L"mspatcha.dll",PROCESS_ATTACH,0000000000000000) 000000030FBD5650 - CALL 0160:0164:trace:module:MODULE_InitDLL (000000030FBD0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"mspatcha.dll",0000000000000000) - END 0160:0164:trace:module:process_attach (L"odbccp32.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (0000000381900000 L"odbccp32.dll",PROCESS_ATTACH,0000000000000000) 0000000381907640 - CALL 0160:0164:trace:module:MODULE_InitDLL (0000000381900000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"odbccp32.dll",0000000000000000) - END 0160:0164:trace:module:process_attach (L"oleaut32.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (00000002739C0000 L"oleaut32.dll",PROCESS_ATTACH,0000000000000000) 0000000273A6A370 - CALL 0160:0164:trace:process:GetEnvironmentVariableW (L"oanocache" 0000000000000000 0) 0160:0164:trace:module:MODULE_InitDLL (00000002739C0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"oleaut32.dll",0000000000000000) - END 0160:0164:trace:module:process_attach (L"sxs.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (00000003543D0000 L"sxs.dll",PROCESS_ATTACH,0000000000000000) 00000003543D4F30 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000003543D0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"sxs.dll",0000000000000000) - END 0160:0164:trace:module:process_attach (L"urlmon.dll",0000000000000000) - START 0160:0164:trace:module:process_attach (L"wininet.dll",0000000000000000) - START 0160:0164:trace:module:process_attach (L"mpr.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (000000024F470000 L"mpr.dll",PROCESS_ATTACH,0000000000000000) 000000024F47A960 - CALL 0160:0164:trace:module:MODULE_InitDLL (000000024F470000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"mpr.dll",0000000000000000) - END 0160:0164:trace:module:process_attach (L"ws2_32.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (00000001EC2B0000 L"ws2_32.dll",PROCESS_ATTACH,0000000000000000) 00000001EC2C27C0 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000001EC2B0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"ws2_32.dll",0000000000000000) - END 0160:0164:trace:module:MODULE_InitDLL (00000003A0440000 L"wininet.dll",PROCESS_ATTACH,0000000000000000) 00000003A0486300 - CALL 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E7B0, base 000000000031E7A8. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e07c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e07c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e07c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e07c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e07c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e07c,0x00000004,0x0) 0160:0164:trace:module:MODULE_InitDLL (00000003A0440000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"wininet.dll",0000000000000000) - END 0160:0164:trace:module:MODULE_InitDLL (00000003422E0000 L"urlmon.dll",PROCESS_ATTACH,0000000000000000) 0000000342334800 - CALL 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E840, base 000000000031E838. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:MODULE_InitDLL (00000003422E0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"urlmon.dll",0000000000000000) - END 0160:0164:trace:module:process_attach (L"wintrust.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (00000001FDFD0000 L"wintrust.dll",PROCESS_ATTACH,0000000000000000) 00000001FDFE63D0 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000001FDFD0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"wintrust.dll",0000000000000000) - END 0160:0164:trace:module:MODULE_InitDLL (00000001F3BB0000 L"msi.dll",PROCESS_ATTACH,0000000000000000) 00000001F3C60C20 - CALL 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31ee28,0x00000008,0x0) 0160:0164:trace:module:MODULE_InitDLL (00000001F3BB0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"msi.dll",0000000000000000) - END 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F000, base 000000000031EFF8. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031ED00, base 000000000031ECF8. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F230, base 000000000031F228. 0160:0164:trace:module:LdrGetDllHandleEx L"msi" -> 00000001F3BB0000 (load path (null)) 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E570, base 000000000031E568. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:fixme:file:NtLockFile I/O completion on lock not implemented yet 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E1F0, base 000000000031E1E8. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:process:GetEnvironmentVariableW (L"TMP" 000000000031DF30 260) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:fixme:ntdll:NtQuerySystemInformation info_class SYSTEM_PERFORMANCE_INFORMATION 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000003,0x31deb0,0x00000060,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31db3c,0x00000004,0x0) 0160:0164:trace:process:GetEnvironmentVariableW (L"TMP" 000000000031DE80 260) 0160:0164:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000000000 0) 0160:0164:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000A8CB30 10) 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031DDA0, base 000000000031DD98. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031DAA0, base 000000000031DA98. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 000000000048F900 257) 0160:0164:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 000000000048F900 257) 0160:0164:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000000000 0) 0160:0164:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000A8CB30 10) 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E5A0, base 000000000031E598. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:load_dll looking for L"C:\\windows\\system32\\mscoree.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"C:\\windows\\system32\\mscoree.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"mscoree.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" at 0x1760000-0x179a000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .text at 0x1761000 off 1000 size 14000 virt 13c10 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .data at 0x1775000 off 15000 size 1000 virt 2c0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .rodata at 0x1776000 off 16000 size 1000 virt 820 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .rdata at 0x1777000 off 17000 size c000 virt bbc0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .pdata at 0x1783000 off 23000 size 1000 virt f30 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .xdata at 0x1784000 off 24000 size 1000 virt e3c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .bss at 0x1785000 off 0 size 0 virt 330 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .edata at 0x1786000 off 25000 size 10000 virt ff5a flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .idata at 0x1796000 off 35000 size 2000 virt 1018 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .rsrc at 0x1798000 off 37000 size 1000 virt e78 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .reloc at 0x1799000 off 38000 size 1000 virt 238 flags 42000040 0160:0164:trace:module:load_native_dll found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" for L"\\??\\C:\\windows\\system32\\mscoree.dll" at 0000000356770000, count=2 0160:0164:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\mscoree.dll" at 0000000356770000 0160:0164:err:mscoree:LoadLibraryShim flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031DEF0, base 000000000031DEE8. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) error reading registry key for installroot 0160:0164:trace:module:load_dll looking for L"fusion.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" at 0x1fc170000-0x1fc185000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .text at 0x1fc171000 off 1000 size 8000 virt 77f0 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .data at 0x1fc179000 off 9000 size 1000 virt a0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .rodata at 0x1fc17a000 off a000 size 1000 virt 104 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .rdata at 0x1fc17b000 off b000 size 2000 virt 1da0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .pdata at 0x1fc17d000 off d000 size 1000 virt 3f0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .xdata at 0x1fc17e000 off e000 size 1000 virt 42c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .bss at 0x1fc17f000 off 0 size 0 virt 360 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .edata at 0x1fc180000 off f000 size 2000 virt 1604 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .idata at 0x1fc182000 off 11000 size 1000 virt a10 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .rsrc at 0x1fc183000 off 12000 size 1000 virt 3c8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .reloc at 0x1fc184000 off 13000 size 1000 virt 70 flags 42000040 0160:0164:trace:module:load_dll looking for L"bcrypt.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" for L"bcrypt.dll" at 00000002D4D40000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"dbghelp.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" for L"dbghelp.dll" at 00000003BE590000, count=3 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" 000000000048FB20 00000001FC170000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" at 00000001FC170000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" at 00000001FC170000 0160:0164:trace:module:process_attach (L"fusion.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (00000001FC170000 L"fusion.dll",PROCESS_ATTACH,0000000000000000) 00000001FC177C00 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000001FC170000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"fusion.dll",0000000000000000) - END 0160:0164:err:mscoree:LoadLibraryShim error reading registry key for installroot 0160:0164:trace:module:load_dll looking for L"fusion.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" for L"fusion.dll" at 00000001FC170000, count=2 0160:0164:err:mscoree:LoadLibraryShim error reading registry key for installroot 0160:0164:trace:module:load_dll looking for L"fusion.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" for L"fusion.dll" at 00000001FC170000, count=3 0160:0164:err:mscoree:LoadLibraryShim error reading registry key for installroot 0160:0164:trace:module:load_dll looking for L"fusion.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" for L"fusion.dll" at 00000001FC170000, count=4 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E5A0, base 000000000031E598. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:LdrUnloadDll (00000001FC170000) 0160:0164:trace:module:LdrUnloadDll (L"fusion.dll") - START 0160:0164:trace:module:MODULE_DecRefCount (L"fusion.dll") ldr.LoadCount: 3 0160:0164:trace:module:LdrUnloadDll END 0160:0164:trace:module:LdrUnloadDll (00000001FC170000) 0160:0164:trace:module:LdrUnloadDll (L"fusion.dll") - START 0160:0164:trace:module:MODULE_DecRefCount (L"fusion.dll") ldr.LoadCount: 2 0160:0164:trace:module:LdrUnloadDll END 0160:0164:trace:module:LdrUnloadDll (00000001FC170000) 0160:0164:trace:module:LdrUnloadDll (L"fusion.dll") - START 0160:0164:trace:module:MODULE_DecRefCount (L"fusion.dll") ldr.LoadCount: 1 0160:0164:trace:module:LdrUnloadDll END 0160:0164:trace:module:LdrUnloadDll (00000001FC170000) 0160:0164:trace:module:LdrUnloadDll (L"fusion.dll") - START 0160:0164:trace:module:MODULE_DecRefCount (L"fusion.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"bcrypt.dll") ldr.LoadCount: 1 0160:0164:trace:module:MODULE_DecRefCount (L"dbghelp.dll") ldr.LoadCount: 2 0160:0164:trace:module:MODULE_InitDLL (00000001FC170000 L"fusion.dll",PROCESS_DETACH,0000000000000000) 00000001FC177C00 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000001FC170000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" 0160:0164:trace:module:LdrUnloadDll END 0160:0164:trace:module:LdrUnloadDll (0000000356770000) 0160:0164:trace:module:LdrUnloadDll (L"mscoree.dll") - START 0160:0164:trace:module:MODULE_DecRefCount (L"mscoree.dll") ldr.LoadCount: 1 0160:0164:trace:module:LdrUnloadDll END 0160:0164:trace:process:GetEnvironmentVariableW (L"TMP" 000000000031E000 260) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31dc0c,0x00000004,0x0) 0160:0164:trace:process:GetEnvironmentVariableW (L"TMP" 000000000031DF50 260) 0160:0164:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000000000 0) 0160:0164:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000A8CB30 10) 0160:0164:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 000000000048D390 257) 0160:0164:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 000000000048D390 257) 0160:0164:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000000000 0) 0160:0164:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000A8CB30 10) 0160:0164:trace:module:load_dll looking for L"C:\\windows\\system32\\mscoree.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"C:\\windows\\system32\\mscoree.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"mscoree.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" at 0x1760000-0x179a000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .text at 0x1761000 off 1000 size 14000 virt 13c10 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .data at 0x1775000 off 15000 size 1000 virt 2c0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .rodata at 0x1776000 off 16000 size 1000 virt 820 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .rdata at 0x1777000 off 17000 size c000 virt bbc0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .pdata at 0x1783000 off 23000 size 1000 virt f30 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .xdata at 0x1784000 off 24000 size 1000 virt e3c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .bss at 0x1785000 off 0 size 0 virt 330 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .edata at 0x1786000 off 25000 size 10000 virt ff5a flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .idata at 0x1796000 off 35000 size 2000 virt 1018 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .rsrc at 0x1798000 off 37000 size 1000 virt e78 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .reloc at 0x1799000 off 38000 size 1000 virt 238 flags 42000040 0160:0164:trace:module:load_native_dll found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" for L"\\??\\C:\\windows\\system32\\mscoree.dll" at 0000000356770000, count=2 0160:0164:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\mscoree.dll" at 0000000356770000 0160:0164:err:mscoree:LoadLibraryShim error reading registry key for installroot 0160:0164:trace:module:load_dll looking for L"fusion.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" 0160:0164:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" 0160:0164:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" at 0x1fc170000-0x1fc185000 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .text at 0x1fc171000 off 1000 size 8000 virt 77f0 flags 60000020 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .data at 0x1fc179000 off 9000 size 1000 virt a0 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .rodata at 0x1fc17a000 off a000 size 1000 virt 104 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .rdata at 0x1fc17b000 off b000 size 2000 virt 1da0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .pdata at 0x1fc17d000 off d000 size 1000 virt 3f0 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .xdata at 0x1fc17e000 off e000 size 1000 virt 42c flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .bss at 0x1fc17f000 off 0 size 0 virt 360 flags c0000080 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .edata at 0x1fc180000 off f000 size 2000 virt 1604 flags 40000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .idata at 0x1fc182000 off 11000 size 1000 virt a10 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .rsrc at 0x1fc183000 off 12000 size 1000 virt 3c8 flags c0000040 0160:0164:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" section .reloc at 0x1fc184000 off 13000 size 1000 virt 70 flags 42000040 0160:0164:trace:module:load_dll looking for L"bcrypt.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" for L"bcrypt.dll" at 00000002D4D40000, count=2 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"dbghelp.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" for L"dbghelp.dll" at 00000003BE590000, count=3 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0160:0164:trace:module:import_dll is not hybrid module 0160:0164:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" 0000000000490CA0 00000001FC170000 0160:0164:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" at 00000001FC170000: builtin 0160:0164:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" at 00000001FC170000 0160:0164:trace:module:process_attach (L"fusion.dll",0000000000000000) - START 0160:0164:trace:module:MODULE_InitDLL (00000001FC170000 L"fusion.dll",PROCESS_ATTACH,0000000000000000) 00000001FC177C00 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000001FC170000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0160:0164:trace:module:process_attach (L"fusion.dll",0000000000000000) - END 0160:0164:err:mscoree:LoadLibraryShim error reading registry key for installroot 0160:0164:trace:module:load_dll looking for L"fusion.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" for L"fusion.dll" at 00000001FC170000, count=2 0160:0164:err:mscoree:LoadLibraryShim error reading registry key for installroot 0160:0164:trace:module:load_dll looking for L"fusion.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" for L"fusion.dll" at 00000001FC170000, count=3 0160:0164:err:mscoree:LoadLibraryShim error reading registry key for installroot 0160:0164:trace:module:load_dll looking for L"fusion.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" for L"fusion.dll" at 00000001FC170000, count=4 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E670, base 000000000031E668. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004e 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB1008 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0049 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0958 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004f 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB1208 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0074:0084:trace:process:NtQueryInformationProcess (0x70,0x00000000,0x4507d8,0x00000030,0x0) 0074:0084:trace:process:NtQueryInformationProcess (0x70,0x0000001a,0x12cf258,0x00000008,0x0) 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031DD90, base 000000000031DD88. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:process:CreateProcessInternalW app (null) cmdline L"\"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\\\installinf-x86.exe\" \"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\suppo"... 0160:0164:trace:process:find_exe_file looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\\\installinf-x86.exe" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;.;C:\\windows\\system32;C:\\windows\\system;C:\\windows;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0160:0164:trace:process:NtCreateUserProcess L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" image L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" cmdline L"\"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\\\installinf-x86.exe\" \"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\suppo"... parent 0x0 0160:0164:trace:process:send_to_cx_loader loader (null) wineserversocket 15 stdin_fd 0 stdout_fd 1 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 0160:0164:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0168:016c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" 0168:016c:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" 0168:016c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" 0168:016c:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" 0168:016c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" at 0x400000-0x408000 0168:016c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" section .text at 0x401000 off 400 size 1600 virt 154e flags 60000020 0168:016c:trace:module:map_image_into_view clearing 0x402600 - 0x403000 0168:016c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" section .rdata at 0x403000 off 1a00 size c00 virt af3 flags 40000040 0168:016c:trace:module:map_image_into_view clearing 0x403c00 - 0x404000 0168:016c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" section .buildid at 0x404000 off 2600 size 200 virt 56 flags 40000040 0168:016c:trace:module:map_image_into_view clearing 0x404200 - 0x405000 0168:016c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" section .data at 0x405000 off 2800 size 200 virt 108 flags c0000040 0168:016c:trace:module:map_image_into_view clearing 0x405200 - 0x406000 0168:016c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" section .tls at 0x406000 off 2a00 size 200 virt 8 flags c0000040 0168:016c:trace:module:map_image_into_view clearing 0x406200 - 0x407000 0168:016c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" section .reloc at 0x407000 off 2c00 size 400 virt 270 flags 42000040 0168:016c:trace:module:map_image_into_view clearing 0x407400 - 0x408000 0168:016c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0168:016c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\syswow64\\ntdll.dll" at 0x7bc00000-0x7bc97000 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .text at 0x7bc01000 off 1000 size 66000 virt 652b8 flags 60000020 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .data at 0x7bc67000 off 67000 size 1000 virt b60 flags c0000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .rodata at 0x7bc68000 off 68000 size 2000 virt 1ff4 flags c0000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .rdata at 0x7bc6a000 off 6a000 size 11000 virt 10568 flags 40000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .bss at 0x7bc7b000 off 0 size 0 virt 24e4 flags c0000080 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .edata at 0x7bc7e000 off 7b000 size 13000 virt 12769 flags 40000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .idata at 0x7bc91000 off 8e000 size 1000 virt 14 flags c0000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .rsrc at 0x7bc92000 off 8f000 size 1000 virt 3ac flags c0000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .reloc at 0x7bc93000 off 90000 size 4000 virt 3e18 flags 42000040 0168:016c:trace:module:load_wow64_ntdll loaded L"\\??\\C:\\windows\\syswow64\\ntdll.dll" at 0x7bc00000 0168:016c:fixme:module:dlopen_32on64_opengl32 loaded "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_32on64-unix/opengl32.dll.so" early @ 0x6a22c000 0168:016c:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x131000 0160:0164:trace:process:NtCreateUserProcess L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" pid 0168 tid 016c handles 0xb8/0xbc 0160:0164:trace:process:CreateProcessInternalW started process pid 0168 tid 016c 0168:016c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x60f790,0x00000040,0x0) 0168:016c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" 0000000000712EA0 0000000000400000 0168:016c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" at 0000000000400000: native 0168:016c:trace:module:load_dll looking for L"C:\\windows\\system32\\wow64.dll" in (null) 0168:016c:trace:module:get_load_order looking for L"C:\\windows\\system32\\wow64.dll" 0168:016c:trace:module:get_load_order got hardcoded default for L"wow64.dll" 0168:016c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\wow64.dll" at 0x6f000000-0x6f026000 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .text at 0x6f001000 off 1000 size 12000 virt 11ab0 flags 60000020 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .data at 0x6f013000 off 13000 size 1000 virt 840 flags c0000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .rodata at 0x6f014000 off 14000 size 1000 virt 2a8 flags c0000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .rdata at 0x6f015000 off 15000 size 3000 virt 2c70 flags 40000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .pdata at 0x6f018000 off 18000 size 1000 virt d68 flags 40000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .xdata at 0x6f019000 off 19000 size 1000 virt d5c flags 40000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .bss at 0x6f01a000 off 0 size 0 virt 4160 flags c0000080 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .edata at 0x6f01f000 off 1a000 size 3000 virt 2c2c flags 40000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .idata at 0x6f022000 off 1d000 size 3000 virt 2908 flags c0000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .reloc at 0x6f025000 off 20000 size 1000 virt 3f8 flags 42000040 0168:016c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0168:016c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0168:016c:trace:module:import_dll is not hybrid module 0168:016c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wow64.dll" 0000000000713310 000000006F000000 0168:016c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wow64.dll" at 000000006F000000: builtin 0168:016c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wow64.dll" at 000000006F000000 0168:016c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000060F3C0, base 000000000060F3B0. 0168:016c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0168:016c:trace:module:load_dll looking for L"\\??\\C:\\windows\\system32\\wow64cpu.dll" in (null) 0168:016c:trace:module:get_load_order looking for L"C:\\windows\\system32\\wow64cpu.dll" 0168:016c:trace:module:get_load_order got hardcoded default for L"wow64cpu.dll" 0168:016c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\wow64cpu.dll" at 0x6f100000-0x6f10c000 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .text at 0x6f101000 off 1000 size 1000 virt 7c0 flags 60000020 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .data at 0x6f102000 off 2000 size 1000 virt 40 flags c0000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .rodata at 0x6f103000 off 3000 size 1000 virt 24 flags c0000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .rdata at 0x6f104000 off 4000 size 1000 virt a0 flags 40000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .pdata at 0x6f105000 off 5000 size 1000 virt 84 flags 40000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .xdata at 0x6f106000 off 6000 size 1000 virt 5c flags 40000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .bss at 0x6f107000 off 0 size 0 virt 2000 flags c0000080 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .edata at 0x6f109000 off 7000 size 1000 virt 21e flags 40000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .idata at 0x6f10a000 off 8000 size 1000 virt 21c flags c0000040 0168:016c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .reloc at 0x6f10b000 off 9000 size 1000 virt 1c flags 42000040 0168:016c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0168:016c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0168:016c:trace:module:import_dll is not hybrid module 0168:016c:trace:module:load_dll looking for L"wow64.dll" in (null) 0168:016c:trace:module:load_dll Found L"C:\\windows\\system32\\wow64.dll" for L"wow64.dll" at 000000006F000000, count=2 0168:016c:trace:module:import_dll is not hybrid module 0168:016c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wow64cpu.dll" 0000000000713540 000000006F100000 0168:016c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wow64cpu.dll" at 000000006F100000: builtin 0168:016c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wow64cpu.dll" at 000000006F100000 0168:016c:trace:module:process_attach (L"wow64cpu.dll",0000000000000000) - START 0168:016c:trace:module:process_attach (L"wow64.dll",0000000000000000) - START 0168:016c:trace:module:MODULE_InitDLL (000000006F000000 L"wow64.dll",PROCESS_ATTACH,0000000000000000) 000000006F012780 - CALL 0168:016c:trace:module:MODULE_InitDLL (000000006F000000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0168:016c:trace:module:process_attach (L"wow64.dll",0000000000000000) - END 0168:016c:trace:module:MODULE_InitDLL (000000006F100000 L"wow64cpu.dll",PROCESS_ATTACH,0000000000000000) 000000006F101790 - CALL 0168:016c:trace:module:MODULE_InitDLL (000000006F100000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0168:016c:trace:module:process_attach (L"wow64cpu.dll",0000000000000000) - END 0168:016c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x60ef70,0x00000040,0x0) 0168:016c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" 00822C40 00400000 0168:016c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\share\\wine\\mono\\wine-mono-7.2.0\\support\\installinf-x86.exe" at 00400000: native 0168:016c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0168:016c:warn:module:load_dll Failed to load module L"kernel32.dll"; status=c0000135 wine: could not load kernel32.dll, status c0000135 0160:0164:trace:process:NtQueryInformationProcess (0xb8,0x00000000,0x31e720,0x00000030,0x0) 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:err:msi:execute_script flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E3B0, base 000000000031E3A8. 0160:0164:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) Execution of script 0 halted; action L"INSTALLFAKEDLLS" returned 1627 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:err:msi:ITERATE_Actions Execution halted, action L"InstallFinalize" returned 1627 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:fixme:msi:internal_ui_handler internal UI not implemented for message 0x0b000000 (UI level = 1) 0160:0164:fixme:msi:internal_ui_handler internal UI not implemented for message 0x0b000000 (UI level = 1) 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0049 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0958 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0049 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0958 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004e 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB1008 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004e 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB1008 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0049 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0958 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004f 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB1208 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0160:0164:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0160:0164:trace:module:LdrUnloadDll (00000001FC170000) 0160:0164:trace:module:LdrUnloadDll (L"fusion.dll") - START 0160:0164:trace:module:MODULE_DecRefCount (L"fusion.dll") ldr.LoadCount: 3 0160:0164:trace:module:LdrUnloadDll END 0160:0164:trace:module:LdrUnloadDll (00000001FC170000) 0160:0164:trace:module:LdrUnloadDll (L"fusion.dll") - START 0160:0164:trace:module:MODULE_DecRefCount (L"fusion.dll") ldr.LoadCount: 2 0160:0164:trace:module:LdrUnloadDll END 0160:0164:trace:module:LdrUnloadDll (00000001FC170000) 0160:0164:trace:module:LdrUnloadDll (L"fusion.dll") - START 0160:0164:trace:module:MODULE_DecRefCount (L"fusion.dll") ldr.LoadCount: 1 0160:0164:trace:module:LdrUnloadDll END 0160:0164:trace:module:LdrUnloadDll (00000001FC170000) 0160:0164:trace:module:LdrUnloadDll (L"fusion.dll") - START 0160:0164:trace:module:MODULE_DecRefCount (L"fusion.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"bcrypt.dll") ldr.LoadCount: 1 0160:0164:trace:module:MODULE_DecRefCount (L"dbghelp.dll") ldr.LoadCount: 2 0160:0164:trace:module:MODULE_InitDLL (00000001FC170000 L"fusion.dll",PROCESS_DETACH,0000000000000000) 00000001FC177C00 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000001FC170000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\fusion.dll" 0160:0164:trace:module:LdrUnloadDll END 0160:0164:trace:module:LdrUnloadDll (0000000356770000) 0160:0164:trace:module:LdrUnloadDll (L"mscoree.dll") - START 0160:0164:trace:module:MODULE_DecRefCount (L"mscoree.dll") ldr.LoadCount: 1 0160:0164:trace:module:LdrUnloadDll END 0160:0164:err:mscoree:install_wine_mono MsiInstallProduct failed, err=1627 0160:0164:trace:process:CreateProcessInternalW app L"C:\\windows\\system32\\control.exe" cmdline L"C:\\windows\\system32\\control.exe appwiz.cpl install_mono" 0160:0164:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\control.exe" image L"C:\\windows\\system32\\control.exe" cmdline L"C:\\windows\\system32\\control.exe appwiz.cpl install_mono" parent 0x0 0160:0164:trace:process:send_to_cx_loader loader (null) wineserversocket 13 stdin_fd 0 stdout_fd 1 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 0160:0164:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\control.exe" 0170:0174:trace:module:get_load_order got hardcoded default for L"control.exe" 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\control.exe" 0170:0174:trace:module:get_load_order got hardcoded default for L"control.exe" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\control.exe" at 0x140000000-0x140007000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\control.exe" section .text at 0x140001000 off 1000 size 1000 virt 370 flags 60000020 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\control.exe" section .rdata at 0x140002000 off 2000 size 1000 virt 1a0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\control.exe" section .pdata at 0x140003000 off 3000 size 1000 virt 30 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\control.exe" section .xdata at 0x140004000 off 4000 size 1000 virt 2c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\control.exe" section .idata at 0x140005000 off 5000 size 1000 virt 358 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\control.exe" section .rsrc at 0x140006000 off 6000 size 1000 virt 350 flags c0000040 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0170:0174:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0160:0164:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\control.exe" pid 0170 tid 0174 handles 0x9c/0xa0 0160:0164:trace:process:CreateProcessInternalW started process pid 0170 tid 0174 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\control.exe" 0000000000432990 0000000140000000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\control.exe" at 0000000140000000: builtin 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernel32.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"kernel32.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0170:0174:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernelbase.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"kernelbase.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 0000000000433080 000000007B000000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000432D90 000000007B600000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 0170:0174:trace:module:load_dll looking for L"comctl32.dll" in (null) 0170:0174:trace:module:find_dll_file found L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" for L"comctl32.dll" 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" at 0x2bb750000-0x2bb88f000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .text at 0x2bb751000 off 1000 size ae000 virt ad9d0 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .data at 0x2bb7ff000 off af000 size 1000 virt 300 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .rodata at 0x2bb800000 off b0000 size 1000 virt 734 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .rdata at 0x2bb801000 off b1000 size 1f000 virt 1ef80 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .pdata at 0x2bb820000 off d0000 size 4000 virt 3198 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .xdata at 0x2bb824000 off d4000 size 5000 virt 40a8 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .bss at 0x2bb829000 off 0 size 0 virt 1720 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .edata at 0x2bb82b000 off d9000 size f000 virt eff3 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .idata at 0x2bb83a000 off e8000 size 4000 virt 3b2c flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .rsrc at 0x2bb83e000 off ec000 size 50000 virt 4fad8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .reloc at 0x2bb88e000 off 13c000 size 1000 virt 1d4 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\advapi32.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"advapi32.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvcrt.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"msvcrt.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 0000000000434350 00000001C8DB0000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"sechost.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\sechost.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"sechost.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\ucrtbase.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"ucrtbase.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 0000000000434890 00000003AF670000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 0000000000434620 000000032A700000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 00000000004341F0 0000000330260000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"gdi32.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\gdi32.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"gdi32.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\user32.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"user32.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"gdi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"sechost.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"version.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\version.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"version.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 0000000000436730 00000002F1FA0000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 00000002F1FA0000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 00000002F1FA0000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"win32u.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\win32u.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"win32u.dll" 0170:0174:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\win32u.dll" is a fake Wine dll 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\win32u.dll" 0000000000436A80 000000006AC60000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\win32u.dll" at 000000006AC60000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\win32u.dll" at 000000006AC60000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\user32.dll" 0000000000436360 000000023D820000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\user32.dll" at 000000023D820000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\user32.dll" at 000000023D820000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"win32u.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AC60000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\gdi32.dll" 0000000000434B80 000000026B4C0000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"imm32.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\imm32.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"imm32.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=4 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imm32.dll" 0000000000436D90 00000003AFD00000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imm32.dll" at 00000003AFD00000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imm32.dll" at 00000003AFD00000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=11 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=6 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=13 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=6 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=3 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" 0000000000435470 00000002BB750000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" at 00000002BB750000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" at 00000002BB750000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=12 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"shell32.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\shell32.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"shell32.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" at 0x1c69e0000-0x1c72fe000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .text at 0x1c69e1000 off 1000 size 89000 virt 88c60 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .data at 0x1c6a6a000 off 8a000 size 2000 virt 13e0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rodata at 0x1c6a6c000 off 8c000 size 2000 virt 18ec flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rdata at 0x1c6a6e000 off 8e000 size 29000 virt 28e90 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .pdata at 0x1c6a97000 off b7000 size 6000 virt 5748 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .xdata at 0x1c6a9d000 off bd000 size 6000 virt 5c20 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .bss at 0x1c6aa3000 off 0 size 0 virt 570 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .edata at 0x1c6aa4000 off c3000 size 15000 virt 14070 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .idata at 0x1c6ab9000 off d8000 size 5000 virt 4aa0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rsrc at 0x1c6abe000 off dd000 size 83e000 virt 83d918 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .reloc at 0x1c72fc000 off 91b000 size 2000 virt 1264 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=5 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"gdi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=13 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=14 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"shlwapi.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\shlwapi.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"shlwapi.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" at 0x2e3540000-0x2e3591000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .text at 0x2e3541000 off 1000 size 1e000 virt 1dac0 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .data at 0x2e355f000 off 1f000 size 1000 virt 210 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rodata at 0x2e3560000 off 20000 size 2000 virt 18fc flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rdata at 0x2e3562000 off 22000 size b000 virt a290 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .pdata at 0x2e356d000 off 2d000 size 2000 virt 11b8 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .xdata at 0x2e356f000 off 2f000 size 2000 virt 13a8 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .bss at 0x2e3571000 off 0 size 0 virt 1c0 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .edata at 0x2e3572000 off 31000 size 14000 virt 13ab5 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .idata at 0x2e3586000 off 45000 size 5000 virt 442c flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rsrc at 0x2e358b000 off 4a000 size 5000 virt 4ed0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .reloc at 0x2e3590000 off 4f000 size 1000 virt e0 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=6 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"gdi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=3 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=14 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=7 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=15 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"shcore.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\shcore.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"shcore.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" at 0x3126f0000-0x312709000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .text at 0x3126f1000 off 1000 size 9000 virt 8b70 flags 60000020 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .data at 0x3126fa000 off a000 size 1000 virt b0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rodata at 0x3126fb000 off b000 size 1000 virt fb4 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rdata at 0x3126fc000 off c000 size 3000 virt 2360 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .pdata at 0x3126ff000 off f000 size 1000 virt 57c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .xdata at 0x312700000 off 10000 size 1000 virt 61c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .bss at 0x312701000 off 0 size 0 virt 160 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .edata at 0x312702000 off 11000 size 5000 virt 480e flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .idata at 0x312707000 off 16000 size 1000 virt c74 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .reloc at 0x312708000 off 17000 size 1000 virt a8 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=7 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=15 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=16 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ole32.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\ole32.dll" 0170:0174:trace:module:get_load_order_value got standard key b for L"ole32" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" at 0x2e8f10000-0x2e902b000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .text at 0x2e8f11000 off 1000 size a8000 virt a76a0 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .data at 0x2e8fb9000 off a9000 size 1000 virt 480 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rodata at 0x2e8fba000 off aa000 size 1000 virt 778 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rdata at 0x2e8fbb000 off ab000 size 1e000 virt 1d750 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .pdata at 0x2e8fd9000 off c9000 size 7000 virt 6b10 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .xdata at 0x2e8fe0000 off d0000 size 7000 virt 67c4 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .bss at 0x2e8fe7000 off 0 size 0 virt 210 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .edata at 0x2e8fe8000 off d7000 size 18000 virt 17412 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .idata at 0x2e9000000 off ef000 size 4000 virt 367c flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rsrc at 0x2e9004000 off f3000 size 25000 virt 24bc0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .reloc at 0x2e9029000 off 118000 size 2000 virt 1804 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=8 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"combase.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\combase.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"combase.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" at 0x327020000-0x327073000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .text at 0x327021000 off 1000 size 27000 virt 26590 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .data at 0x327048000 off 28000 size 1000 virt 580 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rodata at 0x327049000 off 29000 size 2000 virt 16c0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rdata at 0x32704b000 off 2b000 size d000 virt cf90 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .pdata at 0x327058000 off 38000 size 2000 virt 17a0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .xdata at 0x32705a000 off 3a000 size 2000 virt 18e4 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .bss at 0x32705c000 off 0 size 0 virt 1a0 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .edata at 0x32705d000 off 3c000 size 13000 virt 12d6e flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .idata at 0x327070000 off 4f000 size 2000 virt 1804 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .reloc at 0x327072000 off 51000 size 1000 virt 23c flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=9 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"gdi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=4 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=16 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=17 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ole32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\rpcrt4.dll" 0170:0174:trace:module:get_load_order_value got standard key b for L"rpcrt4" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0x231ae0000-0x231b62000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .text at 0x231ae1000 off 1000 size 47000 virt 46400 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .data at 0x231b28000 off 48000 size 1000 virt 710 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rodata at 0x231b29000 off 49000 size 2000 virt 1b44 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rdata at 0x231b2b000 off 4b000 size 15000 virt 14b90 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .pdata at 0x231b40000 off 60000 size 3000 virt 2334 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .xdata at 0x231b43000 off 63000 size 3000 virt 289c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .bss at 0x231b46000 off 0 size 0 virt 690 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .edata at 0x231b47000 off 66000 size 17000 virt 16730 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .idata at 0x231b5e000 off 7d000 size 2000 virt 19a8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rsrc at 0x231b60000 off 7f000 size 1000 virt 3a8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .reloc at 0x231b61000 off 80000 size 1000 virt 504 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=10 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=17 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=18 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=7 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rpcrt4.dll" 0000000000438130 0000000231AE0000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=8 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=4 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\combase.dll" 0000000000437DA0 0000000327020000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\combase.dll" at 0000000327020000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\combase.dll" at 0000000327020000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"gdi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=5 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=18 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=8 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=19 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=9 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=5 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ole32.dll" 0000000000437A90 00000002E8F10000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ole32.dll" at 00000002E8F10000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ole32.dll" at 00000002E8F10000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=10 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=6 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shcore.dll" 0000000000437780 00000003126F0000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shcore.dll" at 00000003126F0000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shcore.dll" at 00000003126F0000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=11 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=7 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shlwapi.dll" 00000000004373F0 00000002E3540000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shlwapi.dll" at 00000002E3540000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shlwapi.dll" at 00000002E3540000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=12 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=8 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shell32.dll" 00000000004371A0 00000001C69E0000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shell32.dll" at 00000001C69E0000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shell32.dll" at 00000001C69E0000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=13 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=9 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 0170:0174:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 0170:0174:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 0170:0174:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 0170:0174:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 0170:0174:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 0170:0174:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 0170:0174:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 0170:0174:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 000000000043A920 17) 0170:0174:trace:module:LdrGetDllHandleEx flags 0, load_path 000000000043AA30, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0170:0174:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0170:0174:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0170:0174:trace:module:LoadResource 0000000010000002 00000000100077D8 0170:0174:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 0170:0174:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 000000000043A970 17) 0170:0174:trace:module:LdrGetDllHandleEx flags 0, load_path 000000000043AB50, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0170:0174:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0170:0174:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0170:0174:trace:module:LoadResource 0000000010000002 00000000100077D8 0170:0174:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 0170:0174:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 0170:0174:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 0170:0174:trace:module:process_attach (L"comctl32.dll",000000000031FB00) - START 0170:0174:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 0170:0174:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 0170:0174:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 0170:0174:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 0170:0174:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\control.exe" 0170:0174:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 0170:0174:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\control.exe" 0170:0174:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0170:0174:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 0170:0174:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 0170:0174:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 0170:0174:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 0170:0174:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F290. 0170:0174:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\control.exe" 0170:0174:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F2E0. 0170:0174:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\control.exe" 0170:0174:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 0170:0174:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 0170:0174:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 0170:0174:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 0170:0174:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 0170:0174:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - START 0170:0174:trace:module:process_attach (L"user32.dll",000000000031FB00) - START 0170:0174:trace:module:process_attach (L"version.dll",000000000031FB00) - START 0170:0174:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000031FB00) 00000002F1FA2510 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"version.dll",000000000031FB00) - END 0170:0174:trace:module:process_attach (L"win32u.dll",000000000031FB00) - START 0170:0174:trace:module:MODULE_InitDLL (000000006AC60000 L"win32u.dll",PROCESS_ATTACH,000000000031FB00) 000000006AD09460 - CALL 0170:0174:trace:module:MODULE_InitDLL (000000006AC60000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"win32u.dll",000000000031FB00) - END 0170:0174:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000031FB00) 000000023D8C5690 - CALL 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F0A0, base 000000000031F098. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031ED90, base 000000000031ED88. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:load_dll looking for L"imm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\imm32.dll" for L"imm32.dll" at 00000003AFD00000, count=2 0170:0174:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 0170:0174:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EB20, base 000000000031EB18. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EFC0, base 000000000031EFB8. 0170:0174:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 0170:0174:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 0170:0174:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"user32.dll",000000000031FB00) - END 0170:0174:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000031FB00) 000000026B509F00 - CALL 0170:0174:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - END 0170:0174:trace:module:MODULE_InitDLL (00000002BB750000 L"comctl32.dll",PROCESS_ATTACH,000000000031FB00) 00000002BB7FDA80 - CALL 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F120, base 000000000031F118. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:load_dll looking for L"winemac.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\winemac.drv" 0170:0174:trace:module:get_load_order got hardcoded default for L"winemac.drv" 0170:0174:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\winemac.drv" is a fake Wine dll 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"win32u.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AC60000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\winemac.drv" 0000000000442770 000000006DF10000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\winemac.drv" at 000000006DF10000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\winemac.drv" at 000000006DF10000 0170:0174:trace:module:process_attach (L"winemac.drv",0000000000000000) - START 0170:0174:trace:module:MODULE_InitDLL (000000006DF10000 L"winemac.drv",PROCESS_ATTACH,0000000000000000) 000000006DF28C10 - CALL 0170:0174:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031B7D0. 0170:0174:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\control.exe" 0170:0174:trace:module:FindResourceExW 000000006DF10000 #0006 #0011 0000 0170:0174:trace:module:LoadResource 000000006DF10000 000000006DF8E9D8 0170:0174:trace:module:FindResourceExW 000000006DF10000 #0006 #0011 0000 0170:0174:trace:module:LoadResource 000000006DF10000 000000006DF8E9D8 0170:0174:trace:module:FindResourceExW 000000006DF10000 #0006 #0011 0000 0170:0174:trace:module:LoadResource 000000006DF10000 000000006DF8E9D8 0170:0174:trace:module:FindResourceExW 000000006DF10000 #0006 #0011 0000 0170:0174:trace:module:LoadResource 000000006DF10000 000000006DF8E9D8 0170:0174:trace:module:FindResourceExW 000000006DF10000 #0006 #0011 0000 0170:0174:trace:module:LoadResource 000000006DF10000 000000006DF8E9D8 0170:0174:trace:module:FindResourceExW 000000006DF10000 #0006 #0011 0000 0170:0174:trace:module:LoadResource 000000006DF10000 000000006DF8E9D8 0170:0174:trace:module:FindResourceExW 000000006DF10000 #0006 #0011 0000 0170:0174:trace:module:LoadResource 000000006DF10000 000000006DF8E9D8 0170:0174:trace:module:FindResourceExW 000000006DF10000 #0006 #0012 0000 0170:0174:trace:module:LoadResource 000000006DF10000 000000006DF8EBC8 0170:0174:trace:module:FindResourceExW 000000006DF10000 #0006 #0012 0000 0170:0174:trace:module:LoadResource 000000006DF10000 000000006DF8EBC8 0170:0174:trace:module:FindResourceExW 000000006DF10000 #0006 #0012 0000 0170:0174:trace:module:LoadResource 000000006DF10000 000000006DF8EBC8 0170:0174:trace:module:FindResourceExW 000000006DF10000 #0006 #0012 0000 0170:0174:trace:module:LoadResource 000000006DF10000 000000006DF8EBC8 0170:0174:trace:module:FindResourceExW 000000006DF10000 #0006 #0012 0000 0170:0174:trace:module:LoadResource 000000006DF10000 000000006DF8EBC8 0170:0174:trace:module:MODULE_InitDLL (000000006DF10000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"winemac.drv",0000000000000000) - END 0170:0174:trace:module:EnumResourceNamesExW 0000000000000000 #000e 000000006DF1FB00 31d068 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0170:0174:trace:module:LoadResource 000000023D820000 000000023D908880 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C080, base 000000000031C078. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C4D0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f01 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4C0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0009 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0170:0174:trace:module:LoadResource 000000023D820000 000000023D9088E0 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C4D0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0170:0174:trace:module:load_dll looking for L"uxtheme.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\uxtheme.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"uxtheme.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 0x2f7230000-0x2f7265000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .text at 0x2f7231000 off 1000 size 13000 virt 123c0 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .data at 0x2f7244000 off 14000 size 1000 virt 110 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rodata at 0x2f7245000 off 15000 size 1000 virt 430 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rdata at 0x2f7246000 off 16000 size 16000 virt 15a30 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .pdata at 0x2f725c000 off 2c000 size 1000 virt 87c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .xdata at 0x2f725d000 off 2d000 size 1000 virt 97c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .bss at 0x2f725e000 off 0 size 0 virt 4a0 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .edata at 0x2f725f000 off 2e000 size 2000 virt 1de0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .idata at 0x2f7261000 off 30000 size 2000 virt 14ac flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rsrc at 0x2f7263000 off 32000 size 1000 virt 5f8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .reloc at 0x2f7264000 off 33000 size 1000 virt bc flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\uxtheme.dll" 0000000000442B40 00000002F7230000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\uxtheme.dll" at 00000002F7230000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 00000002F7230000 0170:0174:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - START 0170:0174:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_ATTACH,0000000000000000) 00000002F72424B0 - CALL 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C6C0, base 000000000031C6B8. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C870, base 000000000031C868. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000442F10, dll_characteristics 0000000000000000, name 000000000031CA90, base 000000000031CA28. 0170:0174:trace:module:LdrGetDllHandleEx L"C:\\windows\\resources\\themes\\light\\light.msstyles" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0170:0174:trace:module:FindResourceExW 0000000000F10001 L"PACKTHEM_VERSION" #0001 0000 0170:0174:trace:module:LoadResource 0000000000F10001 0000000000F15310 0170:0174:trace:module:FindResourceExW 0000000000F10001 L"COLORNAMES" #0001 0000 0170:0174:trace:module:LoadResource 0000000000F10001 0000000000F152F0 0170:0174:trace:module:FindResourceExW 0000000000F10001 L"SIZENAMES" #0001 0000 0170:0174:trace:module:LoadResource 0000000000F10001 0000000000F15320 0170:0174:trace:module:FindResourceExW 0000000000F10001 L"FILERESNAMES" #0001 0000 0170:0174:trace:module:LoadResource 0000000000F10001 0000000000F15300 0170:0174:trace:module:FindResourceExW 0000000000F10001 L"TEXTFILE" L"BLUE_INI" 0000 0170:0174:trace:module:LoadResource 0000000000F10001 0000000000F15330 0170:0174:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - END 0170:0174:trace:module:load_dll looking for L"winemac.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\winemac.drv" for L"winemac.drv" at 000000006DF10000, count=2 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f01 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4C0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0009 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFE0. 0170:0174:trace:module:FindResourceExW 00000002BB750000 #000e #0016 0000 0170:0174:trace:module:LoadResource 00000002BB750000 00000002BB8406B0 0170:0174:trace:module:FindResourceExW 00000002BB750000 #0003 #0002 0000 0170:0174:trace:module:LoadResource 00000002BB750000 00000002BB83F310 0170:0174:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031EC70. 0170:0174:trace:module:FindResourceExW 00000002BB750000 #000e #0019 0000 0170:0174:trace:module:LoadResource 00000002BB750000 00000002BB8406C0 0170:0174:trace:module:FindResourceExW 00000002BB750000 #0003 #0003 0000 0170:0174:trace:module:LoadResource 00000002BB750000 00000002BB83F320 0170:0174:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031EC70. 0170:0174:trace:module:FindResourceExW 00000002BB750000 #000e #001c 0000 0170:0174:trace:module:LoadResource 00000002BB750000 00000002BB8406D0 0170:0174:trace:module:FindResourceExW 00000002BB750000 #0003 #0004 0000 0170:0174:trace:module:LoadResource 00000002BB750000 00000002BB83F330 0170:0174:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031EC70. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0170:0174:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0170:0174:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0170:0174:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0170:0174:trace:module:MODULE_InitDLL (00000002BB750000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"comctl32.dll",000000000031FB00) - END 0170:0174:trace:module:process_attach (L"shell32.dll",000000000031FB00) - START 0170:0174:trace:module:process_attach (L"shlwapi.dll",000000000031FB00) - START 0170:0174:trace:module:process_attach (L"shcore.dll",000000000031FB00) - START 0170:0174:trace:module:process_attach (L"ole32.dll",000000000031FB00) - START 0170:0174:trace:module:process_attach (L"combase.dll",000000000031FB00) - START 0170:0174:trace:module:process_attach (L"rpcrt4.dll",000000000031FB00) - START 0170:0174:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_ATTACH,000000000031FB00) 0000000231B26040 - CALL 0170:0174:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"rpcrt4.dll",000000000031FB00) - END 0170:0174:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_ATTACH,000000000031FB00) 00000003270465C0 - CALL 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EED0, base 000000000031EEC8. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"combase.dll",000000000031FB00) - END 0170:0174:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_ATTACH,000000000031FB00) 00000002E8FB74E0 - CALL 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EF80, base 000000000031EF78. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"ole32.dll",000000000031FB00) - END 0170:0174:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_ATTACH,000000000031FB00) 00000003126F8FD0 - CALL 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F010, base 000000000031F008. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"shcore.dll",000000000031FB00) - END 0170:0174:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_ATTACH,000000000031FB00) 00000002E355DE00 - CALL 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F0A0, base 000000000031F098. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"shlwapi.dll",000000000031FB00) - END 0170:0174:trace:module:MODULE_InitDLL (00000001C69E0000 L"shell32.dll",PROCESS_ATTACH,000000000031FB00) 00000001C6A688D0 - CALL 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F130, base 000000000031F128. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:LdrGetDllFullName module 00000001C69E0000, name 000000000031F650. 0170:0174:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\shell32.dll" 0170:0174:trace:module:MODULE_InitDLL (00000001C69E0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0170:0174:trace:module:process_attach (L"shell32.dll",000000000031FB00) - END 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FA20, base 000000000031FA18. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:process:ExpandEnvironmentStringsW (L"appwiz.cpl" 0000000000000000 0) 0170:0174:trace:process:ExpandEnvironmentStringsW (L"appwiz.cpl" 0000000000442F10 12) 0170:0174:trace:module:CreateActCtxW 000000000031F690 00000008 0170:0174:trace:module:load_dll looking for L"appwiz.cpl" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\appwiz.cpl" 0170:0174:trace:module:get_load_order got hardcoded default for L"appwiz.cpl" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\appwiz.cpl" at 0x1c3c60000-0x1c3cc0000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\appwiz.cpl" section .text at 0x1c3c61000 off 1000 size 6000 virt 53d0 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\appwiz.cpl" section .data at 0x1c3c67000 off 7000 size 1000 virt b0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\appwiz.cpl" section .rodata at 0x1c3c68000 off 8000 size 1000 virt c flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\appwiz.cpl" section .rdata at 0x1c3c69000 off 9000 size 7000 virt 6f70 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\appwiz.cpl" section .pdata at 0x1c3c70000 off 10000 size 1000 virt 300 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\appwiz.cpl" section .xdata at 0x1c3c71000 off 11000 size 1000 virt 31c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\appwiz.cpl" section .bss at 0x1c3c72000 off 0 size 0 virt 11a0 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\appwiz.cpl" section .edata at 0x1c3c74000 off 12000 size d000 virt c18d flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\appwiz.cpl" section .idata at 0x1c3c81000 off 1f000 size 1000 virt f8c flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\appwiz.cpl" section .rsrc at 0x1c3c82000 off 20000 size 3d000 virt 3cdf8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\appwiz.cpl" section .reloc at 0x1c3cbf000 off 5d000 size 1000 virt 88 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"bcrypt.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\bcrypt.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"bcrypt.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 0x2d4d40000-0x2d4d57000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .text at 0x2d4d41000 off 1000 size a000 virt 97c0 flags 60000020 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .data at 0x2d4d4b000 off b000 size 1000 virt 70 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rodata at 0x2d4d4c000 off c000 size 1000 virt 3b8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rdata at 0x2d4d4d000 off d000 size 2000 virt 1c40 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .pdata at 0x2d4d4f000 off f000 size 1000 virt 420 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .xdata at 0x2d4d50000 off 10000 size 1000 virt 52c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .bss at 0x2d4d51000 off 0 size 0 virt 170 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .edata at 0x2d4d52000 off 11000 size 2000 virt 1317 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .idata at 0x2d4d54000 off 13000 size 1000 virt 6cc flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rsrc at 0x2d4d55000 off 14000 size 1000 virt 3c0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .reloc at 0x2d4d56000 off 15000 size 1000 virt 44 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\bcrypt.dll" 0000000000477030 00000002D4D40000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\bcrypt.dll" at 00000002D4D40000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\bcrypt.dll" at 00000002D4D40000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"comctl32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:find_dll_file found L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" for L"comctl32.dll" 0170:0174:trace:module:load_dll Found L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" for L"comctl32.dll" at 00000002BB750000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"comdlg32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\comdlg32.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"comdlg32.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\comdlg32.dll" at 0x31f800000-0x31f8ff000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .text at 0x31f801000 off 1000 size 2f000 virt 2e920 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .data at 0x31f830000 off 30000 size 1000 virt 150 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .rodata at 0x31f831000 off 31000 size 1000 virt c4 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .rdata at 0x31f832000 off 32000 size e000 virt d590 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .pdata at 0x31f840000 off 40000 size 2000 virt 12c0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .xdata at 0x31f842000 off 42000 size 2000 virt 1594 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .bss at 0x31f844000 off 0 size 0 virt a30 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .edata at 0x31f845000 off 44000 size d000 virt cacc flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .idata at 0x31f852000 off 51000 size 3000 virt 2ca8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .rsrc at 0x31f855000 off 54000 size a9000 virt a8780 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\comdlg32.dll" section .reloc at 0x31f8fe000 off fd000 size 1000 virt 2e0 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"comctl32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:find_dll_file found L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" for L"comctl32.dll" 0170:0174:trace:module:load_dll Found L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" for L"comctl32.dll" at 00000002BB750000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"shell32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"shlwapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"winspool.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\winspool.drv" 0170:0174:trace:module:get_load_order got hardcoded default for L"winspool.drv" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\winspool.drv" at 0x1c4ee0000-0x1c4f10000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .text at 0x1c4ee1000 off 1000 size 19000 virt 18c70 flags 60000020 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .data at 0x1c4efa000 off 1a000 size 1000 virt 210 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .rodata at 0x1c4efb000 off 1b000 size 1000 virt 7c0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .rdata at 0x1c4efc000 off 1c000 size 4000 virt 3210 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .pdata at 0x1c4f00000 off 20000 size 1000 virt 930 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .xdata at 0x1c4f01000 off 21000 size 1000 virt bfc flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .bss at 0x1c4f02000 off 0 size 0 virt 450 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .edata at 0x1c4f03000 off 22000 size 3000 virt 28db flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .idata at 0x1c4f06000 off 25000 size 1000 virt f44 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .rsrc at 0x1c4f07000 off 26000 size 8000 virt 78d0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\winspool.drv" section .reloc at 0x1c4f0f000 off 2e000 size 1000 virt 84 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\winspool.drv" 00000000004777D0 00000001C4EE0000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\winspool.drv" at 00000001C4EE0000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\winspool.drv" at 00000001C4EE0000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\comdlg32.dll" 0000000000477320 000000031F800000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\comdlg32.dll" at 000000031F800000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\comdlg32.dll" at 000000031F800000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernelbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"shell32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"urlmon.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\urlmon.dll" 0170:0174:trace:module:get_load_order_value got standard key n,b for L"urlmon" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" at 0x3422e0000-0x34237c000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .text at 0x3422e1000 off 1000 size 55000 virt 54af0 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .data at 0x342336000 off 56000 size 1000 virt 760 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .rodata at 0x342337000 off 57000 size 1000 virt 948 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .rdata at 0x342338000 off 58000 size 17000 virt 164e0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .pdata at 0x34234f000 off 6f000 size 4000 virt 34ec flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .xdata at 0x342353000 off 73000 size 4000 virt 3484 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .bss at 0x342357000 off 0 size 0 virt 1f0 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .edata at 0x342358000 off 77000 size 11000 virt 1037c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .idata at 0x342369000 off 88000 size 3000 virt 27ec flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .rsrc at 0x34236c000 off 8b000 size f000 virt e468 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .reloc at 0x34237b000 off 9a000 size 1000 virt acc flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"oleaut32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\oleaut32.dll" 0170:0174:trace:module:get_load_order_value got standard key b for L"oleaut32" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" at 0x2739c0000-0x273af6000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .text at 0x2739c1000 off 1000 size ab000 virt aa720 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .data at 0x273a6c000 off ac000 size 2000 virt 1100 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rodata at 0x273a6e000 off ae000 size 1000 virt 984 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rdata at 0x273a6f000 off af000 size 1f000 virt 1e700 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .pdata at 0x273a8e000 off ce000 size 6000 virt 57e4 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .xdata at 0x273a94000 off d4000 size 6000 virt 50e4 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .bss at 0x273a9a000 off 0 size 0 virt 38230 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .edata at 0x273ad3000 off da000 size 19000 virt 18c59 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .idata at 0x273aec000 off f3000 size 3000 virt 2aa0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rsrc at 0x273aef000 off f6000 size 5000 virt 4ee0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .reloc at 0x273af4000 off fb000 size 2000 virt 14e4 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"rpcrt4.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\oleaut32.dll" 00000000004795A0 00000002739C0000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\oleaut32.dll" at 00000002739C0000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\oleaut32.dll" at 00000002739C0000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"rpcrt4.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"shell32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"shlwapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"wininet.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\wininet.dll" 0170:0174:trace:module:get_load_order_value got standard key b for L"wininet" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" at 0x3a0440000-0x3a04c3000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .text at 0x3a0441000 off 1000 size 47000 virt 46520 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .data at 0x3a0488000 off 48000 size 1000 virt 450 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .rodata at 0x3a0489000 off 49000 size 1000 virt 854 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .rdata at 0x3a048a000 off 4a000 size c000 virt b330 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .pdata at 0x3a0496000 off 56000 size 2000 virt 19b0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .xdata at 0x3a0498000 off 58000 size 2000 virt 1ebc flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .bss at 0x3a049a000 off 0 size 0 virt 1e0 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .edata at 0x3a049b000 off 5a000 size 5000 virt 49b6 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .idata at 0x3a04a0000 off 5f000 size 2000 virt 1ec8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .rsrc at 0x3a04a2000 off 61000 size 20000 virt 1f3e8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .reloc at 0x3a04c2000 off 81000 size 1000 virt 300 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"mpr.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\mpr.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"mpr.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" at 0x24f470000-0x24f48f000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .text at 0x24f471000 off 1000 size b000 virt a4a0 flags 60000020 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .data at 0x24f47c000 off c000 size 1000 virt c0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .rodata at 0x24f47d000 off d000 size 1000 virt 31c flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .rdata at 0x24f47e000 off e000 size 2000 virt 14a0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .pdata at 0x24f480000 off 10000 size 1000 virt 654 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .xdata at 0x24f481000 off 11000 size 1000 virt 6d4 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .bss at 0x24f482000 off 0 size 0 virt 160 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .edata at 0x24f483000 off 12000 size 2000 virt 19e3 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .idata at 0x24f485000 off 14000 size 1000 virt a00 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .rsrc at 0x24f486000 off 15000 size 8000 virt 77c0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .reloc at 0x24f48e000 off 1d000 size 1000 virt 20 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\mpr.dll" 0000000000479E20 000000024F470000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\mpr.dll" at 000000024F470000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\mpr.dll" at 000000024F470000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"shell32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"shlwapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ws2_32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\ws2_32.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"ws2_32.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" at 0x1ec2b0000-0x1ec2d6000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .text at 0x1ec2b1000 off 1000 size 13000 virt 12500 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .data at 0x1ec2c4000 off 14000 size 1000 virt 1b0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rodata at 0x1ec2c5000 off 15000 size 1000 virt 85c flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rdata at 0x1ec2c6000 off 16000 size 5000 virt 4990 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .pdata at 0x1ec2cb000 off 1b000 size 1000 virt 954 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .xdata at 0x1ec2cc000 off 1c000 size 1000 virt a3c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .bss at 0x1ec2cd000 off 0 size 0 virt 170 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .edata at 0x1ec2ce000 off 1d000 size 3000 virt 23c6 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .idata at 0x1ec2d1000 off 20000 size 1000 virt c14 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rsrc at 0x1ec2d2000 off 21000 size 3000 virt 29b8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .reloc at 0x1ec2d5000 off 24000 size 1000 virt 70 flags 42000040 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ws2_32.dll" 000000000047A2B0 00000001EC2B0000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ws2_32.dll" at 00000001EC2B0000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ws2_32.dll" at 00000001EC2B0000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wininet.dll" 0000000000479B10 00000003A0440000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wininet.dll" at 00000003A0440000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wininet.dll" at 00000003A0440000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\urlmon.dll" 00000000004793C0 00000003422E0000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\urlmon.dll" at 00000003422E0000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\urlmon.dll" at 00000003422E0000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\appwiz.cpl" 0000000000476ED0 00000001C3C60000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\appwiz.cpl" at 00000001C3C60000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\appwiz.cpl" at 00000001C3C60000 0170:0174:trace:module:process_attach (L"appwiz.cpl",0000000000000000) - START 0170:0174:trace:module:process_attach (L"bcrypt.dll",0000000000000000) - START 0170:0174:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_ATTACH,0000000000000000) 00000002D4D49C40 - CALL 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F030, base 000000000031F028. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"bcrypt.dll",0000000000000000) - END 0170:0174:trace:module:process_attach (L"comdlg32.dll",0000000000000000) - START 0170:0174:trace:module:process_attach (L"winspool.drv",0000000000000000) - START 0170:0174:trace:module:MODULE_InitDLL (00000001C4EE0000 L"winspool.drv",PROCESS_ATTACH,0000000000000000) 00000001C4EF90D0 - CALL 0170:0174:trace:module:load_dll looking for L"WINEPS.DRV" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:warn:module:load_dll Failed to load module L"WINEPS.DRV"; status=c0000135 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EFA0, base 000000000031EF98. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E3A0, base 000000000031E398. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:MODULE_InitDLL (00000001C4EE0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"winspool.drv",0000000000000000) - END 0170:0174:trace:module:MODULE_InitDLL (000000031F800000 L"comdlg32.dll",PROCESS_ATTACH,0000000000000000) 000000031F82E950 - CALL 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EB50, base 000000000031EB48. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F040, base 000000000031F038. 0170:0174:trace:module:LdrGetDllHandleEx L"SHELL32.DLL" -> 00000001C69E0000 (load path (null)) 0170:0174:trace:module:MODULE_InitDLL (000000031F800000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"comdlg32.dll",0000000000000000) - END 0170:0174:trace:module:process_attach (L"urlmon.dll",0000000000000000) - START 0170:0174:trace:module:process_attach (L"oleaut32.dll",0000000000000000) - START 0170:0174:trace:module:MODULE_InitDLL (00000002739C0000 L"oleaut32.dll",PROCESS_ATTACH,0000000000000000) 0000000273A6A370 - CALL 0170:0174:trace:process:GetEnvironmentVariableW (L"oanocache" 0000000000000000 0) 0170:0174:trace:module:MODULE_InitDLL (00000002739C0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"oleaut32.dll",0000000000000000) - END 0170:0174:trace:module:process_attach (L"wininet.dll",0000000000000000) - START 0170:0174:trace:module:process_attach (L"mpr.dll",0000000000000000) - START 0170:0174:trace:module:MODULE_InitDLL (000000024F470000 L"mpr.dll",PROCESS_ATTACH,0000000000000000) 000000024F47A960 - CALL 0170:0174:trace:module:MODULE_InitDLL (000000024F470000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"mpr.dll",0000000000000000) - END 0170:0174:trace:module:process_attach (L"ws2_32.dll",0000000000000000) - START 0170:0174:trace:module:MODULE_InitDLL (00000001EC2B0000 L"ws2_32.dll",PROCESS_ATTACH,0000000000000000) 00000001EC2C27C0 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000001EC2B0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"ws2_32.dll",0000000000000000) - END 0170:0174:trace:module:MODULE_InitDLL (00000003A0440000 L"wininet.dll",PROCESS_ATTACH,0000000000000000) 00000003A0486300 - CALL 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EAC0, base 000000000031EAB8. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e38c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e38c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e38c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e38c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e38c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e38c,0x00000004,0x0) 0170:0174:trace:module:MODULE_InitDLL (00000003A0440000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"wininet.dll",0000000000000000) - END 0170:0174:trace:module:MODULE_InitDLL (00000003422E0000 L"urlmon.dll",PROCESS_ATTACH,0000000000000000) 0000000342334800 - CALL 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EB50, base 000000000031EB48. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:MODULE_InitDLL (00000003422E0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"urlmon.dll",0000000000000000) - END 0170:0174:trace:module:MODULE_InitDLL (00000001C3C60000 L"appwiz.cpl",PROCESS_ATTACH,0000000000000000) 00000001C3C658B0 - CALL 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EBF0, base 000000000031EBE8. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:MODULE_InitDLL (00000001C3C60000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"appwiz.cpl",0000000000000000) - END 0170:0174:trace:module:FindResourceExW 00000001C3C60000 #000e #0001 0000 0170:0174:trace:module:LoadResource 00000001C3C60000 00000001C3C839E8 0170:0174:trace:module:FindResourceExW 00000001C3C60000 #0003 #0009 0000 0170:0174:trace:module:LdrGetDllFullName module 00000001C3C60000, name 000000000031F040. 0170:0174:trace:module:LoadResource 00000001C3C60000 00000001C3C82AA8 0170:0174:trace:module:LdrGetDllFullName module 00000001C3C60000, name 000000000031EC80. 0170:0174:trace:module:FindResourceExW 00000001C3C60000 #0006 #0001 0000 0170:0174:trace:module:LoadResource 00000001C3C60000 00000001C3C83638 0170:0174:trace:module:FindResourceExW 00000001C3C60000 #0006 #0001 0000 0170:0174:trace:module:LoadResource 00000001C3C60000 00000001C3C83638 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F990, base 000000000031F988. 0170:0174:trace:module:LdrGetDllHandleEx L"kernel32.dll" -> 000000007B600000 (load path (null)) 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F730, base 000000000031F728. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F270, base 000000000031F268. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EF60, base 000000000031EF58. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:LdrResolveDelayLoadedAPI (00000001C3C60000, 00000001C3C66390, 0000000000000000, 000000007B60C498, 00000001C3C815F4, 0x00000000) 0170:0174:trace:module:load_dll looking for L"msi.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\msi.dll" 0170:0174:trace:module:get_load_order_value got standard key b for L"msi" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" at 0x1f3bb0000-0x1f3cfe000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .text at 0x1f3bb1000 off 1000 size b2000 virt b1210 flags 60000020 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .data at 0x1f3c63000 off b3000 size 1000 virt 710 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .rodata at 0x1f3c64000 off b4000 size 1000 virt 908 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .rdata at 0x1f3c65000 off b5000 size 24000 virt 23970 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .pdata at 0x1f3c89000 off d9000 size 5000 virt 46ec flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .xdata at 0x1f3c8e000 off de000 size 6000 virt 59b0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .bss at 0x1f3c94000 off 0 size 0 virt 290 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .edata at 0x1f3c95000 off e4000 size 16000 virt 150f2 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .idata at 0x1f3cab000 off fa000 size 4000 virt 3758 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .rsrc at 0x1f3caf000 off fe000 size 4e000 virt 4d508 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .reloc at 0x1f3cfd000 off 14c000 size 1000 virt 604 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"cabinet.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\cabinet.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"cabinet.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" at 0x1dc080000-0x1dc09e000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .text at 0x1dc081000 off 1000 size 12000 virt 115d0 flags 60000020 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .data at 0x1dc093000 off 13000 size 1000 virt 90 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .rodata at 0x1dc094000 off 14000 size 1000 virt a4 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .rdata at 0x1dc095000 off 15000 size 2000 virt 1c10 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .pdata at 0x1dc097000 off 17000 size 1000 virt 5b8 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .xdata at 0x1dc098000 off 18000 size 1000 virt 628 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .bss at 0x1dc099000 off 0 size 0 virt 140 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .edata at 0x1dc09a000 off 19000 size 1000 virt 76a flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .idata at 0x1dc09b000 off 1a000 size 1000 virt 5e8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .rsrc at 0x1dc09c000 off 1b000 size 1000 virt 3a8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .reloc at 0x1dc09d000 off 1c000 size 1000 virt 64 flags 42000040 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\cabinet.dll" 000000000047AF30 00000001DC080000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\cabinet.dll" at 00000001DC080000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\cabinet.dll" at 00000001DC080000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"comctl32.dll" in (null) 0170:0174:trace:module:find_dll_file found L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" for L"comctl32.dll" 0170:0174:trace:module:load_dll Found L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" for L"comctl32.dll" at 00000002BB750000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"crypt32.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\crypt32.dll" 0170:0174:trace:module:get_load_order_value got standard key n,b for L"crypt32" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 0x1dd3f0000-0x1dd4be000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .text at 0x1dd3f1000 off 1000 size 63000 virt 62550 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .data at 0x1dd454000 off 64000 size 3000 virt 2640 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rodata at 0x1dd457000 off 67000 size 1000 virt 74c flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rdata at 0x1dd458000 off 68000 size 12000 virt 11830 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .pdata at 0x1dd46a000 off 7a000 size 3000 virt 2958 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .xdata at 0x1dd46d000 off 7d000 size 4000 virt 3260 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .bss at 0x1dd471000 off 0 size 0 virt 32d0 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .edata at 0x1dd475000 off 81000 size 5000 virt 4c9c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .idata at 0x1dd47a000 off 86000 size 2000 virt 1650 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rsrc at 0x1dd47c000 off 88000 size 41000 virt 40f48 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .reloc at 0x1dd4bd000 off c9000 size 1000 virt 514 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"bcrypt.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\bcrypt.dll" for L"bcrypt.dll" at 00000002D4D40000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\crypt32.dll" 000000000047B280 00000001DD3F0000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\crypt32.dll" at 00000001DD3F0000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\crypt32.dll" at 00000001DD3F0000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"gdi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"imagehlp.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\imagehlp.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"imagehlp.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" at 0x2bc640000-0x2bc650000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .text at 0x2bc641000 off 1000 size 5000 virt 40d0 flags 60000020 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .data at 0x2bc646000 off 6000 size 1000 virt a0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .rodata at 0x2bc647000 off 7000 size 1000 virt 2ac flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .rdata at 0x2bc648000 off 8000 size 1000 virt 980 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .pdata at 0x2bc649000 off 9000 size 1000 virt 264 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .xdata at 0x2bc64a000 off a000 size 1000 virt 2f0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .bss at 0x2bc64b000 off 0 size 0 virt 140 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .edata at 0x2bc64c000 off b000 size 2000 virt 195b flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .idata at 0x2bc64e000 off d000 size 1000 virt 6d0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .reloc at 0x2bc64f000 off e000 size 1000 virt 24 flags 42000040 0170:0174:trace:module:load_dll looking for L"dbghelp.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\dbghelp.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"dbghelp.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" at 0x3be590000-0x3be604000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .text at 0x3be591000 off 1000 size 4d000 virt 4c1d0 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .data at 0x3be5de000 off 4e000 size 1000 virt 460 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .rodata at 0x3be5df000 off 4f000 size 1000 virt 89c flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .rdata at 0x3be5e0000 off 50000 size d000 virt ccb0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .pdata at 0x3be5ed000 off 5d000 size 2000 virt 1db8 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .xdata at 0x3be5ef000 off 5f000 size 3000 virt 232c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .bss at 0x3be5f2000 off 0 size 0 virt 8ea0 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .edata at 0x3be5fb000 off 62000 size 5000 virt 430d flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .idata at 0x3be600000 off 67000 size 2000 virt 1050 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .rsrc at 0x3be602000 off 69000 size 1000 virt 3c0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .reloc at 0x3be603000 off 6a000 size 1000 virt 144 flags 42000040 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\dbghelp.dll" 000000000047B980 00000003BE590000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\dbghelp.dll" at 00000003BE590000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\dbghelp.dll" at 00000003BE590000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imagehlp.dll" 000000000047B690 00000002BC640000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imagehlp.dll" at 00000002BC640000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imagehlp.dll" at 00000002BC640000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"mspatcha.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\mspatcha.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"mspatcha.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" at 0x30fbd0000-0x30fbe1000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .text at 0x30fbd1000 off 1000 size 6000 virt 51c0 flags 60000020 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .data at 0x30fbd7000 off 7000 size 1000 virt 90 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .rodata at 0x30fbd8000 off 8000 size 1000 virt 7c flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .rdata at 0x30fbd9000 off 9000 size 1000 virt aa0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .pdata at 0x30fbda000 off a000 size 1000 virt 270 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .xdata at 0x30fbdb000 off b000 size 1000 virt 288 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .bss at 0x30fbdc000 off 0 size 0 virt 140 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .edata at 0x30fbdd000 off c000 size 1000 virt 613 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .idata at 0x30fbde000 off d000 size 1000 virt 650 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .rsrc at 0x30fbdf000 off e000 size 1000 virt 3c8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .reloc at 0x30fbe0000 off f000 size 1000 virt 20 flags 42000040 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\mspatcha.dll" 000000000047BCD0 000000030FBD0000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\mspatcha.dll" at 000000030FBD0000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\mspatcha.dll" at 000000030FBD0000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"odbccp32.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\odbccp32.dll" 0170:0174:trace:module:get_load_order_value got standard key n,b for L"odbccp32" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" at 0x381900000-0x381913000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .text at 0x381901000 off 1000 size 8000 virt 7180 flags 60000020 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .data at 0x381909000 off 9000 size 1000 virt 80 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .rodata at 0x38190a000 off a000 size 1000 virt 4a8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .rdata at 0x38190b000 off b000 size 1000 virt fe0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .pdata at 0x38190c000 off c000 size 1000 virt 3a8 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .xdata at 0x38190d000 off d000 size 1000 virt 498 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .bss at 0x38190e000 off 0 size 0 virt 1e0 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .edata at 0x38190f000 off e000 size 2000 virt 117c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .idata at 0x381911000 off 10000 size 1000 virt 784 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .reloc at 0x381912000 off 11000 size 1000 virt 20 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\odbccp32.dll" 000000000047BFC0 0000000381900000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\odbccp32.dll" at 0000000381900000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\odbccp32.dll" at 0000000381900000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ole32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"oleaut32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\oleaut32.dll" for L"oleaut32.dll" at 00000002739C0000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"shell32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"shlwapi.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"sxs.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\sxs.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"sxs.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" at 0x3543d0000-0x3543e2000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .text at 0x3543d1000 off 1000 size 5000 virt 4a80 flags 60000020 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .data at 0x3543d6000 off 6000 size 1000 virt 90 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .rodata at 0x3543d7000 off 7000 size 1000 virt 1c flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .rdata at 0x3543d8000 off 8000 size 2000 virt 1cc0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .pdata at 0x3543da000 off a000 size 1000 virt 2d0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .xdata at 0x3543db000 off b000 size 1000 virt 340 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .bss at 0x3543dc000 off 0 size 0 virt 140 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .edata at 0x3543dd000 off c000 size 3000 virt 201f flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .idata at 0x3543e0000 off f000 size 1000 virt 878 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .reloc at 0x3543e1000 off 10000 size 1000 virt 54 flags 42000040 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ole32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"oleaut32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\oleaut32.dll" for L"oleaut32.dll" at 00000002739C0000, count=3 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sxs.dll" 000000000047C3F0 00000003543D0000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sxs.dll" at 00000003543D0000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sxs.dll" at 00000003543D0000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"urlmon.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\urlmon.dll" for L"urlmon.dll" at 00000003422E0000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"version.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\version.dll" for L"version.dll" at 00000002F1FA0000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"wininet.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\wininet.dll" for L"wininet.dll" at 00000003A0440000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"wintrust.dll" in (null) 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\wintrust.dll" 0170:0174:trace:module:get_load_order_value got standard key n,b for L"wintrust" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" at 0x1fdfd0000-0x1fdff8000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .text at 0x1fdfd1000 off 1000 size 17000 virt 16330 flags 60000060 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .data at 0x1fdfe8000 off 18000 size 1000 virt 410 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .rodata at 0x1fdfe9000 off 19000 size 1000 virt 604 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .rdata at 0x1fdfea000 off 1a000 size 4000 virt 34e0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .pdata at 0x1fdfee000 off 1e000 size 1000 virt 9cc flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .xdata at 0x1fdfef000 off 1f000 size 1000 virt a8c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .bss at 0x1fdff0000 off 0 size 0 virt 400 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .edata at 0x1fdff1000 off 20000 size 3000 virt 281e flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .idata at 0x1fdff4000 off 23000 size 2000 virt 1240 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .rsrc at 0x1fdff6000 off 25000 size 1000 virt 3b8 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .reloc at 0x1fdff7000 off 26000 size 1000 virt 54 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"crypt32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\crypt32.dll" for L"crypt32.dll" at 00000001DD3F0000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"user32.dll" in (null) 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wintrust.dll" 000000000047E930 00000001FDFD0000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wintrust.dll" at 00000001FDFD0000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wintrust.dll" at 00000001FDFD0000 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msi.dll" 000000000047ACC0 00000001F3BB0000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msi.dll" at 00000001F3BB0000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msi.dll" at 00000001F3BB0000 0170:0174:trace:module:process_attach (L"msi.dll",0000000000000000) - START 0170:0174:trace:module:process_attach (L"cabinet.dll",0000000000000000) - START 0170:0174:trace:module:MODULE_InitDLL (00000001DC080000 L"cabinet.dll",PROCESS_ATTACH,0000000000000000) 00000001DC091A80 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000001DC080000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"cabinet.dll",0000000000000000) - END 0170:0174:trace:module:process_attach (L"crypt32.dll",0000000000000000) - START 0170:0174:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_ATTACH,0000000000000000) 00000001DD4524D0 - CALL 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0170:0174:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0170:0174:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F300, base 000000000031F2F8. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"crypt32.dll",0000000000000000) - END 0170:0174:trace:module:process_attach (L"imagehlp.dll",0000000000000000) - START 0170:0174:trace:module:process_attach (L"dbghelp.dll",0000000000000000) - START 0170:0174:trace:module:MODULE_InitDLL (00000003BE590000 L"dbghelp.dll",PROCESS_ATTACH,0000000000000000) 00000003BE5DC0A0 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000003BE590000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"dbghelp.dll",0000000000000000) - END 0170:0174:trace:module:MODULE_InitDLL (00000002BC640000 L"imagehlp.dll",PROCESS_ATTACH,0000000000000000) 00000002BC644570 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000002BC640000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"imagehlp.dll",0000000000000000) - END 0170:0174:trace:module:process_attach (L"mspatcha.dll",0000000000000000) - START 0170:0174:trace:module:MODULE_InitDLL (000000030FBD0000 L"mspatcha.dll",PROCESS_ATTACH,0000000000000000) 000000030FBD5650 - CALL 0170:0174:trace:module:MODULE_InitDLL (000000030FBD0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"mspatcha.dll",0000000000000000) - END 0170:0174:trace:module:process_attach (L"odbccp32.dll",0000000000000000) - START 0170:0174:trace:module:MODULE_InitDLL (0000000381900000 L"odbccp32.dll",PROCESS_ATTACH,0000000000000000) 0000000381907640 - CALL 0170:0174:trace:module:MODULE_InitDLL (0000000381900000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"odbccp32.dll",0000000000000000) - END 0170:0174:trace:module:process_attach (L"sxs.dll",0000000000000000) - START 0170:0174:trace:module:MODULE_InitDLL (00000003543D0000 L"sxs.dll",PROCESS_ATTACH,0000000000000000) 00000003543D4F30 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000003543D0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"sxs.dll",0000000000000000) - END 0170:0174:trace:module:process_attach (L"wintrust.dll",0000000000000000) - START 0170:0174:trace:module:MODULE_InitDLL (00000001FDFD0000 L"wintrust.dll",PROCESS_ATTACH,0000000000000000) 00000001FDFE63D0 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000001FDFD0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"wintrust.dll",0000000000000000) - END 0170:0174:trace:module:MODULE_InitDLL (00000001F3BB0000 L"msi.dll",PROCESS_ATTACH,0000000000000000) 00000001F3C60C20 - CALL 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f408,0x00000008,0x0) 0170:0174:trace:module:MODULE_InitDLL (00000001F3BB0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"msi.dll",0000000000000000) - END 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F710, base 000000000031F708. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F400, base 000000000031F3F8. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031ECD0, base 000000000031ECC8. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:fixme:file:NtLockFile I/O completion on lock not implemented yet 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E950, base 000000000031E948. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:process:GetEnvironmentVariableW (L"TMP" 000000000031E690 260) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:fixme:ntdll:NtQuerySystemInformation info_class SYSTEM_PERFORMANCE_INFORMATION 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000003,0x31e610,0x00000060,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e29c,0x00000004,0x0) 0170:0174:trace:process:GetEnvironmentVariableW (L"TMP" 000000000031E5E0 260) 0170:0174:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000000000 0) 0170:0174:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000BBE6B0 10) 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E500, base 000000000031E4F8. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E200, base 000000000031E1F8. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000494AE0 257) 0170:0174:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000494AE0 257) 0170:0174:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000000000 0) 0170:0174:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000BBE6B0 10) 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031ED00, base 000000000031ECF8. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:load_dll looking for L"C:\\windows\\system32\\mscoree.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:get_load_order looking for L"C:\\windows\\system32\\mscoree.dll" 0170:0174:trace:module:get_load_order got hardcoded default for L"mscoree.dll" 0170:0174:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" at 0x356770000-0x3567aa000 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .text at 0x356771000 off 1000 size 14000 virt 13c10 flags 60000020 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .data at 0x356785000 off 15000 size 1000 virt 2c0 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .rodata at 0x356786000 off 16000 size 1000 virt 820 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .rdata at 0x356787000 off 17000 size c000 virt bbc0 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .pdata at 0x356793000 off 23000 size 1000 virt f30 flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .xdata at 0x356794000 off 24000 size 1000 virt e3c flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .bss at 0x356795000 off 0 size 0 virt 330 flags c0000080 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .edata at 0x356796000 off 25000 size 10000 virt ff5a flags 40000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .idata at 0x3567a6000 off 35000 size 2000 virt 1018 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .rsrc at 0x3567a8000 off 37000 size 1000 virt e78 flags c0000040 0170:0174:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .reloc at 0x3567a9000 off 38000 size 1000 virt 238 flags 42000040 0170:0174:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"dbghelp.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\dbghelp.dll" for L"dbghelp.dll" at 00000003BE590000, count=2 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"shell32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"shlwapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0170:0174:trace:module:import_dll is not hybrid module 0170:0174:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\mscoree.dll" 0000000000494CD0 0000000356770000 0170:0174:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\mscoree.dll" at 0000000356770000: builtin 0170:0174:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\mscoree.dll" at 0000000356770000 0170:0174:trace:module:process_attach (L"mscoree.dll",0000000000000000) - START 0170:0174:trace:module:MODULE_InitDLL (0000000356770000 L"mscoree.dll",PROCESS_ATTACH,0000000000000000) 0000000356783CA0 - CALL 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E610, base 000000000031E608. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:MODULE_InitDLL (0000000356770000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0170:0174:trace:module:process_attach (L"mscoree.dll",0000000000000000) - END 0170:0174:err:mscoree:LoadLibraryShim flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E650, base 000000000031E648. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) error reading registry key for installroot 0170:0174:trace:module:load_dll looking for L"fusion.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:warn:module:load_dll Failed to load module L"fusion.dll"; status=c0000135 0170:0174:err:mscoree:LoadLibraryShim error reading registry key for installroot 0170:0174:trace:module:load_dll looking for L"fusion.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:warn:module:load_dll Failed to load module L"fusion.dll"; status=c0000135 0170:0174:err:mscoree:LoadLibraryShim error reading registry key for installroot 0170:0174:trace:module:load_dll looking for L"fusion.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:warn:module:load_dll Failed to load module L"fusion.dll"; status=c0000135 0170:0174:err:mscoree:LoadLibraryShim error reading registry key for installroot 0170:0174:trace:module:load_dll looking for L"fusion.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:warn:module:load_dll Failed to load module L"fusion.dll"; status=c0000135 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 005c:0114:trace:module:LdrShutdownThread () 005c:0114:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",THREAD_DETACH,0000000000000000) 00000003AFD0B870 - CALL 005c:0114:trace:module:MODULE_InitDLL (00000003AFD00000,THREAD_DETACH,0000000000000000) - RETURN 1 005c:0114:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",THREAD_DETACH,0000000000000000) 000000023D8C5690 - CALL 005c:0114:trace:module:MODULE_InitDLL (000000023D820000,THREAD_DETACH,0000000000000000) - RETURN 1 005c:0114:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_DETACH,0000000000000000) 0000000231B26040 - CALL 005c:0114:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_DETACH,0000000000000000) - RETURN 1 005c:0114:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_DETACH,0000000000000000) 00000003AF6F1C30 - CALL 005c:0114:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_DETACH,0000000000000000) - RETURN 1 005c:0114:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_DETACH,0000000000000000) 00000001C8E1AB00 - CALL 005c:0114:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_DETACH,0000000000000000) - RETURN 1 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0030:0050:trace:module:LdrShutdownThread () 0030:0050:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_DETACH,0000000000000000) 0000000231B26040 - CALL 0030:0050:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:0050:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_DETACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:0050:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:0050:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_DETACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:0050:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:0040:trace:module:LdrShutdownThread () 0030:0040:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_DETACH,0000000000000000) 0000000231B26040 - CALL 0030:0040:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:0040:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_DETACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:0040:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:0040:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_DETACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:0040:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_DETACH,0000000000000000) - RETURN 1 0074:0084:trace:process:NtQueryInformationProcess (0x70,0x00000000,0x440d08,0x00000030,0x0) 0074:0084:trace:process:NtQueryInformationProcess (0x70,0x0000001a,0x12cf258,0x00000008,0x0) 0170:0174:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E420, base 000000000031E418. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:process:CreateProcessInternalW app (null) cmdline L"msiexec /i C:\\windows\\mono\\mono-2.0\\support\\\\winemono-support.msi" 0170:0174:trace:process:find_exe_file looking for L"msiexec" in L"C:\\windows\\system32;.;C:\\windows\\system32;C:\\windows\\system;C:\\windows;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0170:0174:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\msiexec.exe" image L"C:\\windows\\system32\\msiexec.exe" cmdline L"msiexec /i C:\\windows\\mono\\mono-2.0\\support\\\\winemono-support.msi" parent 0x0 0170:0174:trace:process:send_to_cx_loader loader (null) wineserversocket 12 stdin_fd 0 stdout_fd 1 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 0170:0174:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\msiexec.exe" 0178:017c:trace:module:get_load_order_value got standard key b for L"*msiexec.exe" 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\msiexec.exe" 0178:017c:trace:module:get_load_order_value got standard key b for L"*msiexec.exe" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\msiexec.exe" at 0x140000000-0x14001b000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msiexec.exe" section .text at 0x140001000 off 1000 size 6000 virt 5920 flags 60000020 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msiexec.exe" section .data at 0x140007000 off 7000 size 1000 virt 50 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msiexec.exe" section .rdata at 0x140008000 off 8000 size 1000 virt c40 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msiexec.exe" section .pdata at 0x140009000 off 9000 size 1000 virt 1ec flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msiexec.exe" section .xdata at 0x14000a000 off a000 size 1000 virt 1f4 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msiexec.exe" section .bss at 0x14000b000 off 0 size 0 virt 180 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msiexec.exe" section .idata at 0x14000c000 off b000 size 1000 virt d10 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msiexec.exe" section .rsrc at 0x14000d000 off c000 size d000 virt cb00 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\msiexec.exe" section .reloc at 0x14001a000 off 19000 size 1000 virt 10 flags 42000040 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0178:017c:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0170:0174:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\msiexec.exe" pid 0178 tid 017c handles 0xac/0xb0 0170:0174:trace:process:CreateProcessInternalW started process pid 0178 tid 017c 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msiexec.exe" 00000000004329A0 0000000140000000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msiexec.exe" at 0000000140000000: builtin 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernel32.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"kernel32.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0178:017c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernelbase.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"kernelbase.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 0000000000433090 000000007B000000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000432DA0 000000007B600000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\advapi32.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"advapi32.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvcrt.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"msvcrt.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 0000000000435480 00000001C8DB0000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"sechost.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\sechost.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"sechost.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\ucrtbase.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"ucrtbase.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 00000000004344A0 00000003AF670000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 0000000000434270 000000032A700000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 0000000000433D30 0000000330260000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"comctl32.dll" in (null) 0178:017c:trace:module:find_dll_file found L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" for L"comctl32.dll" 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" at 0x2bb750000-0x2bb88f000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .text at 0x2bb751000 off 1000 size ae000 virt ad9d0 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .data at 0x2bb7ff000 off af000 size 1000 virt 300 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .rodata at 0x2bb800000 off b0000 size 1000 virt 734 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .rdata at 0x2bb801000 off b1000 size 1f000 virt 1ef80 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .pdata at 0x2bb820000 off d0000 size 4000 virt 3198 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .xdata at 0x2bb824000 off d4000 size 5000 virt 40a8 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .bss at 0x2bb829000 off 0 size 0 virt 1720 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .edata at 0x2bb82b000 off d9000 size f000 virt eff3 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .idata at 0x2bb83a000 off e8000 size 4000 virt 3b2c flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .rsrc at 0x2bb83e000 off ec000 size 50000 virt 4fad8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" section .reloc at 0x2bb88e000 off 13c000 size 1000 virt 1d4 flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\gdi32.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"gdi32.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\user32.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"user32.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=4 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"sechost.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"version.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\version.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"version.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 00000000004367C0 00000002F1FA0000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 00000002F1FA0000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 00000002F1FA0000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"win32u.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\win32u.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"win32u.dll" 0178:017c:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\win32u.dll" is a fake Wine dll 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\win32u.dll" 0000000000436B10 000000006B560000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\win32u.dll" at 000000006B560000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\win32u.dll" at 000000006B560000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\user32.dll" 00000000004363B0 000000023D820000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\user32.dll" at 000000023D820000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\user32.dll" at 000000023D820000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"win32u.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006B560000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\gdi32.dll" 0000000000434A00 000000026B4C0000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"imm32.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\imm32.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"imm32.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=5 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imm32.dll" 0000000000436E20 00000003AFD00000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imm32.dll" at 00000003AFD00000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imm32.dll" at 00000003AFD00000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=11 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=6 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=13 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=6 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=3 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" 0000000000434790 00000002BB750000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" at 00000002BB750000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" at 00000002BB750000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=12 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"msi.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\msi.dll" 0178:017c:trace:module:get_load_order_value got standard key b for L"msi" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" at 0x1f3bb0000-0x1f3cfe000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .text at 0x1f3bb1000 off 1000 size b2000 virt b1210 flags 60000020 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .data at 0x1f3c63000 off b3000 size 1000 virt 710 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .rodata at 0x1f3c64000 off b4000 size 1000 virt 908 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .rdata at 0x1f3c65000 off b5000 size 24000 virt 23970 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .pdata at 0x1f3c89000 off d9000 size 5000 virt 46ec flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .xdata at 0x1f3c8e000 off de000 size 6000 virt 59b0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .bss at 0x1f3c94000 off 0 size 0 virt 290 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .edata at 0x1f3c95000 off e4000 size 16000 virt 150f2 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .idata at 0x1f3cab000 off fa000 size 4000 virt 3758 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .rsrc at 0x1f3caf000 off fe000 size 4e000 virt 4d508 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" section .reloc at 0x1f3cfd000 off 14c000 size 1000 virt 604 flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=6 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"cabinet.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\cabinet.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"cabinet.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" at 0x1dc080000-0x1dc09e000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .text at 0x1dc081000 off 1000 size 12000 virt 115d0 flags 60000020 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .data at 0x1dc093000 off 13000 size 1000 virt 90 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .rodata at 0x1dc094000 off 14000 size 1000 virt a4 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .rdata at 0x1dc095000 off 15000 size 2000 virt 1c10 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .pdata at 0x1dc097000 off 17000 size 1000 virt 5b8 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .xdata at 0x1dc098000 off 18000 size 1000 virt 628 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .bss at 0x1dc099000 off 0 size 0 virt 140 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .edata at 0x1dc09a000 off 19000 size 1000 virt 76a flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .idata at 0x1dc09b000 off 1a000 size 1000 virt 5e8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .rsrc at 0x1dc09c000 off 1b000 size 1000 virt 3a8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" section .reloc at 0x1dc09d000 off 1c000 size 1000 virt 64 flags 42000040 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=13 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=14 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=7 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\cabinet.dll" 0000000000437480 00000001DC080000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\cabinet.dll" at 00000001DC080000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\cabinet.dll" at 00000001DC080000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"comctl32.dll" in (null) 0178:017c:trace:module:find_dll_file found L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" for L"comctl32.dll" 0178:017c:trace:module:load_dll Found L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" for L"comctl32.dll" at 00000002BB750000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"crypt32.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\crypt32.dll" 0178:017c:trace:module:get_load_order_value got standard key n,b for L"crypt32" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 0x1dd3f0000-0x1dd4be000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .text at 0x1dd3f1000 off 1000 size 63000 virt 62550 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .data at 0x1dd454000 off 64000 size 3000 virt 2640 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rodata at 0x1dd457000 off 67000 size 1000 virt 74c flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rdata at 0x1dd458000 off 68000 size 12000 virt 11830 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .pdata at 0x1dd46a000 off 7a000 size 3000 virt 2958 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .xdata at 0x1dd46d000 off 7d000 size 4000 virt 3260 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .bss at 0x1dd471000 off 0 size 0 virt 32d0 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .edata at 0x1dd475000 off 81000 size 5000 virt 4c9c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .idata at 0x1dd47a000 off 86000 size 2000 virt 1650 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rsrc at 0x1dd47c000 off 88000 size 41000 virt 40f48 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .reloc at 0x1dd4bd000 off c9000 size 1000 virt 514 flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=7 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"bcrypt.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\bcrypt.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"bcrypt.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 0x2d4d40000-0x2d4d57000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .text at 0x2d4d41000 off 1000 size a000 virt 97c0 flags 60000020 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .data at 0x2d4d4b000 off b000 size 1000 virt 70 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rodata at 0x2d4d4c000 off c000 size 1000 virt 3b8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rdata at 0x2d4d4d000 off d000 size 2000 virt 1c40 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .pdata at 0x2d4d4f000 off f000 size 1000 virt 420 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .xdata at 0x2d4d50000 off 10000 size 1000 virt 52c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .bss at 0x2d4d51000 off 0 size 0 virt 170 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .edata at 0x2d4d52000 off 11000 size 2000 virt 1317 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .idata at 0x2d4d54000 off 13000 size 1000 virt 6cc flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rsrc at 0x2d4d55000 off 14000 size 1000 virt 3c0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .reloc at 0x2d4d56000 off 15000 size 1000 virt 44 flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=8 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=14 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=15 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=8 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\bcrypt.dll" 0000000000437AE0 00000002D4D40000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\bcrypt.dll" at 00000002D4D40000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\bcrypt.dll" at 00000002D4D40000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=15 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=16 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=9 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=4 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\crypt32.dll" 00000000004377D0 00000001DD3F0000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\crypt32.dll" at 00000001DD3F0000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\crypt32.dll" at 00000001DD3F0000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"imagehlp.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\imagehlp.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"imagehlp.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" at 0x2bc640000-0x2bc650000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .text at 0x2bc641000 off 1000 size 5000 virt 40d0 flags 60000020 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .data at 0x2bc646000 off 6000 size 1000 virt a0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .rodata at 0x2bc647000 off 7000 size 1000 virt 2ac flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .rdata at 0x2bc648000 off 8000 size 1000 virt 980 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .pdata at 0x2bc649000 off 9000 size 1000 virt 264 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .xdata at 0x2bc64a000 off a000 size 1000 virt 2f0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .bss at 0x2bc64b000 off 0 size 0 virt 140 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .edata at 0x2bc64c000 off b000 size 2000 virt 195b flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .idata at 0x2bc64e000 off d000 size 1000 virt 6d0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" section .reloc at 0x2bc64f000 off e000 size 1000 virt 24 flags 42000040 0178:017c:trace:module:load_dll looking for L"dbghelp.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\dbghelp.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"dbghelp.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" at 0x3be590000-0x3be604000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .text at 0x3be591000 off 1000 size 4d000 virt 4c1d0 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .data at 0x3be5de000 off 4e000 size 1000 virt 460 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .rodata at 0x3be5df000 off 4f000 size 1000 virt 89c flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .rdata at 0x3be5e0000 off 50000 size d000 virt ccb0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .pdata at 0x3be5ed000 off 5d000 size 2000 virt 1db8 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .xdata at 0x3be5ef000 off 5f000 size 3000 virt 232c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .bss at 0x3be5f2000 off 0 size 0 virt 8ea0 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .edata at 0x3be5fb000 off 62000 size 5000 virt 430d flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .idata at 0x3be600000 off 67000 size 2000 virt 1050 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .rsrc at 0x3be602000 off 69000 size 1000 virt 3c0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" section .reloc at 0x3be603000 off 6a000 size 1000 virt 144 flags 42000040 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=16 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=17 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=10 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\dbghelp.dll" 00000000004381E0 00000003BE590000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\dbghelp.dll" at 00000003BE590000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\dbghelp.dll" at 00000003BE590000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=17 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=18 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=11 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imagehlp.dll" 0000000000437EF0 00000002BC640000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imagehlp.dll" at 00000002BC640000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imagehlp.dll" at 00000002BC640000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=18 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"mspatcha.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\mspatcha.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"mspatcha.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" at 0x30fbd0000-0x30fbe1000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .text at 0x30fbd1000 off 1000 size 6000 virt 51c0 flags 60000020 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .data at 0x30fbd7000 off 7000 size 1000 virt 90 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .rodata at 0x30fbd8000 off 8000 size 1000 virt 7c flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .rdata at 0x30fbd9000 off 9000 size 1000 virt aa0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .pdata at 0x30fbda000 off a000 size 1000 virt 270 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .xdata at 0x30fbdb000 off b000 size 1000 virt 288 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .bss at 0x30fbdc000 off 0 size 0 virt 140 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .edata at 0x30fbdd000 off c000 size 1000 virt 613 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .idata at 0x30fbde000 off d000 size 1000 virt 650 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .rsrc at 0x30fbdf000 off e000 size 1000 virt 3c8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" section .reloc at 0x30fbe0000 off f000 size 1000 virt 20 flags 42000040 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=19 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=19 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=12 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\mspatcha.dll" 0000000000438530 000000030FBD0000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\mspatcha.dll" at 000000030FBD0000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\mspatcha.dll" at 000000030FBD0000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=20 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"odbccp32.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\odbccp32.dll" 0178:017c:trace:module:get_load_order_value got standard key n,b for L"odbccp32" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" at 0x381900000-0x381913000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .text at 0x381901000 off 1000 size 8000 virt 7180 flags 60000020 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .data at 0x381909000 off 9000 size 1000 virt 80 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .rodata at 0x38190a000 off a000 size 1000 virt 4a8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .rdata at 0x38190b000 off b000 size 1000 virt fe0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .pdata at 0x38190c000 off c000 size 1000 virt 3a8 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .xdata at 0x38190d000 off d000 size 1000 virt 498 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .bss at 0x38190e000 off 0 size 0 virt 1e0 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .edata at 0x38190f000 off e000 size 2000 virt 117c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .idata at 0x381911000 off 10000 size 1000 virt 784 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" section .reloc at 0x381912000 off 11000 size 1000 virt 20 flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=9 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=20 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=21 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=13 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\odbccp32.dll" 0000000000438820 0000000381900000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\odbccp32.dll" at 0000000381900000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\odbccp32.dll" at 0000000381900000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ole32.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\ole32.dll" 0178:017c:trace:module:get_load_order_value got standard key b for L"ole32" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" at 0x2e8f10000-0x2e902b000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .text at 0x2e8f11000 off 1000 size a8000 virt a76a0 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .data at 0x2e8fb9000 off a9000 size 1000 virt 480 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rodata at 0x2e8fba000 off aa000 size 1000 virt 778 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rdata at 0x2e8fbb000 off ab000 size 1e000 virt 1d750 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .pdata at 0x2e8fd9000 off c9000 size 7000 virt 6b10 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .xdata at 0x2e8fe0000 off d0000 size 7000 virt 67c4 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .bss at 0x2e8fe7000 off 0 size 0 virt 210 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .edata at 0x2e8fe8000 off d7000 size 18000 virt 17412 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .idata at 0x2e9000000 off ef000 size 4000 virt 367c flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rsrc at 0x2e9004000 off f3000 size 25000 virt 24bc0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .reloc at 0x2e9029000 off 118000 size 2000 virt 1804 flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=10 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"combase.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\combase.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"combase.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" at 0x327020000-0x327073000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .text at 0x327021000 off 1000 size 27000 virt 26590 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .data at 0x327048000 off 28000 size 1000 virt 580 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rodata at 0x327049000 off 29000 size 2000 virt 16c0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rdata at 0x32704b000 off 2b000 size d000 virt cf90 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .pdata at 0x327058000 off 38000 size 2000 virt 17a0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .xdata at 0x32705a000 off 3a000 size 2000 virt 18e4 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .bss at 0x32705c000 off 0 size 0 virt 1a0 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .edata at 0x32705d000 off 3c000 size 13000 virt 12d6e flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .idata at 0x327070000 off 4f000 size 2000 virt 1804 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .reloc at 0x327072000 off 51000 size 1000 virt 23c flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=11 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=3 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=21 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=22 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ole32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\rpcrt4.dll" 0178:017c:trace:module:get_load_order_value got standard key b for L"rpcrt4" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0x231ae0000-0x231b62000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .text at 0x231ae1000 off 1000 size 47000 virt 46400 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .data at 0x231b28000 off 48000 size 1000 virt 710 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rodata at 0x231b29000 off 49000 size 2000 virt 1b44 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rdata at 0x231b2b000 off 4b000 size 15000 virt 14b90 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .pdata at 0x231b40000 off 60000 size 3000 virt 2334 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .xdata at 0x231b43000 off 63000 size 3000 virt 289c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .bss at 0x231b46000 off 0 size 0 virt 690 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .edata at 0x231b47000 off 66000 size 17000 virt 16730 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .idata at 0x231b5e000 off 7d000 size 2000 virt 19a8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rsrc at 0x231b60000 off 7f000 size 1000 virt 3a8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .reloc at 0x231b61000 off 80000 size 1000 virt 504 flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=12 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=22 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=23 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=14 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rpcrt4.dll" 00000000004391B0 0000000231AE0000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\rpcrt4.dll" at 0000000231AE0000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=15 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=5 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\combase.dll" 0000000000438E20 0000000327020000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\combase.dll" at 0000000327020000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\combase.dll" at 0000000327020000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=4 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=23 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=7 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=24 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=16 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=6 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ole32.dll" 0000000000438B50 00000002E8F10000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ole32.dll" at 00000002E8F10000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ole32.dll" at 00000002E8F10000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"oleaut32.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\oleaut32.dll" 0178:017c:trace:module:get_load_order_value got standard key b for L"oleaut32" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" at 0x2739c0000-0x273af6000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .text at 0x2739c1000 off 1000 size ab000 virt aa720 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .data at 0x273a6c000 off ac000 size 2000 virt 1100 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rodata at 0x273a6e000 off ae000 size 1000 virt 984 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rdata at 0x273a6f000 off af000 size 1f000 virt 1e700 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .pdata at 0x273a8e000 off ce000 size 6000 virt 57e4 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .xdata at 0x273a94000 off d4000 size 6000 virt 50e4 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .bss at 0x273a9a000 off 0 size 0 virt 38230 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .edata at 0x273ad3000 off da000 size 19000 virt 18c59 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .idata at 0x273aec000 off f3000 size 3000 virt 2aa0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .rsrc at 0x273aef000 off f6000 size 5000 virt 4ee0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" section .reloc at 0x273af4000 off fb000 size 2000 virt 14e4 flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=13 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=5 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=24 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=25 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ole32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=3 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=17 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=7 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\oleaut32.dll" 00000000004396C0 00000002739C0000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\oleaut32.dll" at 00000002739C0000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\oleaut32.dll" at 00000002739C0000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=4 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"shell32.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\shell32.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"shell32.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" at 0x1c69e0000-0x1c72fe000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .text at 0x1c69e1000 off 1000 size 89000 virt 88c60 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .data at 0x1c6a6a000 off 8a000 size 2000 virt 13e0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rodata at 0x1c6a6c000 off 8c000 size 2000 virt 18ec flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rdata at 0x1c6a6e000 off 8e000 size 29000 virt 28e90 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .pdata at 0x1c6a97000 off b7000 size 6000 virt 5748 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .xdata at 0x1c6a9d000 off bd000 size 6000 virt 5c20 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .bss at 0x1c6aa3000 off 0 size 0 virt 570 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .edata at 0x1c6aa4000 off c3000 size 15000 virt 14070 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .idata at 0x1c6ab9000 off d8000 size 5000 virt 4aa0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rsrc at 0x1c6abe000 off dd000 size 83e000 virt 83d918 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .reloc at 0x1c72fc000 off 91b000 size 2000 virt 1264 flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=14 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=6 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=25 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=26 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"shlwapi.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\shlwapi.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"shlwapi.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" at 0x2e3540000-0x2e3591000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .text at 0x2e3541000 off 1000 size 1e000 virt 1dac0 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .data at 0x2e355f000 off 1f000 size 1000 virt 210 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rodata at 0x2e3560000 off 20000 size 2000 virt 18fc flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rdata at 0x2e3562000 off 22000 size b000 virt a290 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .pdata at 0x2e356d000 off 2d000 size 2000 virt 11b8 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .xdata at 0x2e356f000 off 2f000 size 2000 virt 13a8 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .bss at 0x2e3571000 off 0 size 0 virt 1c0 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .edata at 0x2e3572000 off 31000 size 14000 virt 13ab5 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .idata at 0x2e3586000 off 45000 size 5000 virt 442c flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rsrc at 0x2e358b000 off 4a000 size 5000 virt 4ed0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .reloc at 0x2e3590000 off 4f000 size 1000 virt e0 flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=15 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=7 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=26 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=8 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=27 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"shcore.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\shcore.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"shcore.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" at 0x3126f0000-0x312709000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .text at 0x3126f1000 off 1000 size 9000 virt 8b70 flags 60000020 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .data at 0x3126fa000 off a000 size 1000 virt b0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rodata at 0x3126fb000 off b000 size 1000 virt fb4 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rdata at 0x3126fc000 off c000 size 3000 virt 2360 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .pdata at 0x3126ff000 off f000 size 1000 virt 57c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .xdata at 0x312700000 off 10000 size 1000 virt 61c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .bss at 0x312701000 off 0 size 0 virt 160 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .edata at 0x312702000 off 11000 size 5000 virt 480e flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .idata at 0x312707000 off 16000 size 1000 virt c74 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .reloc at 0x312708000 off 17000 size 1000 virt a8 flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=16 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=27 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=28 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ole32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=3 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=18 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=8 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shcore.dll" 000000000043A210 00000003126F0000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shcore.dll" at 00000003126F0000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shcore.dll" at 00000003126F0000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=19 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=9 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shlwapi.dll" 0000000000439E80 00000002E3540000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shlwapi.dll" at 00000002E3540000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shlwapi.dll" at 00000002E3540000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=20 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=10 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\shell32.dll" 0000000000439B30 00000001C69E0000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\shell32.dll" at 00000001C69E0000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\shell32.dll" at 00000001C69E0000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"shlwapi.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"sxs.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\sxs.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"sxs.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" at 0x3543d0000-0x3543e2000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .text at 0x3543d1000 off 1000 size 5000 virt 4a80 flags 60000020 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .data at 0x3543d6000 off 6000 size 1000 virt 90 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .rodata at 0x3543d7000 off 7000 size 1000 virt 1c flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .rdata at 0x3543d8000 off 8000 size 2000 virt 1cc0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .pdata at 0x3543da000 off a000 size 1000 virt 2d0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .xdata at 0x3543db000 off b000 size 1000 virt 340 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .bss at 0x3543dc000 off 0 size 0 virt 140 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .edata at 0x3543dd000 off c000 size 3000 virt 201f flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .idata at 0x3543e0000 off f000 size 1000 virt 878 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" section .reloc at 0x3543e1000 off 10000 size 1000 virt 54 flags 42000040 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=28 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=29 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ole32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=4 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"oleaut32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\oleaut32.dll" for L"oleaut32.dll" at 00000002739C0000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=21 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sxs.dll" 000000000043A720 00000003543D0000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sxs.dll" at 00000003543D0000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sxs.dll" at 00000003543D0000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=22 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"urlmon.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\urlmon.dll" 0178:017c:trace:module:get_load_order_value got standard key n,b for L"urlmon" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" at 0x3422e0000-0x34237c000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .text at 0x3422e1000 off 1000 size 55000 virt 54af0 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .data at 0x342336000 off 56000 size 1000 virt 760 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .rodata at 0x342337000 off 57000 size 1000 virt 948 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .rdata at 0x342338000 off 58000 size 17000 virt 164e0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .pdata at 0x34234f000 off 6f000 size 4000 virt 34ec flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .xdata at 0x342353000 off 73000 size 4000 virt 3484 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .bss at 0x342357000 off 0 size 0 virt 1f0 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .edata at 0x342358000 off 77000 size 11000 virt 1037c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .idata at 0x342369000 off 88000 size 3000 virt 27ec flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .rsrc at 0x34236c000 off 8b000 size f000 virt e468 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" section .reloc at 0x34237b000 off 9a000 size 1000 virt acc flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=17 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=29 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=30 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ole32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=5 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"oleaut32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\oleaut32.dll" for L"oleaut32.dll" at 00000002739C0000, count=3 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=5 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"shell32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"shlwapi.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=3 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=23 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=11 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"wininet.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\wininet.dll" 0178:017c:trace:module:get_load_order_value got standard key b for L"wininet" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" at 0x3a0440000-0x3a04c3000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .text at 0x3a0441000 off 1000 size 47000 virt 46520 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .data at 0x3a0488000 off 48000 size 1000 virt 450 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .rodata at 0x3a0489000 off 49000 size 1000 virt 854 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .rdata at 0x3a048a000 off 4a000 size c000 virt b330 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .pdata at 0x3a0496000 off 56000 size 2000 virt 19b0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .xdata at 0x3a0498000 off 58000 size 2000 virt 1ebc flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .bss at 0x3a049a000 off 0 size 0 virt 1e0 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .edata at 0x3a049b000 off 5a000 size 5000 virt 49b6 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .idata at 0x3a04a0000 off 5f000 size 2000 virt 1ec8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .rsrc at 0x3a04a2000 off 61000 size 20000 virt 1f3e8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" section .reloc at 0x3a04c2000 off 81000 size 1000 virt 300 flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=18 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=30 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"mpr.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\mpr.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"mpr.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" at 0x24f470000-0x24f48f000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .text at 0x24f471000 off 1000 size b000 virt a4a0 flags 60000020 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .data at 0x24f47c000 off c000 size 1000 virt c0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .rodata at 0x24f47d000 off d000 size 1000 virt 31c flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .rdata at 0x24f47e000 off e000 size 2000 virt 14a0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .pdata at 0x24f480000 off 10000 size 1000 virt 654 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .xdata at 0x24f481000 off 11000 size 1000 virt 6d4 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .bss at 0x24f482000 off 0 size 0 virt 160 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .edata at 0x24f483000 off 12000 size 2000 virt 19e3 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .idata at 0x24f485000 off 14000 size 1000 virt a00 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .rsrc at 0x24f486000 off 15000 size 8000 virt 77c0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" section .reloc at 0x24f48e000 off 1d000 size 1000 virt 20 flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=19 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=31 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=31 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=24 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=12 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\mpr.dll" 000000000043B2D0 000000024F470000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\mpr.dll" at 000000024F470000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\mpr.dll" at 000000024F470000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=32 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"shell32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=3 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"shlwapi.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=4 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=25 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=13 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ws2_32.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\ws2_32.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"ws2_32.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" at 0x1ec2b0000-0x1ec2d6000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .text at 0x1ec2b1000 off 1000 size 13000 virt 12500 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .data at 0x1ec2c4000 off 14000 size 1000 virt 1b0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rodata at 0x1ec2c5000 off 15000 size 1000 virt 85c flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rdata at 0x1ec2c6000 off 16000 size 5000 virt 4990 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .pdata at 0x1ec2cb000 off 1b000 size 1000 virt 954 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .xdata at 0x1ec2cc000 off 1c000 size 1000 virt a3c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .bss at 0x1ec2cd000 off 0 size 0 virt 170 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .edata at 0x1ec2ce000 off 1d000 size 3000 virt 23c6 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .idata at 0x1ec2d1000 off 20000 size 1000 virt c14 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .rsrc at 0x1ec2d2000 off 21000 size 3000 virt 29b8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" section .reloc at 0x1ec2d5000 off 24000 size 1000 virt 70 flags 42000040 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=32 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=33 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=26 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ws2_32.dll" 000000000043B760 00000001EC2B0000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ws2_32.dll" at 00000001EC2B0000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ws2_32.dll" at 00000001EC2B0000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wininet.dll" 000000000043AFC0 00000003A0440000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wininet.dll" at 00000003A0440000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wininet.dll" at 00000003A0440000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\urlmon.dll" 000000000043AAF0 00000003422E0000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\urlmon.dll" at 00000003422E0000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\urlmon.dll" at 00000003422E0000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=14 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"version.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\version.dll" for L"version.dll" at 00000002F1FA0000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"wininet.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\wininet.dll" for L"wininet.dll" at 00000003A0440000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"wintrust.dll" in (null) 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\wintrust.dll" 0178:017c:trace:module:get_load_order_value got standard key n,b for L"wintrust" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" at 0x1fdfd0000-0x1fdff8000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .text at 0x1fdfd1000 off 1000 size 17000 virt 16330 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .data at 0x1fdfe8000 off 18000 size 1000 virt 410 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .rodata at 0x1fdfe9000 off 19000 size 1000 virt 604 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .rdata at 0x1fdfea000 off 1a000 size 4000 virt 34e0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .pdata at 0x1fdfee000 off 1e000 size 1000 virt 9cc flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .xdata at 0x1fdfef000 off 1f000 size 1000 virt a8c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .bss at 0x1fdff0000 off 0 size 0 virt 400 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .edata at 0x1fdff1000 off 20000 size 3000 virt 281e flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .idata at 0x1fdff4000 off 23000 size 2000 virt 1240 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .rsrc at 0x1fdff6000 off 25000 size 1000 virt 3b8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" section .reloc at 0x1fdff7000 off 26000 size 1000 virt 54 flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=20 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"crypt32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\crypt32.dll" for L"crypt32.dll" at 00000001DD3F0000, count=2 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=33 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=34 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=27 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=15 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wintrust.dll" 000000000043BB30 00000001FDFD0000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wintrust.dll" at 00000001FDFD0000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wintrust.dll" at 00000001FDFD0000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msi.dll" 0000000000437270 00000001F3BB0000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msi.dll" at 00000001F3BB0000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msi.dll" at 00000001F3BB0000 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=35 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ole32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=6 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=28 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in (null) 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=16 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 0178:017c:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 0178:017c:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 0178:017c:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 0178:017c:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 0178:017c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 0178:017c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 000000000043E080 17) 0178:017c:trace:module:LdrGetDllHandleEx flags 0, load_path 000000000043E190, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0178:017c:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0178:017c:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0178:017c:trace:module:LoadResource 0000000010000002 00000000100077D8 0178:017c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 0178:017c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 000000000043E0D0 17) 0178:017c:trace:module:LdrGetDllHandleEx flags 0, load_path 000000000043E2B0, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0178:017c:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0178:017c:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0178:017c:trace:module:LoadResource 0000000010000002 00000000100077D8 0178:017c:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 0178:017c:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 0178:017c:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 0178:017c:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 0178:017c:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 0178:017c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F3B0. 0178:017c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\msiexec.exe" 0178:017c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F400. 0178:017c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\msiexec.exe" 0178:017c:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0178:017c:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 0178:017c:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 0178:017c:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 0178:017c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 0178:017c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\msiexec.exe" 0178:017c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 0178:017c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\msiexec.exe" 0178:017c:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 0178:017c:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 0178:017c:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 0178:017c:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 0178:017c:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 0178:017c:trace:module:process_attach (L"comctl32.dll",000000000031FB00) - START 0178:017c:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - START 0178:017c:trace:module:process_attach (L"user32.dll",000000000031FB00) - START 0178:017c:trace:module:process_attach (L"version.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000031FB00) 00000002F1FA2510 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"version.dll",000000000031FB00) - END 0178:017c:trace:module:process_attach (L"win32u.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (000000006B560000 L"win32u.dll",PROCESS_ATTACH,000000000031FB00) 000000006B609460 - CALL 0178:017c:trace:module:MODULE_InitDLL (000000006B560000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"win32u.dll",000000000031FB00) - END 0178:017c:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000031FB00) 000000023D8C5690 - CALL 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F0A0, base 000000000031F098. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031ED90, base 000000000031ED88. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:load_dll looking for L"imm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\imm32.dll" for L"imm32.dll" at 00000003AFD00000, count=2 0178:017c:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 0178:017c:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EB20, base 000000000031EB18. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EFC0, base 000000000031EFB8. 0178:017c:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 0178:017c:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0178:017c:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 0178:017c:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"user32.dll",000000000031FB00) - END 0178:017c:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000031FB00) 000000026B509F00 - CALL 0178:017c:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - END 0178:017c:trace:module:MODULE_InitDLL (00000002BB750000 L"comctl32.dll",PROCESS_ATTACH,000000000031FB00) 00000002BB7FDA80 - CALL 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F120, base 000000000031F118. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:load_dll looking for L"winemac.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\winemac.drv" 0178:017c:trace:module:get_load_order got hardcoded default for L"winemac.drv" 0178:017c:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\winemac.drv" is a fake Wine dll 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"win32u.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006B560000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\winemac.drv" 0000000000445F70 000000006B4B0000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\winemac.drv" at 000000006B4B0000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\winemac.drv" at 000000006B4B0000 0178:017c:trace:module:process_attach (L"winemac.drv",0000000000000000) - START 0178:017c:trace:module:MODULE_InitDLL (000000006B4B0000 L"winemac.drv",PROCESS_ATTACH,0000000000000000) 000000006B4D3C10 - CALL 0178:017c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031B7D0. 0178:017c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\msiexec.exe" 0178:017c:trace:module:FindResourceExW 000000006B4B0000 #0006 #0011 0000 0178:017c:trace:module:LoadResource 000000006B4B0000 000000006B5399D8 0178:017c:trace:module:FindResourceExW 000000006B4B0000 #0006 #0011 0000 0178:017c:trace:module:LoadResource 000000006B4B0000 000000006B5399D8 0178:017c:trace:module:FindResourceExW 000000006B4B0000 #0006 #0011 0000 0178:017c:trace:module:LoadResource 000000006B4B0000 000000006B5399D8 0178:017c:trace:module:FindResourceExW 000000006B4B0000 #0006 #0011 0000 0178:017c:trace:module:LoadResource 000000006B4B0000 000000006B5399D8 0178:017c:trace:module:FindResourceExW 000000006B4B0000 #0006 #0011 0000 0178:017c:trace:module:LoadResource 000000006B4B0000 000000006B5399D8 0178:017c:trace:module:FindResourceExW 000000006B4B0000 #0006 #0011 0000 0178:017c:trace:module:LoadResource 000000006B4B0000 000000006B5399D8 0178:017c:trace:module:FindResourceExW 000000006B4B0000 #0006 #0011 0000 0178:017c:trace:module:LoadResource 000000006B4B0000 000000006B5399D8 0178:017c:trace:module:FindResourceExW 000000006B4B0000 #0006 #0012 0000 0178:017c:trace:module:LoadResource 000000006B4B0000 000000006B539BC8 0178:017c:trace:module:FindResourceExW 000000006B4B0000 #0006 #0012 0000 0178:017c:trace:module:LoadResource 000000006B4B0000 000000006B539BC8 0178:017c:trace:module:FindResourceExW 000000006B4B0000 #0006 #0012 0000 0178:017c:trace:module:LoadResource 000000006B4B0000 000000006B539BC8 0178:017c:trace:module:FindResourceExW 000000006B4B0000 #0006 #0012 0000 0178:017c:trace:module:LoadResource 000000006B4B0000 000000006B539BC8 0178:017c:trace:module:FindResourceExW 000000006B4B0000 #0006 #0012 0000 0178:017c:trace:module:LoadResource 000000006B4B0000 000000006B539BC8 0178:017c:trace:module:MODULE_InitDLL (000000006B4B0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0178:017c:trace:module:process_attach (L"winemac.drv",0000000000000000) - END 0178:017c:trace:module:EnumResourceNamesExW 0000000000000000 #000e 000000006B4CAB00 31d068 0178:017c:trace:module:FindResourceExW 0000000140000000 #000e #0001 0000 0178:017c:trace:module:LoadResource 0000000000000000 000000014000D2B0 0178:017c:trace:module:FindResourceExW 0000000000000000 #0003 #000a 0000 0178:017c:trace:module:LoadResource 0000000000000000 000000014000D2A0 0178:017c:trace:module:FindResourceExW 0000000000000000 #0003 #0009 0000 0178:017c:trace:module:LoadResource 0000000000000000 000000014000D290 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C7F0, base 000000000031C7E8. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:FindResourceExW 0000000000000000 #0003 #0008 0000 0178:017c:trace:module:LoadResource 0000000000000000 000000014000D280 0178:017c:trace:module:FindResourceExW 0000000000000000 #0003 #0003 0000 0178:017c:trace:module:LoadResource 0000000000000000 000000014000D230 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0178:017c:trace:module:LoadResource 000000023D820000 000000023D908880 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C4D0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f01 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4C0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0009 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0178:017c:trace:module:LoadResource 000000023D820000 000000023D9088E0 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C4D0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C890. 0178:017c:trace:module:load_dll looking for L"uxtheme.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\uxtheme.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"uxtheme.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 0x2f7230000-0x2f7265000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .text at 0x2f7231000 off 1000 size 13000 virt 123c0 flags 60000060 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .data at 0x2f7244000 off 14000 size 1000 virt 110 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rodata at 0x2f7245000 off 15000 size 1000 virt 430 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rdata at 0x2f7246000 off 16000 size 16000 virt 15a30 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .pdata at 0x2f725c000 off 2c000 size 1000 virt 87c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .xdata at 0x2f725d000 off 2d000 size 1000 virt 97c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .bss at 0x2f725e000 off 0 size 0 virt 4a0 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .edata at 0x2f725f000 off 2e000 size 2000 virt 1de0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .idata at 0x2f7261000 off 30000 size 2000 virt 14ac flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rsrc at 0x2f7263000 off 32000 size 1000 virt 5f8 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .reloc at 0x2f7264000 off 33000 size 1000 virt bc flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"gdi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\uxtheme.dll" 00000000004464C0 00000002F7230000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\uxtheme.dll" at 00000002F7230000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 00000002F7230000 0178:017c:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - START 0178:017c:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_ATTACH,0000000000000000) 00000002F72424B0 - CALL 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C6C0, base 000000000031C6B8. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C870, base 000000000031C868. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000004466E0, dll_characteristics 0000000000000000, name 000000000031CA90, base 000000000031CA28. 0178:017c:trace:module:LdrGetDllHandleEx L"C:\\windows\\resources\\themes\\light\\light.msstyles" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0178:017c:trace:module:FindResourceExW 0000000000F10001 L"PACKTHEM_VERSION" #0001 0000 0178:017c:trace:module:LoadResource 0000000000F10001 0000000000F15310 0178:017c:trace:module:FindResourceExW 0000000000F10001 L"COLORNAMES" #0001 0000 0178:017c:trace:module:LoadResource 0000000000F10001 0000000000F152F0 0178:017c:trace:module:FindResourceExW 0000000000F10001 L"SIZENAMES" #0001 0000 0178:017c:trace:module:LoadResource 0000000000F10001 0000000000F15320 0178:017c:trace:module:FindResourceExW 0000000000F10001 L"FILERESNAMES" #0001 0000 0178:017c:trace:module:LoadResource 0000000000F10001 0000000000F15300 0178:017c:trace:module:FindResourceExW 0000000000F10001 L"TEXTFILE" L"BLUE_INI" 0000 0178:017c:trace:module:LoadResource 0000000000F10001 0000000000F15330 0178:017c:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0178:017c:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - END 0178:017c:trace:module:load_dll looking for L"winemac.drv" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\winemac.drv" for L"winemac.drv" at 000000006B4B0000, count=2 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f01 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4C0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0009 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFE0. 0178:017c:trace:module:FindResourceExW 00000002BB750000 #000e #0016 0000 0178:017c:trace:module:LoadResource 00000002BB750000 00000002BB8406B0 0178:017c:trace:module:FindResourceExW 00000002BB750000 #0003 #0002 0000 0178:017c:trace:module:LoadResource 00000002BB750000 00000002BB83F310 0178:017c:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031EC70. 0178:017c:trace:module:FindResourceExW 00000002BB750000 #000e #0019 0000 0178:017c:trace:module:LoadResource 00000002BB750000 00000002BB8406C0 0178:017c:trace:module:FindResourceExW 00000002BB750000 #0003 #0003 0000 0178:017c:trace:module:LoadResource 00000002BB750000 00000002BB83F320 0178:017c:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031EC70. 0178:017c:trace:module:FindResourceExW 00000002BB750000 #000e #001c 0000 0178:017c:trace:module:LoadResource 00000002BB750000 00000002BB8406D0 0178:017c:trace:module:FindResourceExW 00000002BB750000 #0003 #0004 0000 0178:017c:trace:module:LoadResource 00000002BB750000 00000002BB83F330 0178:017c:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031EC70. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0178:017c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0178:017c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0178:017c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFF0. 0178:017c:trace:module:MODULE_InitDLL (00000002BB750000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"comctl32.dll",000000000031FB00) - END 0178:017c:trace:module:process_attach (L"msi.dll",000000000031FB00) - START 0178:017c:trace:module:process_attach (L"cabinet.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (00000001DC080000 L"cabinet.dll",PROCESS_ATTACH,000000000031FB00) 00000001DC091A80 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000001DC080000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"cabinet.dll",000000000031FB00) - END 0178:017c:trace:module:process_attach (L"crypt32.dll",000000000031FB00) - START 0178:017c:trace:module:process_attach (L"bcrypt.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_ATTACH,000000000031FB00) 00000002D4D49C40 - CALL 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F4E0, base 000000000031F4D8. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"bcrypt.dll",000000000031FB00) - END 0178:017c:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_ATTACH,000000000031FB00) 00000001DD4524D0 - CALL 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0178:017c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F570, base 000000000031F568. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"crypt32.dll",000000000031FB00) - END 0178:017c:trace:module:process_attach (L"imagehlp.dll",000000000031FB00) - START 0178:017c:trace:module:process_attach (L"dbghelp.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (00000003BE590000 L"dbghelp.dll",PROCESS_ATTACH,000000000031FB00) 00000003BE5DC0A0 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000003BE590000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"dbghelp.dll",000000000031FB00) - END 0178:017c:trace:module:MODULE_InitDLL (00000002BC640000 L"imagehlp.dll",PROCESS_ATTACH,000000000031FB00) 00000002BC644570 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000002BC640000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"imagehlp.dll",000000000031FB00) - END 0178:017c:trace:module:process_attach (L"mspatcha.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (000000030FBD0000 L"mspatcha.dll",PROCESS_ATTACH,000000000031FB00) 000000030FBD5650 - CALL 0178:017c:trace:module:MODULE_InitDLL (000000030FBD0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"mspatcha.dll",000000000031FB00) - END 0178:017c:trace:module:process_attach (L"odbccp32.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (0000000381900000 L"odbccp32.dll",PROCESS_ATTACH,000000000031FB00) 0000000381907640 - CALL 0178:017c:trace:module:MODULE_InitDLL (0000000381900000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"odbccp32.dll",000000000031FB00) - END 0178:017c:trace:module:process_attach (L"ole32.dll",000000000031FB00) - START 0178:017c:trace:module:process_attach (L"combase.dll",000000000031FB00) - START 0178:017c:trace:module:process_attach (L"rpcrt4.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_ATTACH,000000000031FB00) 0000000231B26040 - CALL 0178:017c:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"rpcrt4.dll",000000000031FB00) - END 0178:017c:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_ATTACH,000000000031FB00) 00000003270465C0 - CALL 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EFF0, base 000000000031EFE8. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"combase.dll",000000000031FB00) - END 0178:017c:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_ATTACH,000000000031FB00) 00000002E8FB74E0 - CALL 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F0A0, base 000000000031F098. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"ole32.dll",000000000031FB00) - END 0178:017c:trace:module:process_attach (L"oleaut32.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (00000002739C0000 L"oleaut32.dll",PROCESS_ATTACH,000000000031FB00) 0000000273A6A370 - CALL 0178:017c:trace:process:GetEnvironmentVariableW (L"oanocache" 0000000000000000 0) 0178:017c:trace:module:MODULE_InitDLL (00000002739C0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"oleaut32.dll",000000000031FB00) - END 0178:017c:trace:module:process_attach (L"shell32.dll",000000000031FB00) - START 0178:017c:trace:module:process_attach (L"shlwapi.dll",000000000031FB00) - START 0178:017c:trace:module:process_attach (L"shcore.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_ATTACH,000000000031FB00) 00000003126F8FD0 - CALL 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EF80, base 000000000031EF78. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"shcore.dll",000000000031FB00) - END 0178:017c:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_ATTACH,000000000031FB00) 00000002E355DE00 - CALL 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F010, base 000000000031F008. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"shlwapi.dll",000000000031FB00) - END 0178:017c:trace:module:MODULE_InitDLL (00000001C69E0000 L"shell32.dll",PROCESS_ATTACH,000000000031FB00) 00000001C6A688D0 - CALL 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F0A0, base 000000000031F098. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:LdrGetDllFullName module 00000001C69E0000, name 000000000031F5C0. 0178:017c:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\shell32.dll" 0178:017c:trace:module:MODULE_InitDLL (00000001C69E0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"shell32.dll",000000000031FB00) - END 0178:017c:trace:module:process_attach (L"sxs.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (00000003543D0000 L"sxs.dll",PROCESS_ATTACH,000000000031FB00) 00000003543D4F30 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000003543D0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"sxs.dll",000000000031FB00) - END 0178:017c:trace:module:process_attach (L"urlmon.dll",000000000031FB00) - START 0178:017c:trace:module:process_attach (L"wininet.dll",000000000031FB00) - START 0178:017c:trace:module:process_attach (L"mpr.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (000000024F470000 L"mpr.dll",PROCESS_ATTACH,000000000031FB00) 000000024F47A960 - CALL 0178:017c:trace:module:MODULE_InitDLL (000000024F470000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"mpr.dll",000000000031FB00) - END 0178:017c:trace:module:process_attach (L"ws2_32.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (00000001EC2B0000 L"ws2_32.dll",PROCESS_ATTACH,000000000031FB00) 00000001EC2C27C0 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000001EC2B0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"ws2_32.dll",000000000031FB00) - END 0178:017c:trace:module:MODULE_InitDLL (00000003A0440000 L"wininet.dll",PROCESS_ATTACH,000000000031FB00) 00000003A0486300 - CALL 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F000, base 000000000031EFF8. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8cc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8cc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8cc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8cc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8cc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e8cc,0x00000004,0x0) 0178:017c:trace:module:MODULE_InitDLL (00000003A0440000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"wininet.dll",000000000031FB00) - END 0178:017c:trace:module:MODULE_InitDLL (00000003422E0000 L"urlmon.dll",PROCESS_ATTACH,000000000031FB00) 0000000342334800 - CALL 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F090, base 000000000031F088. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:MODULE_InitDLL (00000003422E0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"urlmon.dll",000000000031FB00) - END 0178:017c:trace:module:process_attach (L"wintrust.dll",000000000031FB00) - START 0178:017c:trace:module:MODULE_InitDLL (00000001FDFD0000 L"wintrust.dll",PROCESS_ATTACH,000000000031FB00) 00000001FDFE63D0 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000001FDFD0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"wintrust.dll",000000000031FB00) - END 0178:017c:trace:module:MODULE_InitDLL (00000001F3BB0000 L"msi.dll",PROCESS_ATTACH,000000000031FB00) 00000001F3C60C20 - CALL 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f678,0x00000008,0x0) 0178:017c:trace:module:MODULE_InitDLL (00000001F3BB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0178:017c:trace:module:process_attach (L"msi.dll",000000000031FB00) - END 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F9F0, base 000000000031F9E8. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F580, base 000000000031F578. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F510, base 000000000031F508. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F320, base 000000000031F318. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EDF0, base 000000000031EDE8. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:fixme:file:NtLockFile I/O completion on lock not implemented yet 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EA70, base 000000000031EA68. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:process:GetEnvironmentVariableW (L"TMP" 000000000031E7B0 260) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:fixme:ntdll:NtQuerySystemInformation info_class SYSTEM_PERFORMANCE_INFORMATION 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000003,0x31e730,0x00000060,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000000c,0x31e3bc,0x00000004,0x0) 0178:017c:trace:process:GetEnvironmentVariableW (L"TMP" 000000000031E700 260) 0178:017c:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000000000 0) 0178:017c:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000BBCA40 10) 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E620, base 000000000031E618. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E320, base 000000000031E318. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 000000000048DD60 257) 0178:017c:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 000000000048DD60 257) 0178:017c:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000000000 0) 0178:017c:trace:process:GetEnvironmentVariableW (L"WINEUSERNAME" 0000000000BBCA40 10) 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EE20, base 000000000031EE18. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:load_dll looking for L"C:\\windows\\system32\\mscoree.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:get_load_order looking for L"C:\\windows\\system32\\mscoree.dll" 0178:017c:trace:module:get_load_order got hardcoded default for L"mscoree.dll" 0178:017c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" at 0x356770000-0x3567aa000 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .text at 0x356771000 off 1000 size 14000 virt 13c10 flags 60000020 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .data at 0x356785000 off 15000 size 1000 virt 2c0 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .rodata at 0x356786000 off 16000 size 1000 virt 820 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .rdata at 0x356787000 off 17000 size c000 virt bbc0 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .pdata at 0x356793000 off 23000 size 1000 virt f30 flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .xdata at 0x356794000 off 24000 size 1000 virt e3c flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .bss at 0x356795000 off 0 size 0 virt 330 flags c0000080 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .edata at 0x356796000 off 25000 size 10000 virt ff5a flags 40000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .idata at 0x3567a6000 off 35000 size 2000 virt 1018 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .rsrc at 0x3567a8000 off 37000 size 1000 virt e78 flags c0000040 0178:017c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" section .reloc at 0x3567a9000 off 38000 size 1000 virt 238 flags 42000040 0178:017c:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"dbghelp.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\dbghelp.dll" for L"dbghelp.dll" at 00000003BE590000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ole32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"shell32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\shell32.dll" for L"shell32.dll" at 00000001C69E0000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"shlwapi.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\shlwapi.dll" for L"shlwapi.dll" at 00000002E3540000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0178:017c:trace:module:import_dll is not hybrid module 0178:017c:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\mscoree.dll" 000000000048DF50 0000000356770000 0178:017c:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\mscoree.dll" at 0000000356770000: builtin 0178:017c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\mscoree.dll" at 0000000356770000 0178:017c:trace:module:process_attach (L"mscoree.dll",0000000000000000) - START 0178:017c:trace:module:MODULE_InitDLL (0000000356770000 L"mscoree.dll",PROCESS_ATTACH,0000000000000000) 0000000356783CA0 - CALL 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E730, base 000000000031E728. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:MODULE_InitDLL (0000000356770000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0178:017c:trace:module:process_attach (L"mscoree.dll",0000000000000000) - END 0178:017c:err:mscoree:LoadLibraryShim flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E770, base 000000000031E768. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) error reading registry key for installroot 0178:017c:trace:module:load_dll looking for L"fusion.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:warn:module:load_dll Failed to load module L"fusion.dll"; status=c0000135 0178:017c:err:mscoree:LoadLibraryShim error reading registry key for installroot 0178:017c:trace:module:load_dll looking for L"fusion.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:warn:module:load_dll Failed to load module L"fusion.dll"; status=c0000135 0178:017c:err:mscoree:LoadLibraryShim error reading registry key for installroot 0178:017c:trace:module:load_dll looking for L"fusion.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:warn:module:load_dll Failed to load module L"fusion.dll"; status=c0000135 0178:017c:err:mscoree:LoadLibraryShim error reading registry key for installroot 0178:017c:trace:module:load_dll looking for L"fusion.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:warn:module:load_dll Failed to load module L"fusion.dll"; status=c0000135 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004e 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB1008 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0049 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0958 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004f 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB1208 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0074:0084:trace:process:NtQueryInformationProcess (0x70,0x00000000,0x440df8,0x00000030,0x0) 0074:0084:trace:process:NtQueryInformationProcess (0x70,0x0000001a,0x12cf258,0x00000008,0x0) 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031E540, base 000000000031E538. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:process:CreateProcessInternalW app (null) cmdline L"\"C:\\windows\\mono\\mono-2.0\\support\\\\installinf-x86.exe\" \"C:\\windows\\mono\\mono-2.0\\support\\\\dotnetfakedlls.inf\"" 0178:017c:trace:process:find_exe_file looking for L"C:\\windows\\mono\\mono-2.0\\support\\\\installinf-x86.exe" in L"C:\\windows\\system32;.;C:\\windows\\system32;C:\\windows\\system;C:\\windows;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0178:017c:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" image L"C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" cmdline L"\"C:\\windows\\mono\\mono-2.0\\support\\\\installinf-x86.exe\" \"C:\\windows\\mono\\mono-2.0\\support\\\\dotnetfakedlls.inf\"" parent 0x0 0178:017c:trace:process:send_to_cx_loader loader (null) wineserversocket 11 stdin_fd 0 stdout_fd 1 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 0178:017c:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0180:0184:trace:module:get_load_order looking for L"C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" 0180:0184:trace:module:get_load_order got main exe default n,b for L"C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" 0180:0184:trace:module:get_load_order looking for L"C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" 0180:0184:trace:module:get_load_order got main exe default n,b for L"C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" 0180:0184:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" at 0x400000-0x408000 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" section .text at 0x401000 off 400 size 1600 virt 154e flags 60000020 0180:0184:trace:module:map_image_into_view clearing 0x402600 - 0x403000 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" section .rdata at 0x403000 off 1a00 size c00 virt af3 flags 40000040 0180:0184:trace:module:map_image_into_view clearing 0x403c00 - 0x404000 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" section .buildid at 0x404000 off 2600 size 200 virt 56 flags 40000040 0180:0184:trace:module:map_image_into_view clearing 0x404200 - 0x405000 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" section .data at 0x405000 off 2800 size 200 virt 108 flags c0000040 0180:0184:trace:module:map_image_into_view clearing 0x405200 - 0x406000 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" section .tls at 0x406000 off 2a00 size 200 virt 8 flags c0000040 0180:0184:trace:module:map_image_into_view clearing 0x406200 - 0x407000 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" section .reloc at 0x407000 off 2c00 size 400 virt 270 flags 42000040 0180:0184:trace:module:map_image_into_view clearing 0x407400 - 0x408000 0180:0184:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0180:0184:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\syswow64\\ntdll.dll" at 0x7bc00000-0x7bc97000 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .text at 0x7bc01000 off 1000 size 66000 virt 652b8 flags 60000020 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .data at 0x7bc67000 off 67000 size 1000 virt b60 flags c0000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .rodata at 0x7bc68000 off 68000 size 2000 virt 1ff4 flags c0000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .rdata at 0x7bc6a000 off 6a000 size 11000 virt 10568 flags 40000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .bss at 0x7bc7b000 off 0 size 0 virt 24e4 flags c0000080 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .edata at 0x7bc7e000 off 7b000 size 13000 virt 12769 flags 40000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .idata at 0x7bc91000 off 8e000 size 1000 virt 14 flags c0000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .rsrc at 0x7bc92000 off 8f000 size 1000 virt 3ac flags c0000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .reloc at 0x7bc93000 off 90000 size 4000 virt 3e18 flags 42000040 0180:0184:trace:module:load_wow64_ntdll loaded L"\\??\\C:\\windows\\syswow64\\ntdll.dll" at 0x7bc00000 0180:0184:fixme:module:dlopen_32on64_opengl32 loaded "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_32on64-unix/opengl32.dll.so" early @ 0x69958000 0180:0184:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x131000 0178:017c:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" pid 0180 tid 0184 handles 0xa8/0xac 0178:017c:trace:process:CreateProcessInternalW started process pid 0180 tid 0184 0180:0184:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x60f790,0x00000040,0x0) 0180:0184:trace:module:build_module loaded L"\\??\\C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" 0000000000712A90 0000000000400000 0180:0184:trace:loaddll:build_module Loaded L"C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" at 0000000000400000: native 0180:0184:trace:module:load_dll looking for L"C:\\windows\\system32\\wow64.dll" in (null) 0180:0184:trace:module:get_load_order looking for L"C:\\windows\\system32\\wow64.dll" 0180:0184:trace:module:get_load_order got hardcoded default for L"wow64.dll" 0180:0184:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\wow64.dll" at 0x6f000000-0x6f026000 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .text at 0x6f001000 off 1000 size 12000 virt 11ab0 flags 60000020 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .data at 0x6f013000 off 13000 size 1000 virt 840 flags c0000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .rodata at 0x6f014000 off 14000 size 1000 virt 2a8 flags c0000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .rdata at 0x6f015000 off 15000 size 3000 virt 2c70 flags 40000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .pdata at 0x6f018000 off 18000 size 1000 virt d68 flags 40000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .xdata at 0x6f019000 off 19000 size 1000 virt d5c flags 40000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .bss at 0x6f01a000 off 0 size 0 virt 4160 flags c0000080 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .edata at 0x6f01f000 off 1a000 size 3000 virt 2c2c flags 40000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .idata at 0x6f022000 off 1d000 size 3000 virt 2908 flags c0000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .reloc at 0x6f025000 off 20000 size 1000 virt 3f8 flags 42000040 0180:0184:trace:module:load_dll looking for L"ntdll.dll" in (null) 0180:0184:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0180:0184:trace:module:import_dll is not hybrid module 0180:0184:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wow64.dll" 0000000000712F30 000000006F000000 0180:0184:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wow64.dll" at 000000006F000000: builtin 0180:0184:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wow64.dll" at 000000006F000000 0180:0184:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000060F3C0, base 000000000060F3B0. 0180:0184:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0180:0184:trace:module:load_dll looking for L"\\??\\C:\\windows\\system32\\wow64cpu.dll" in (null) 0180:0184:trace:module:get_load_order looking for L"C:\\windows\\system32\\wow64cpu.dll" 0180:0184:trace:module:get_load_order got hardcoded default for L"wow64cpu.dll" 0180:0184:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\wow64cpu.dll" at 0x6f100000-0x6f10c000 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .text at 0x6f101000 off 1000 size 1000 virt 7c0 flags 60000020 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .data at 0x6f102000 off 2000 size 1000 virt 40 flags c0000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .rodata at 0x6f103000 off 3000 size 1000 virt 24 flags c0000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .rdata at 0x6f104000 off 4000 size 1000 virt a0 flags 40000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .pdata at 0x6f105000 off 5000 size 1000 virt 84 flags 40000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .xdata at 0x6f106000 off 6000 size 1000 virt 5c flags 40000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .bss at 0x6f107000 off 0 size 0 virt 2000 flags c0000080 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .edata at 0x6f109000 off 7000 size 1000 virt 21e flags 40000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .idata at 0x6f10a000 off 8000 size 1000 virt 21c flags c0000040 0180:0184:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .reloc at 0x6f10b000 off 9000 size 1000 virt 1c flags 42000040 0180:0184:trace:module:load_dll looking for L"ntdll.dll" in (null) 0180:0184:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0180:0184:trace:module:import_dll is not hybrid module 0180:0184:trace:module:load_dll looking for L"wow64.dll" in (null) 0180:0184:trace:module:load_dll Found L"C:\\windows\\system32\\wow64.dll" for L"wow64.dll" at 000000006F000000, count=2 0180:0184:trace:module:import_dll is not hybrid module 0180:0184:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wow64cpu.dll" 0000000000713160 000000006F100000 0180:0184:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wow64cpu.dll" at 000000006F100000: builtin 0180:0184:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wow64cpu.dll" at 000000006F100000 0180:0184:trace:module:process_attach (L"wow64cpu.dll",0000000000000000) - START 0180:0184:trace:module:process_attach (L"wow64.dll",0000000000000000) - START 0180:0184:trace:module:MODULE_InitDLL (000000006F000000 L"wow64.dll",PROCESS_ATTACH,0000000000000000) 000000006F012780 - CALL 0180:0184:trace:module:MODULE_InitDLL (000000006F000000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0180:0184:trace:module:process_attach (L"wow64.dll",0000000000000000) - END 0180:0184:trace:module:MODULE_InitDLL (000000006F100000 L"wow64cpu.dll",PROCESS_ATTACH,0000000000000000) 000000006F101790 - CALL 0180:0184:trace:module:MODULE_InitDLL (000000006F100000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0180:0184:trace:module:process_attach (L"wow64cpu.dll",0000000000000000) - END 0180:0184:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x60ef70,0x00000040,0x0) 0180:0184:trace:module:build_module loaded L"\\??\\C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" 00822820 00400000 0180:0184:trace:loaddll:build_module Loaded L"C:\\windows\\mono\\mono-2.0\\support\\installinf-x86.exe" at 00400000: native 0180:0184:trace:module:load_dll looking for L"kernel32.dll" in (null) 0180:0184:warn:module:load_dll Failed to load module L"kernel32.dll"; status=c0000135 wine: could not load kernel32.dll, status c0000135 0178:017c:trace:process:NtQueryInformationProcess (0xa8,0x00000000,0x31eed0,0x00000030,0x0) 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:err:msi:execute_script flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EB60, base 000000000031EB58. 0178:017c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) Execution of script 0 halted; action L"INSTALLFAKEDLLS" returned 1627 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:err:msi:ITERATE_Actions Execution halted, action L"InstallFinalize" returned 1627 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:fixme:msi:internal_ui_handler internal UI not implemented for message 0x0b000000 (UI level = 5) 0178:017c:fixme:msi:internal_ui_handler internal UI not implemented for message 0x0b000000 (UI level = 5) 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0049 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0958 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0049 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0958 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004e 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB1008 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004e 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB1008 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0049 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0958 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004f 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB1208 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0048 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB07F8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0046 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0518 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004c 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0B18 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0178:017c:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0178:017c:trace:module:LdrUnloadDll (0000000356770000) 0178:017c:trace:module:LdrUnloadDll (L"mscoree.dll") - START 0178:017c:trace:module:MODULE_DecRefCount (L"mscoree.dll") ldr.LoadCount: 0 0178:017c:trace:module:MODULE_InitDLL (0000000356770000 L"mscoree.dll",PROCESS_DETACH,0000000000000000) 0000000356783CA0 - CALL 0178:017c:trace:module:MODULE_InitDLL (0000000356770000,PROCESS_DETACH,0000000000000000) - RETURN 1 0178:017c:trace:module:free_modref unloading L"C:\\windows\\system32\\mscoree.dll" 0178:017c:trace:module:LdrUnloadDll END 0178:017c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FD50, base 000000000031FD48. 0178:017c:trace:module:LdrGetDllHandleEx L"mscoree" -> 0000000000000000 (load path (null)) 0178:017c:trace:module:LdrShutdownProcess () 0178:017c:trace:module:MODULE_InitDLL (00000001F3BB0000 L"msi.dll",PROCESS_DETACH,0000000000000001) 00000001F3C60C20 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000001F3BB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000001FDFD0000 L"wintrust.dll",PROCESS_DETACH,0000000000000001) 00000001FDFE63D0 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000001FDFD0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000003422E0000 L"urlmon.dll",PROCESS_DETACH,0000000000000001) 0000000342334800 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000003422E0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000003A0440000 L"wininet.dll",PROCESS_DETACH,0000000000000001) 00000003A0486300 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000003A0440000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000001EC2B0000 L"ws2_32.dll",PROCESS_DETACH,0000000000000001) 00000001EC2C27C0 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000001EC2B0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (000000024F470000 L"mpr.dll",PROCESS_DETACH,0000000000000001) 000000024F47A960 - CALL 0178:017c:trace:module:MODULE_InitDLL (000000024F470000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000003543D0000 L"sxs.dll",PROCESS_DETACH,0000000000000001) 00000003543D4F30 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000003543D0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000001C69E0000 L"shell32.dll",PROCESS_DETACH,0000000000000001) 00000001C6A688D0 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000001C69E0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_DETACH,0000000000000001) 00000002E355DE00 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_DETACH,0000000000000001) 00000003126F8FD0 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000002739C0000 L"oleaut32.dll",PROCESS_DETACH,0000000000000001) 0000000273A6A370 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000002739C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_DETACH,0000000000000001) 00000002E8FB74E0 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_DETACH,0000000000000001) 00000003270465C0 - CALL 0178:017c:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_DETACH,0000000000000001) 0000000231B26040 - CALL 0178:017c:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (0000000381900000 L"odbccp32.dll",PROCESS_DETACH,0000000000000001) 0000000381907640 - CALL 0178:017c:trace:module:MODULE_InitDLL (0000000381900000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (000000030FBD0000 L"mspatcha.dll",PROCESS_DETACH,0000000000000001) 000000030FBD5650 - CALL 0178:017c:trace:module:MODULE_InitDLL (000000030FBD0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000002BC640000 L"imagehlp.dll",PROCESS_DETACH,0000000000000001) 00000002BC644570 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000002BC640000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000003BE590000 L"dbghelp.dll",PROCESS_DETACH,0000000000000001) 00000003BE5DC0A0 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000003BE590000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_DETACH,0000000000000001) 00000001DD4524D0 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_DETACH,0000000000000001) 00000002D4D49C40 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000001DC080000 L"cabinet.dll",PROCESS_DETACH,0000000000000001) 00000001DC091A80 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000001DC080000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_DETACH,0000000000000001) 00000002F72424B0 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (000000006B4B0000 L"winemac.drv",PROCESS_DETACH,0000000000000001) 000000006B4D3C10 - CALL 0178:017c:trace:module:MODULE_InitDLL (000000006B4B0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000002BB750000 L"comctl32.dll",PROCESS_DETACH,0000000000000001) 00000002BB7FDA80 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000002BB750000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 0178:017c:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 0178:017c:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (000000006B560000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006B609460 - CALL 0178:017c:trace:module:MODULE_InitDLL (000000006B560000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 0178:017c:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 0178:017c:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 0178:017c:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 0178:017c:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 0178:017c:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0178:017c:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 0178:017c:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #004d 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0D78 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0047 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB0688 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:fixme:msi:internal_ui_handler flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EEC0, base 000000000031EEB8. 0170:0174:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) internal UI not implemented for message 0x0b000000 (UI level = 1) 0170:0174:fixme:msi:internal_ui_handler internal UI not implemented for message 0x0b000000 (UI level = 1) 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:FindResourceExW 00000001F3BB0000 #0006 #0272 0000 0170:0174:trace:module:LoadResource 00000001F3BB0000 00000001F3CB13B8 0170:0174:trace:module:LdrUnloadDll (0000000356770000) 0170:0174:trace:module:LdrUnloadDll (L"mscoree.dll") - START 0170:0174:trace:module:MODULE_DecRefCount (L"mscoree.dll") ldr.LoadCount: 0 0170:0174:trace:module:MODULE_DecRefCount (L"dbghelp.dll") ldr.LoadCount: 1 0170:0174:trace:module:MODULE_InitDLL (0000000356770000 L"mscoree.dll",PROCESS_DETACH,0000000000000000) 0000000356783CA0 - CALL 0170:0174:trace:module:MODULE_InitDLL (0000000356770000,PROCESS_DETACH,0000000000000000) - RETURN 1 0170:0174:trace:module:free_modref unloading L"C:\\windows\\system32\\mscoree.dll" 0170:0174:trace:module:LdrUnloadDll END 0170:0174:trace:module:LdrUnloadDll (00000001C3C60000) 0170:0174:trace:module:LdrUnloadDll (L"appwiz.cpl") - START 0170:0174:trace:module:MODULE_DecRefCount (L"appwiz.cpl") ldr.LoadCount: 0 0170:0174:trace:module:MODULE_DecRefCount (L"bcrypt.dll") ldr.LoadCount: 1 0170:0174:trace:module:MODULE_DecRefCount (L"comdlg32.dll") ldr.LoadCount: 0 0170:0174:trace:module:MODULE_DecRefCount (L"winspool.drv") ldr.LoadCount: 0 0170:0174:trace:module:MODULE_DecRefCount (L"urlmon.dll") ldr.LoadCount: 1 0170:0174:trace:module:MODULE_InitDLL (00000001C3C60000 L"appwiz.cpl",PROCESS_DETACH,0000000000000000) 00000001C3C658B0 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000001C3C60000,PROCESS_DETACH,0000000000000000) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (000000031F800000 L"comdlg32.dll",PROCESS_DETACH,0000000000000000) 000000031F82E950 - CALL 0170:0174:trace:module:MODULE_InitDLL (000000031F800000,PROCESS_DETACH,0000000000000000) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000001C4EE0000 L"winspool.drv",PROCESS_DETACH,0000000000000000) 00000001C4EF90D0 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000001C4EE0000,PROCESS_DETACH,0000000000000000) - RETURN 1 0170:0174:trace:module:free_modref unloading L"C:\\windows\\system32\\appwiz.cpl" 0170:0174:trace:module:free_modref unloading L"C:\\windows\\system32\\comdlg32.dll" 0170:0174:trace:module:free_modref unloading L"C:\\windows\\system32\\winspool.drv" 0170:0174:trace:module:LdrUnloadDll END 0170:0174:trace:module:LdrShutdownProcess () 0170:0174:trace:module:MODULE_InitDLL (00000001F3BB0000 L"msi.dll",PROCESS_DETACH,0000000000000001) 00000001F3C60C20 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000001F3BB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000001FDFD0000 L"wintrust.dll",PROCESS_DETACH,0000000000000001) 00000001FDFE63D0 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000001FDFD0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000003543D0000 L"sxs.dll",PROCESS_DETACH,0000000000000001) 00000003543D4F30 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000003543D0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (0000000381900000 L"odbccp32.dll",PROCESS_DETACH,0000000000000001) 0000000381907640 - CALL 0170:0174:trace:module:MODULE_InitDLL (0000000381900000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (000000030FBD0000 L"mspatcha.dll",PROCESS_DETACH,0000000000000001) 000000030FBD5650 - CALL 0170:0174:trace:module:MODULE_InitDLL (000000030FBD0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000002BC640000 L"imagehlp.dll",PROCESS_DETACH,0000000000000001) 00000002BC644570 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000002BC640000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000003BE590000 L"dbghelp.dll",PROCESS_DETACH,0000000000000001) 00000003BE5DC0A0 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000003BE590000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_DETACH,0000000000000001) 00000001DD4524D0 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000001DC080000 L"cabinet.dll",PROCESS_DETACH,0000000000000001) 00000001DC091A80 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000001DC080000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000003422E0000 L"urlmon.dll",PROCESS_DETACH,0000000000000001) 0000000342334800 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000003422E0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000003A0440000 L"wininet.dll",PROCESS_DETACH,0000000000000001) 00000003A0486300 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000003A0440000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000001EC2B0000 L"ws2_32.dll",PROCESS_DETACH,0000000000000001) 00000001EC2C27C0 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000001EC2B0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (000000024F470000 L"mpr.dll",PROCESS_DETACH,0000000000000001) 000000024F47A960 - CALL 0170:0174:trace:module:MODULE_InitDLL (000000024F470000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000002739C0000 L"oleaut32.dll",PROCESS_DETACH,0000000000000001) 0000000273A6A370 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000002739C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_DETACH,0000000000000001) 00000002D4D49C40 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000001C69E0000 L"shell32.dll",PROCESS_DETACH,0000000000000001) 00000001C6A688D0 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000001C69E0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_DETACH,0000000000000001) 00000002E355DE00 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_DETACH,0000000000000001) 00000003126F8FD0 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_DETACH,0000000000000001) 00000002E8FB74E0 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_DETACH,0000000000000001) 00000003270465C0 - CALL 0170:0174:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_DETACH,0000000000000001) 0000000231B26040 - CALL 0170:0174:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_DETACH,0000000000000001) 00000002F72424B0 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (000000006DF10000 L"winemac.drv",PROCESS_DETACH,0000000000000001) 000000006DF28C10 - CALL 0170:0174:trace:module:MODULE_InitDLL (000000006DF10000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000002BB750000 L"comctl32.dll",PROCESS_DETACH,0000000000000001) 00000002BB7FDA80 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000002BB750000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 0170:0174:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 0170:0174:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (000000006AC60000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006AD09460 - CALL 0170:0174:trace:module:MODULE_InitDLL (000000006AC60000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 0170:0174:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 0170:0174:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 0170:0174:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 0170:0174:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 0170:0174:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0170:0174:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 0170:0174:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0160:0164:trace:module:LdrUnloadDll (00000001F3BB0000) 0160:0164:trace:module:LdrUnloadDll (L"msi.dll") - START 0160:0164:trace:module:MODULE_DecRefCount (L"msi.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"cabinet.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"comctl32.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"imm32.dll") ldr.LoadCount: 1 0160:0164:trace:module:MODULE_DecRefCount (L"crypt32.dll") ldr.LoadCount: 1 0160:0164:trace:module:MODULE_DecRefCount (L"imagehlp.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"dbghelp.dll") ldr.LoadCount: 1 0160:0164:trace:module:MODULE_DecRefCount (L"mspatcha.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"odbccp32.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 5 0160:0164:trace:module:MODULE_DecRefCount (L"oleaut32.dll") ldr.LoadCount: 2 0160:0164:trace:module:MODULE_DecRefCount (L"rpcrt4.dll") ldr.LoadCount: 4 0160:0164:trace:module:MODULE_DecRefCount (L"shell32.dll") ldr.LoadCount: 3 0160:0164:trace:module:MODULE_DecRefCount (L"shlwapi.dll") ldr.LoadCount: 4 0160:0164:trace:module:MODULE_DecRefCount (L"sxs.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 4 0160:0164:trace:module:MODULE_DecRefCount (L"oleaut32.dll") ldr.LoadCount: 1 0160:0164:trace:module:MODULE_DecRefCount (L"urlmon.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 3 0160:0164:trace:module:MODULE_DecRefCount (L"oleaut32.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 2 0160:0164:trace:module:MODULE_DecRefCount (L"rpcrt4.dll") ldr.LoadCount: 3 0160:0164:trace:module:MODULE_DecRefCount (L"rpcrt4.dll") ldr.LoadCount: 2 0160:0164:trace:module:MODULE_DecRefCount (L"shell32.dll") ldr.LoadCount: 2 0160:0164:trace:module:MODULE_DecRefCount (L"shlwapi.dll") ldr.LoadCount: 3 0160:0164:trace:module:MODULE_DecRefCount (L"wininet.dll") ldr.LoadCount: 1 0160:0164:trace:module:MODULE_DecRefCount (L"wininet.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"mpr.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"shell32.dll") ldr.LoadCount: 1 0160:0164:trace:module:MODULE_DecRefCount (L"shlwapi.dll") ldr.LoadCount: 2 0160:0164:trace:module:MODULE_DecRefCount (L"ws2_32.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"wintrust.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"crypt32.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"bcrypt.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_InitDLL (00000001F3BB0000 L"msi.dll",PROCESS_DETACH,0000000000000000) 00000001F3C60C20 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000001F3BB0000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000001FDFD0000 L"wintrust.dll",PROCESS_DETACH,0000000000000000) 00000001FDFE63D0 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000001FDFD0000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000003422E0000 L"urlmon.dll",PROCESS_DETACH,0000000000000000) 0000000342334800 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000003422E0000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000003A0440000 L"wininet.dll",PROCESS_DETACH,0000000000000000) 00000003A0486300 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000003A0440000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000001EC2B0000 L"ws2_32.dll",PROCESS_DETACH,0000000000000000) 00000001EC2C27C0 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000001EC2B0000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (000000024F470000 L"mpr.dll",PROCESS_DETACH,0000000000000000) 000000024F47A960 - CALL 0160:0164:trace:module:MODULE_InitDLL (000000024F470000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000003543D0000 L"sxs.dll",PROCESS_DETACH,0000000000000000) 00000003543D4F30 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000003543D0000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000002739C0000 L"oleaut32.dll",PROCESS_DETACH,0000000000000000) 0000000273A6A370 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000002739C0000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (0000000381900000 L"odbccp32.dll",PROCESS_DETACH,0000000000000000) 0000000381907640 - CALL 0160:0164:trace:module:MODULE_InitDLL (0000000381900000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (000000030FBD0000 L"mspatcha.dll",PROCESS_DETACH,0000000000000000) 000000030FBD5650 - CALL 0160:0164:trace:module:MODULE_InitDLL (000000030FBD0000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000002BC640000 L"imagehlp.dll",PROCESS_DETACH,0000000000000000) 00000002BC644570 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000002BC640000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_DETACH,0000000000000000) 00000001DD4524D0 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_DETACH,0000000000000000) 00000002D4D49C40 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000002BB750000 L"comctl32.dll",PROCESS_DETACH,0000000000000000) 00000002BB7FDA80 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000002BB750000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000001DC080000 L"cabinet.dll",PROCESS_DETACH,0000000000000000) 00000001DC091A80 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000001DC080000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msi.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wintrust.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\urlmon.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\wininet.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ws2_32.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mpr.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sxs.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\oleaut32.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\odbccp32.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mspatcha.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imagehlp.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\comctl32.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\cabinet.dll" 0160:0164:trace:module:LdrUnloadDll END 0160:0164:trace:module:LdrUnloadDll (0000000356770000) 0160:0164:trace:module:LdrUnloadDll (L"mscoree.dll") - START 0160:0164:trace:module:MODULE_DecRefCount (L"mscoree.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"dbghelp.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 1 0160:0164:trace:module:MODULE_DecRefCount (L"shell32.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"shlwapi.dll") ldr.LoadCount: 1 0160:0164:trace:module:MODULE_DecRefCount (L"shlwapi.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"shcore.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"ole32.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"combase.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_DecRefCount (L"rpcrt4.dll") ldr.LoadCount: 1 0160:0164:trace:module:MODULE_DecRefCount (L"rpcrt4.dll") ldr.LoadCount: 0 0160:0164:trace:module:MODULE_InitDLL (0000000356770000 L"mscoree.dll",PROCESS_DETACH,0000000000000000) 0000000356783CA0 - CALL 0160:0164:trace:module:MODULE_InitDLL (0000000356770000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000001C69E0000 L"shell32.dll",PROCESS_DETACH,0000000000000000) 00000001C6A688D0 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000001C69E0000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_DETACH,0000000000000000) 00000002E355DE00 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_DETACH,0000000000000000) 00000003126F8FD0 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_DETACH,0000000000000000) 00000002E8FB74E0 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_DETACH,0000000000000000) 00000003270465C0 - CALL 0160:0164:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_DETACH,0000000000000000) 0000000231B26040 - CALL 0160:0164:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000003BE590000 L"dbghelp.dll",PROCESS_DETACH,0000000000000000) 00000003BE5DC0A0 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000003BE590000,PROCESS_DETACH,0000000000000000) - RETURN 1 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\mscoree.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" 0160:0164:trace:module:free_modref unloading L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\dbghelp.dll" 0160:0164:trace:module:LdrUnloadDll END 0160:0164:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FD50, base 000000000031FD48. 0160:0164:trace:module:LdrGetDllHandleEx L"mscoree" -> 0000000000000000 (load path (null)) 0160:0164:trace:module:LdrShutdownProcess () 0160:0164:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_DETACH,0000000000000001) 00000002F72424B0 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_DETACH,0000000000000001) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (000000006CD10000 L"winemac.drv",PROCESS_DETACH,0000000000000001) 000000006CD28C10 - CALL 0160:0164:trace:module:MODULE_InitDLL (000000006CD10000,PROCESS_DETACH,0000000000000001) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 0160:0164:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 0160:0164:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (000000006A460000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006A509460 - CALL 0160:0164:trace:module:MODULE_InitDLL (000000006A460000,PROCESS_DETACH,0000000000000001) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 0160:0164:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 0160:0164:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 0160:0164:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 0160:0164:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 0160:0164:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0160:0164:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 0160:0164:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0150:0154:trace:process:NtQueryInformationProcess (0x74,0x00000000,0x21f1d0,0x00000030,0x0) 0150:0154:trace:module:LdrShutdownProcess () 0150:0154:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_DETACH,0000000000000001) 00000001DD4524D0 - CALL 0150:0154:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0150:0154:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 0150:0154:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 0150:0154:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 0150:0154:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 0150:0154:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 0150:0154:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0150:0154:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 0150:0154:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0150:0154:trace:module:MODULE_InitDLL (000000006B360000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006B409460 - CALL 0150:0154:trace:module:MODULE_InitDLL (000000006B360000,PROCESS_DETACH,0000000000000001) - RETURN 1 0150:0154:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_DETACH,0000000000000001) 00000002D4D49C40 - CALL 0150:0154:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_DETACH,0000000000000001) - RETURN 1 0150:0154:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 0150:0154:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 0150:0154:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 0150:0154:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 0150:0154:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 0150:0154:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 0150:0154:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 0150:0154:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0150:0154:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 0150:0154:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 0150:0154:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 0150:0154:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0150:0154:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 0150:0154:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0158:015c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FD50, base 000000000031FD48. 0158:015c:trace:module:LdrGetDllHandleEx L"mscoree" -> 0000000000000000 (load path (null)) 0158:015c:trace:module:LdrShutdownProcess () 0158:015c:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 0158:015c:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0158:015c:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 0158:015c:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 0158:015c:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 0158:015c:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 0158:015c:trace:module:MODULE_InitDLL (000000006AB60000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006AC09460 - CALL 0158:015c:trace:module:MODULE_InitDLL (000000006AB60000,PROCESS_DETACH,0000000000000001) - RETURN 1 0158:015c:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 0158:015c:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0158:015c:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 0158:015c:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 0158:015c:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 0158:015c:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 0158:015c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 0158:015c:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 0158:015c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 0158:015c:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0158:015c:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 0158:015c:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 0158:015c:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 0158:015c:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0158:015c:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 0158:015c:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 -> rc=0 (took 9.66056394577026 seconds) Piping into "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wine" --scope private --wl-app regedit.exe - ***** Sat Jan 21 17:38:11 2023 Starting: '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wine' '--scope' 'private' '--wl-app' 'regedit.exe' '-' CXConfig->read(/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/etc/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/CrossOver.conf) Product version=22.1.0.35656 CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) Mode = 'private' Environment: CX_ROOT = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver" CX_BOTTLE = "SteamAMDWin10Test" WINEPREFIX = "/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test" CX_WINDOWS_VERSION = PATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin:/usr/local/opt/docker-virtualbox/bin:/usr/local/sbin:/Users/hoshi/opt/local/bin:/usr/local/bin:/System/Cryptexes/App/usr/bin:/usr/bin:/bin:/usr/sbin:/sbin:/Applications/VMware Fusion.app/Contents/Public:/usr/local/share/dotnet:/opt/X11/bin:~/.dotnet/tools:/Library/Apple/usr/bin:/Library/Frameworks/Mono.framework/Versions/Current/Commands" DYLD_LIBRARY_PATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib64" WINEDLLPATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine" WINEDLLOVERRIDES = LD_PRELOAD = LD_ASSUME_KERNEL = WINELOADER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64" WINESERVER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineserver" WINEDEBUG = "+pid,+process,+module,+loaddll,+seh,+threadname" WINEWRAPPER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe" CX_LOG = "/Users/hoshi/crossover-beta-wine10-amd.cxlog" CX_DEBUGMSG = "+pid,+process,+module,+loaddll,+seh,+threadname" DISPLAY = "/private/tmp/com.apple.launchd.EjtXTmJGw9/org.xquartz:0" VKD3D_DEBUG = VKD3D_SHADER_DEBUG = CXConfig->read(/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/etc/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) Command: /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64 /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe --run -- /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/regedit.exe - ** Sat Jan 21 17:38:12 2023 Starting '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64' '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe' '--run' '--' '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/regedit.exe' '-' preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0188:018c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0188:018c:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0188:018c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0188:018c:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0188:018c:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" is a fake Wine dll 0188:018c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0188:018c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0188:018c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0188:018c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0188:018c:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x321000 0188:018c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x21fa70,0x00000040,0x0) 0188:018c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0000000000332C60 0000000068A70000 0188:018c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" at 0000000068A70000: builtin 0188:018c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0188:018c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0188:018c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0188:018c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0188:018c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0188:018c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0188:018c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0188:018c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0188:018c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0188:018c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0000000000333510 000000007B000000 0188:018c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000: builtin 0188:018c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0188:018c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 00000000003330A0 000000007B600000 0188:018c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000: builtin 0188:018c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000 0188:018c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0188:018c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0188:018c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0188:018c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0188:018c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0188:018c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0188:018c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0188:018c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0188:018c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0188:018c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0000000000330380 00000001C8DB0000 0188:018c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000: builtin 0188:018c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0188:018c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"sechost.dll" in (null) 0188:018c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0188:018c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0188:018c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0188:018c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0188:018c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0188:018c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0188:018c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0188:018c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0188:018c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0188:018c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0000000000330A60 00000003AF670000 0188:018c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000: builtin 0188:018c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 00000000003307F0 000000032A700000 0188:018c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000: builtin 0188:018c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 00000000003315B0 0000000330260000 0188:018c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000: builtin 0188:018c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"crypt32.dll" in (null) 0188:018c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" 0188:018c:trace:module:get_load_order_value got app defaults b for L"crypt32" 0188:018c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 0x1dd3f0000-0x1dd4be000 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .text at 0x1dd3f1000 off 1000 size 63000 virt 62550 flags 60000060 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .data at 0x1dd454000 off 64000 size 3000 virt 2640 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rodata at 0x1dd457000 off 67000 size 1000 virt 74c flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rdata at 0x1dd458000 off 68000 size 12000 virt 11830 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .pdata at 0x1dd46a000 off 7a000 size 3000 virt 2958 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .xdata at 0x1dd46d000 off 7d000 size 4000 virt 3260 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .bss at 0x1dd471000 off 0 size 0 virt 32d0 flags c0000080 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .edata at 0x1dd475000 off 81000 size 5000 virt 4c9c flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .idata at 0x1dd47a000 off 86000 size 2000 virt 1650 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rsrc at 0x1dd47c000 off 88000 size 41000 virt 40f48 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .reloc at 0x1dd4bd000 off c9000 size 1000 virt 514 flags 42000040 0188:018c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"bcrypt.dll" in (null) 0188:018c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 0188:018c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 0188:018c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 0x2d4d40000-0x2d4d57000 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .text at 0x2d4d41000 off 1000 size a000 virt 97c0 flags 60000020 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .data at 0x2d4d4b000 off b000 size 1000 virt 70 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rodata at 0x2d4d4c000 off c000 size 1000 virt 3b8 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rdata at 0x2d4d4d000 off d000 size 2000 virt 1c40 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .pdata at 0x2d4d4f000 off f000 size 1000 virt 420 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .xdata at 0x2d4d50000 off 10000 size 1000 virt 52c flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .bss at 0x2d4d51000 off 0 size 0 virt 170 flags c0000080 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .edata at 0x2d4d52000 off 11000 size 2000 virt 1317 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .idata at 0x2d4d54000 off 13000 size 1000 virt 6cc flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rsrc at 0x2d4d55000 off 14000 size 1000 virt 3c0 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .reloc at 0x2d4d56000 off 15000 size 1000 virt 44 flags 42000040 0188:018c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0188:018c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 0000000000331980 00000002D4D40000 0188:018c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 00000002D4D40000: builtin 0188:018c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 00000002D4D40000 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0188:018c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"user32.dll" in (null) 0188:018c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0188:018c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0188:018c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 0188:018c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=4 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0188:018c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0188:018c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0188:018c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 0188:018c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=5 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0188:018c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"user32.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"win32u.dll" in (null) 0188:018c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0188:018c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0188:018c:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" is a fake Wine dll 0188:018c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0188:018c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0000000000337330 000000006C810000 0188:018c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006C810000: builtin 0188:018c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006C810000 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0000000000336E50 000000026B4C0000 0188:018c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000: builtin 0188:018c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0188:018c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"sechost.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"version.dll" in (null) 0188:018c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0188:018c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0188:018c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 0188:018c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=11 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0188:018c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=13 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=6 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 00000000003377A0 00000002F1FA0000 0188:018c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000: builtin 0188:018c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"win32u.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" for L"win32u.dll" at 000000006C810000, count=2 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0000000000336C40 000000023D820000 0188:018c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000: builtin 0188:018c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" 0000000000330C30 00000001DD3F0000 0188:018c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 00000001DD3F0000: builtin 0188:018c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 00000001DD3F0000 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=12 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0188:018c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=14 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:process_attach (L"ntdll.dll",000000000021FB00) - START 0188:018c:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000021FB00) 0000000170065B80 - CALL 0188:018c:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0188:018c:trace:module:process_attach (L"ntdll.dll",000000000021FB00) - END 0188:018c:trace:module:process_attach (L"kernel32.dll",000000000021FB00) - START 0188:018c:trace:module:process_attach (L"kernelbase.dll",000000000021FB00) - START 0188:018c:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000021FB00) 000000007B03CAD0 - CALL 0188:018c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x21f618,0x00000008,0x0) 0188:018c:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000021F2A0 85) 0188:018c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 0188:018c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 00000000003341F0 17) 0188:018c:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000339B20, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021EFE8. 0188:018c:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0188:018c:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0188:018c:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0188:018c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0188:018c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0188:018c:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0188:018c:trace:module:LoadResource 0000000010000002 00000000100077D8 0188:018c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 0188:018c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 00000000003341F0 17) 0188:018c:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000339B20, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021EFE8. 0188:018c:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0188:018c:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0188:018c:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0188:018c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0188:018c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0188:018c:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0188:018c:trace:module:LoadResource 0000000010000002 00000000100077D8 0188:018c:trace:process:CreateProcessInternalW app L"C:\\windows\\system32\\conhost.exe" cmdline L"\"C:\\windows\\system32\\conhost.exe\" --unix --width 80 --height 24 --server 0x34" 0188:018c:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\conhost.exe" image L"C:\\windows\\system32\\conhost.exe" cmdline L"\"C:\\windows\\system32\\conhost.exe\" --unix --width 80 --height 24 --server 0x34" parent 0x0 0188:018c:trace:process:send_to_cx_loader loader (null) wineserversocket 7 stdin_fd -1 stdout_fd 12 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 0188:018c:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0190:0194:trace:module:get_load_order looking for L"C:\\windows\\system32\\conhost.exe" 0190:0194:trace:module:get_load_order got hardcoded default for L"conhost.exe" 0190:0194:trace:module:get_load_order looking for L"C:\\windows\\system32\\conhost.exe" 0190:0194:trace:module:get_load_order got hardcoded default for L"conhost.exe" 0190:0194:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\conhost.exe" at 0x140000000-0x14003b000 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .text at 0x140001000 off 1000 size 11000 virt 100d0 flags 60000060 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .data at 0x140012000 off 12000 size 1000 virt f0 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .rdata at 0x140013000 off 13000 size 2000 virt 18f0 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .pdata at 0x140015000 off 15000 size 1000 virt 5f4 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .xdata at 0x140016000 off 16000 size 1000 virt 69c flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .bss at 0x140017000 off 0 size 0 virt 1340 flags c0000080 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .idata at 0x140019000 off 17000 size 2000 virt 199c flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .rsrc at 0x14001b000 off 19000 size 1f000 virt 1eaf0 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .reloc at 0x14003a000 off 38000 size 1000 virt bc flags 42000040 0190:0194:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0190:0194:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0188:018c:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\conhost.exe" pid 0190 tid 0194 handles 0x44/0x48 0188:018c:trace:process:CreateProcessInternalW started process pid 0190 tid 0194 0188:018c:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0188:018c:trace:module:process_attach (L"kernelbase.dll",000000000021FB00) - END 0188:018c:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000021FB00) 000000007B631530 - CALL 0188:018c:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0188:018c:trace:module:process_attach (L"kernel32.dll",000000000021FB00) - END 0188:018c:trace:module:process_attach (L"advapi32.dll",000000000021FB00) - START 0188:018c:trace:module:process_attach (L"msvcrt.dll",000000000021FB00) - START 0188:018c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000021FB00) 00000001C8E1AB00 - CALL 0190:0194:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 0190:0194:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\conhost.exe" 0000000000432910 0000000140000000 0190:0194:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\conhost.exe" at 0000000140000000: builtin 0188:018c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F3B0. 0190:0194:trace:module:load_dll looking for L"kernel32.dll" in (null) 0188:018c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0188:018c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F400. 0188:018c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0188:018c:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0188:018c:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0188:018c:trace:module:process_attach (L"msvcrt.dll",000000000021FB00) - END 0188:018c:trace:module:process_attach (L"sechost.dll",000000000021FB00) - START 0188:018c:trace:module:process_attach (L"ucrtbase.dll",000000000021FB00) - START 0188:018c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000021FB00) 00000003AF6F1C30 - CALL 0188:018c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F320. 0190:0194:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernel32.dll" 0188:018c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0188:018c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F370. 0188:018c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0188:018c:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0188:018c:trace:module:process_attach (L"ucrtbase.dll",000000000021FB00) - END 0190:0194:trace:module:get_load_order got hardcoded default for L"kernel32.dll" 0188:018c:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000021FB00) 000000032A716FC0 - CALL 0188:018c:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0188:018c:trace:module:process_attach (L"sechost.dll",000000000021FB00) - END 0188:018c:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000021FB00) 0000000330283EC0 - CALL 0188:018c:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0188:018c:trace:module:process_attach (L"advapi32.dll",000000000021FB00) - END 0188:018c:trace:module:process_attach (L"crypt32.dll",000000000021FB00) - START 0188:018c:trace:module:process_attach (L"bcrypt.dll",000000000021FB00) - START 0188:018c:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_ATTACH,000000000021FB00) 00000002D4D49C40 - CALL 0188:018c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F570, base 000000000021F568. 0188:018c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0190:0194:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0190:0194:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0190:0194:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernelbase.dll" 0190:0194:trace:module:get_load_order got hardcoded default for L"kernelbase.dll" 0190:0194:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0190:0194:trace:module:load_dll looking for L"ntdll.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 0000000000433000 000000007B000000 0190:0194:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 0190:0194:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"ntdll.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000432D10 000000007B600000 0190:0194:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 0190:0194:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 0188:018c:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0188:018c:trace:module:process_attach (L"bcrypt.dll",000000000021FB00) - END 0188:018c:trace:module:process_attach (L"user32.dll",000000000021FB00) - START 0188:018c:trace:module:process_attach (L"gdi32.dll",000000000021FB00) - START 0188:018c:trace:module:process_attach (L"win32u.dll",000000000021FB00) - START 0188:018c:trace:module:MODULE_InitDLL (000000006C810000 L"win32u.dll",PROCESS_ATTACH,000000000021FB00) 000000006C8AE460 - CALL 0190:0194:trace:module:load_dll looking for L"advapi32.dll" in (null) 0190:0194:trace:module:get_load_order looking for L"C:\\windows\\system32\\advapi32.dll" 0190:0194:trace:module:get_load_order got hardcoded default for L"advapi32.dll" 0190:0194:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0190:0194:trace:module:load_dll looking for L"kernel32.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0190:0194:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvcrt.dll" 0190:0194:trace:module:get_load_order got hardcoded default for L"msvcrt.dll" 0190:0194:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0190:0194:trace:module:load_dll looking for L"kernel32.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"ntdll.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 0000000000433510 00000001C8DB0000 0190:0194:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 0190:0194:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"ntdll.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"sechost.dll" in (null) 0190:0194:trace:module:get_load_order looking for L"C:\\windows\\system32\\sechost.dll" 0190:0194:trace:module:get_load_order got hardcoded default for L"sechost.dll" 0190:0194:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0190:0194:trace:module:load_dll looking for L"kernel32.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"ntdll.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0190:0194:trace:module:get_load_order looking for L"C:\\windows\\system32\\ucrtbase.dll" 0190:0194:trace:module:get_load_order got hardcoded default for L"ucrtbase.dll" 0190:0194:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0190:0194:trace:module:load_dll looking for L"kernel32.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"ntdll.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 0000000000433AF0 00000003AF670000 0190:0194:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 0190:0194:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 00000000004337E0 000000032A700000 0190:0194:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 0190:0194:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 0000000000433300 0000000330260000 0190:0194:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 0190:0194:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"gdi32.dll" in (null) 0190:0194:trace:module:get_load_order looking for L"C:\\windows\\system32\\gdi32.dll" 0190:0194:trace:module:get_load_order got hardcoded default for L"gdi32.dll" 0190:0194:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 0190:0194:trace:module:load_dll looking for L"advapi32.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"kernel32.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"ntdll.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"user32.dll" in (null) 0190:0194:trace:module:get_load_order looking for L"C:\\windows\\system32\\user32.dll" 0190:0194:trace:module:get_load_order got hardcoded default for L"user32.dll" 0190:0194:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 0190:0194:trace:module:load_dll looking for L"advapi32.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"gdi32.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"kernel32.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"ntdll.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"sechost.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"version.dll" in (null) 0190:0194:trace:module:get_load_order looking for L"C:\\windows\\system32\\version.dll" 0190:0194:trace:module:get_load_order got hardcoded default for L"version.dll" 0190:0194:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 0190:0194:trace:module:load_dll looking for L"kernel32.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"ntdll.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 00000000004344A0 00000002F1FA0000 0190:0194:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 00000002F1FA0000: builtin 0190:0194:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 00000002F1FA0000 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"win32u.dll" in (null) 0190:0194:trace:module:get_load_order looking for L"C:\\windows\\system32\\win32u.dll" 0190:0194:trace:module:get_load_order got hardcoded default for L"win32u.dll" 0190:0194:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\win32u.dll" is a fake Wine dll 0190:0194:trace:module:load_dll looking for L"kernel32.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"ntdll.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\win32u.dll" 00000000004347F0 000000006AC60000 0190:0194:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\win32u.dll" at 000000006AC60000: builtin 0190:0194:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\win32u.dll" at 000000006AC60000 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\user32.dll" 0000000000434090 000000023D820000 0190:0194:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\user32.dll" at 000000023D820000: builtin 0190:0194:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\user32.dll" at 000000023D820000 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"win32u.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AC60000, count=2 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\gdi32.dll" 0000000000433DE0 000000026B4C0000 0190:0194:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000: builtin 0190:0194:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"kernel32.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"ntdll.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"user32.dll" in (null) 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 0190:0194:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 0190:0194:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0190:0194:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 0190:0194:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 0190:0194:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 0190:0194:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 0190:0194:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 0190:0194:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 0190:0194:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 0190:0194:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000436C20 17) 0190:0194:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000436D30, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0190:0194:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0190:0194:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0190:0194:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0190:0194:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0190:0194:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0190:0194:trace:module:LoadResource 0000000010000002 00000000100077D8 0190:0194:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 0190:0194:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000436C70 17) 0190:0194:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000436E50, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0190:0194:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0190:0194:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0190:0194:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0190:0194:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0190:0194:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0190:0194:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0190:0194:trace:module:LoadResource 0000000010000002 00000000100077D8 0190:0194:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0190:0194:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 0190:0194:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 0190:0194:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0190:0194:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 0190:0194:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 0190:0194:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 0190:0194:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 0190:0194:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F3B0. 0190:0194:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 0190:0194:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F400. 0190:0194:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 0190:0194:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0190:0194:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0190:0194:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 0190:0194:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 0190:0194:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 0190:0194:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 0190:0194:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 0190:0194:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 0190:0194:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 0190:0194:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 0190:0194:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0190:0194:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 0190:0194:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 0190:0194:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0190:0194:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 0190:0194:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 0190:0194:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0190:0194:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 0190:0194:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - START 0190:0194:trace:module:process_attach (L"user32.dll",000000000031FB00) - START 0190:0194:trace:module:process_attach (L"version.dll",000000000031FB00) - START 0190:0194:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000031FB00) 00000002F1FA2510 - CALL 0190:0194:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0190:0194:trace:module:process_attach (L"version.dll",000000000031FB00) - END 0190:0194:trace:module:process_attach (L"win32u.dll",000000000031FB00) - START 0190:0194:trace:module:MODULE_InitDLL (000000006AC60000 L"win32u.dll",PROCESS_ATTACH,000000000031FB00) 000000006AD09460 - CALL 0188:018c:trace:module:MODULE_InitDLL (000000006C810000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0188:018c:trace:module:process_attach (L"win32u.dll",000000000021FB00) - END 0188:018c:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000021FB00) 000000026B509F00 - CALL 0188:018c:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0188:018c:trace:module:process_attach (L"gdi32.dll",000000000021FB00) - END 0188:018c:trace:module:process_attach (L"version.dll",000000000021FB00) - START 0188:018c:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000021FB00) 00000002F1FA2510 - CALL 0188:018c:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0188:018c:trace:module:process_attach (L"version.dll",000000000021FB00) - END 0188:018c:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000021FB00) 000000023D8C5690 - CALL 0188:018c:trace:module:load_dll looking for L"imm32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0188:018c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0188:018c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0188:018c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 0188:018c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 0188:018c:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0188:018c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0188:018c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0188:018c:trace:module:import_dll is not hybrid module 0188:018c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0000000000341C40 00000003AFD00000 0188:018c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000: builtin 0188:018c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000 0188:018c:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 0188:018c:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 0188:018c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021EBB0, base 000000000021EBA8. 0188:018c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0188:018c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021F048. 0188:018c:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 0188:018c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021EB60, base 000000000021EB58. 0188:018c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0188:018c:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0188:018c:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 0188:018c:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0188:018c:trace:module:process_attach (L"user32.dll",000000000021FB00) - END 0188:018c:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_ATTACH,000000000021FB00) 00000001DD4524D0 - CALL 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0188:018c:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 0188:018c:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 0188:018c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F600, base 000000000021F5F8. 0188:018c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0188:018c:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 0188:018c:trace:module:process_attach (L"crypt32.dll",000000000021FB00) - END 0188:018c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x21f8b8,0x00000008,0x0) 0188:018c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F080, base 000000000021F078. 0188:018c:trace:module:LdrGetDllHandleEx L"kernel32" -> 000000007B600000 (load path (null)) 0190:0194:trace:module:MODULE_InitDLL (000000006AC60000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0190:0194:trace:module:process_attach (L"win32u.dll",000000000031FB00) - END 0190:0194:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000031FB00) 000000023D8C5690 - CALL 0190:0194:trace:module:load_dll looking for L"imm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0190:0194:trace:module:get_load_order looking for L"C:\\windows\\system32\\imm32.dll" 0190:0194:trace:module:get_load_order got hardcoded default for L"imm32.dll" 0190:0194:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 0190:0194:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 0190:0194:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0190:0194:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 0190:0194:trace:module:import_dll is not hybrid module 0190:0194:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imm32.dll" 000000000043E8E0 00000003AFD00000 0190:0194:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imm32.dll" at 00000003AFD00000: builtin 0190:0194:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imm32.dll" at 00000003AFD00000 0190:0194:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 0190:0194:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 0190:0194:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EBB0, base 000000000031EBA8. 0190:0194:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0190:0194:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031F048. 0190:0194:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 0190:0194:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EB60, base 000000000031EB58. 0190:0194:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0190:0194:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0190:0194:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 0190:0194:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0190:0194:trace:module:process_attach (L"user32.dll",000000000031FB00) - END 0190:0194:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000031FB00) 000000026B509F00 - CALL 0190:0194:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0190:0194:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - END 0190:0194:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 0190:0194:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FA50, base 000000000031FA48. 0190:0194:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0190:0194:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F5E0, base 000000000031F5D8. 0190:0194:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0188:018c:trace:process:CreateProcessInternalW app (null) cmdline L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe -" 0188:018c:trace:process:find_exe_file looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;.;C:\\windows\\system32;C:\\windows\\system;C:\\windows;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0188:018c:trace:process:NtCreateUserProcess L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" image L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" cmdline L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe -" parent 0x0 0188:018c:trace:process:send_to_cx_loader loader (null) wineserversocket 11 stdin_fd 13 stdout_fd 1 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 0188:018c:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" 0198:019c:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" 0198:019c:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" at 0x140000000-0x1400a6000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" section .text at 0x140001000 off 1000 size f000 virt e270 flags 60000060 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" section .data at 0x140010000 off 10000 size 1000 virt 410 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" section .rdata at 0x140011000 off 11000 size 2000 virt 1230 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" section .pdata at 0x140013000 off 13000 size 1000 virt 6a8 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" section .xdata at 0x140014000 off 14000 size 1000 virt 7f4 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" section .bss at 0x140015000 off 0 size 0 virt fa0 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" section .idata at 0x140016000 off 15000 size 2000 virt 1d88 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" section .rsrc at 0x140018000 off 17000 size 8d000 virt 8c460 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" section .reloc at 0x1400a5000 off a4000 size 1000 virt 168 flags 42000040 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 0198:019c:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 0188:018c:trace:process:NtCreateUserProcess L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" pid 0198 tid 019c handles 0x6c/0x70 0188:018c:trace:process:CreateProcessInternalW started process pid 0198 tid 019c 0198:019c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" 0000000000432C00 0000000140000000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" at 0000000140000000: builtin 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 0198:019c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 00000000004334B0 000000007B000000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0000000000433040 000000007B600000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000 0198:019c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"msvcrt.dll" in (null) 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 00000000004346C0 00000001C8DB0000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"sechost.dll" in (null) 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0000000000434DA0 00000003AF670000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0000000000434B30 000000032A700000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0000000000435940 0000000330260000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 0198:019c:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 0198:019c:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0198:019c:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 0198:019c:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 0198:019c:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 0198:019c:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 0198:019c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 0198:019c:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 0198:019c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 0198:019c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000434380 17) 0198:019c:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000438850, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0198:019c:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0198:019c:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0198:019c:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0198:019c:trace:module:LoadResource 0000000010000002 00000000100077D8 0198:019c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 0198:019c:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000434820 17) 0198:019c:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000438850, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 0198:019c:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0198:019c:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"tzres.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 0198:019c:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 0198:019c:trace:module:LoadResource 0000000010000002 00000000100077D8 0198:019c:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0198:019c:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 0198:019c:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 0198:019c:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0198:019c:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 0198:019c:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 0198:019c:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 0198:019c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 0198:019c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F3B0. 0198:019c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" 0198:019c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F400. 0198:019c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" 0198:019c:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 0198:019c:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0198:019c:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 0198:019c:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 0198:019c:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 0198:019c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 0198:019c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 0198:019c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" 0198:019c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 0198:019c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" 0198:019c:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0198:019c:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 0198:019c:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 0198:019c:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0198:019c:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 0198:019c:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 0198:019c:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 0198:019c:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 0198:019c:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 0198:019c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 000000014000F1F0, 0000000000000000, 000000007B60C498, 00000001400167FC, 0x00000000) 0198:019c:trace:module:load_dll looking for L"comctl32.dll" in (null) 0198:019c:trace:module:find_dll_file found L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" for L"comctl32.dll" 0198:019c:trace:module:get_load_order looking for L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" at 0x2bb750000-0x2bb88f000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" section .text at 0x2bb751000 off 1000 size ae000 virt ad9d0 flags 60000060 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" section .data at 0x2bb7ff000 off af000 size 1000 virt 300 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" section .rodata at 0x2bb800000 off b0000 size 1000 virt 734 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" section .rdata at 0x2bb801000 off b1000 size 1f000 virt 1ef80 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" section .pdata at 0x2bb820000 off d0000 size 4000 virt 3198 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" section .xdata at 0x2bb824000 off d4000 size 5000 virt 40a8 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" section .bss at 0x2bb829000 off 0 size 0 virt 1720 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" section .edata at 0x2bb82b000 off d9000 size f000 virt eff3 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" section .idata at 0x2bb83a000 off e8000 size 4000 virt 3b2c flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" section .rsrc at 0x2bb83e000 off ec000 size 50000 virt 4fad8 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" section .reloc at 0x2bb88e000 off 13c000 size 1000 virt 1d4 flags 42000040 0198:019c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 0198:019c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"user32.dll" in (null) 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 0198:019c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"sechost.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"version.dll" in (null) 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 000000000043DD40 00000002F1FA0000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"win32u.dll" in (null) 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0198:019c:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" is a fake Wine dll 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0000000000442D50 000000006BC60000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006BC60000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006BC60000 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 000000000043D600 000000023D820000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"win32u.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" for L"win32u.dll" at 000000006BC60000, count=2 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 00000000004405B0 000000026B4C0000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"imm32.dll" in (null) 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 0198:019c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"user32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0000000000443030 00000003AFD00000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"user32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=3 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" 0000000000440290 00000002BB750000 0198:019c:trace:loaddll:build_module Loaded L"C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" at 00000002BB750000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\winsxs\\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.2600.2982_none_deadbeef\\comctl32.dll" at 00000002BB750000 0198:019c:trace:module:process_attach (L"comctl32.dll",0000000000000000) - START 0198:019c:trace:module:process_attach (L"gdi32.dll",0000000000000000) - START 0198:019c:trace:module:process_attach (L"user32.dll",0000000000000000) - START 0198:019c:trace:module:process_attach (L"version.dll",0000000000000000) - START 0198:019c:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,0000000000000000) 00000002F1FA2510 - CALL 0198:019c:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0198:019c:trace:module:process_attach (L"version.dll",0000000000000000) - END 0198:019c:trace:module:process_attach (L"win32u.dll",0000000000000000) - START 0198:019c:trace:module:MODULE_InitDLL (000000006BC60000 L"win32u.dll",PROCESS_ATTACH,0000000000000000) 000000006BD09460 - CALL 0198:019c:trace:module:MODULE_InitDLL (000000006BC60000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0198:019c:trace:module:process_attach (L"win32u.dll",0000000000000000) - END 0198:019c:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,0000000000000000) 000000023D8C5690 - CALL 0198:019c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F080, base 000000000031F078. 0198:019c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0198:019c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031ED70, base 000000000031ED68. 0198:019c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0198:019c:trace:module:load_dll looking for L"imm32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" for L"imm32.dll" at 00000003AFD00000, count=2 0198:019c:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 0198:019c:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 0198:019c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EB00, base 000000000031EAF8. 0198:019c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0198:019c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EFA0, base 000000000031EF98. 0198:019c:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 0198:019c:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0198:019c:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 0198:019c:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0198:019c:trace:module:process_attach (L"user32.dll",0000000000000000) - END 0198:019c:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,0000000000000000) 000000026B509F00 - CALL 0198:019c:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0198:019c:trace:module:process_attach (L"gdi32.dll",0000000000000000) - END 0198:019c:trace:module:MODULE_InitDLL (00000002BB750000 L"comctl32.dll",PROCESS_ATTACH,0000000000000000) 00000002BB7FDA80 - CALL 0198:019c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F100, base 000000000031F0F8. 0198:019c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0198:019c:trace:module:load_dll looking for L"winemac.drv" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" 0198:019c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" 0198:019c:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" is a fake Wine dll 0198:019c:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"gdi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=4 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"win32u.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" for L"win32u.dll" at 000000006BC60000, count=3 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" 00000000004434A0 0000000078110000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" at 0000000078110000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" at 0000000078110000 0198:019c:trace:module:process_attach (L"winemac.drv",0000000000000000) - START 0198:019c:trace:module:MODULE_InitDLL (0000000078110000 L"winemac.drv",PROCESS_ATTACH,0000000000000000) 0000000078128C10 - CALL 0198:019c:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031B7B0. 0198:019c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\regedit.exe" 0198:019c:trace:module:FindResourceExW 0000000078110000 #0006 #0011 0000 0198:019c:trace:module:LoadResource 0000000078110000 000000007818E9D8 0198:019c:trace:module:FindResourceExW 0000000078110000 #0006 #0011 0000 0198:019c:trace:module:LoadResource 0000000078110000 000000007818E9D8 0198:019c:trace:module:FindResourceExW 0000000078110000 #0006 #0011 0000 0198:019c:trace:module:LoadResource 0000000078110000 000000007818E9D8 0198:019c:trace:module:FindResourceExW 0000000078110000 #0006 #0011 0000 0198:019c:trace:module:LoadResource 0000000078110000 000000007818E9D8 0198:019c:trace:module:FindResourceExW 0000000078110000 #0006 #0011 0000 0198:019c:trace:module:LoadResource 0000000078110000 000000007818E9D8 0198:019c:trace:module:FindResourceExW 0000000078110000 #0006 #0011 0000 0198:019c:trace:module:LoadResource 0000000078110000 000000007818E9D8 0198:019c:trace:module:FindResourceExW 0000000078110000 #0006 #0011 0000 0198:019c:trace:module:LoadResource 0000000078110000 000000007818E9D8 0198:019c:trace:module:FindResourceExW 0000000078110000 #0006 #0012 0000 0198:019c:trace:module:LoadResource 0000000078110000 000000007818EBC8 0198:019c:trace:module:FindResourceExW 0000000078110000 #0006 #0012 0000 0198:019c:trace:module:LoadResource 0000000078110000 000000007818EBC8 0198:019c:trace:module:FindResourceExW 0000000078110000 #0006 #0012 0000 0198:019c:trace:module:LoadResource 0000000078110000 000000007818EBC8 0198:019c:trace:module:FindResourceExW 0000000078110000 #0006 #0012 0000 0198:019c:trace:module:LoadResource 0000000078110000 000000007818EBC8 0198:019c:trace:module:FindResourceExW 0000000078110000 #0006 #0012 0000 0198:019c:trace:module:LoadResource 0000000078110000 000000007818EBC8 0198:019c:trace:module:MODULE_InitDLL (0000000078110000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0198:019c:trace:module:process_attach (L"winemac.drv",0000000000000000) - END 0198:019c:trace:module:EnumResourceNamesExW 0000000000000000 #000e 000000007811FB00 31d048 0198:019c:trace:module:FindResourceExW 0000000140000000 #000e #0064 0000 0198:019c:trace:module:LoadResource 0000000000000000 000000014001E4D0 0198:019c:trace:module:FindResourceExW 0000000000000000 #0003 #000f 0000 0198:019c:trace:module:LoadResource 0000000000000000 000000014001A660 0198:019c:trace:module:FindResourceExW 0000000000000000 #0003 #000e 0000 0198:019c:trace:module:LoadResource 0000000000000000 000000014001A650 0198:019c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C7D0, base 000000000031C7C8. 0198:019c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0198:019c:trace:module:FindResourceExW 0000000000000000 #0003 #000d 0000 0198:019c:trace:module:LoadResource 0000000000000000 000000014001A640 0198:019c:trace:module:FindResourceExW 0000000000000000 #0003 #0008 0000 0198:019c:trace:module:LoadResource 0000000000000000 000000014001A5F0 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C870. 0198:019c:trace:module:LoadResource 000000023D820000 000000023D908880 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C4B0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C870. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C870. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C870. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f01 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4C0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0009 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C870. 0198:019c:trace:module:LoadResource 000000023D820000 000000023D9088E0 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C4B0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C870. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C870. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C870. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C870. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C870. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C870. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031C870. 0198:019c:trace:module:load_dll looking for L"uxtheme.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0198:019c:trace:module:get_load_order looking for L"C:\\windows\\system32\\uxtheme.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"uxtheme.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\uxtheme.dll" at 0x2f7230000-0x2f7265000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .text at 0x2f7231000 off 1000 size 13000 virt 123c0 flags 60000060 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .data at 0x2f7244000 off 14000 size 1000 virt 110 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rodata at 0x2f7245000 off 15000 size 1000 virt 430 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rdata at 0x2f7246000 off 16000 size 16000 virt 15a30 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .pdata at 0x2f725c000 off 2c000 size 1000 virt 87c flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .xdata at 0x2f725d000 off 2d000 size 1000 virt 97c flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .bss at 0x2f725e000 off 0 size 0 virt 4a0 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .edata at 0x2f725f000 off 2e000 size 2000 virt 1de0 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .idata at 0x2f7261000 off 30000 size 2000 virt 14ac flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .rsrc at 0x2f7263000 off 32000 size 1000 virt 5f8 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\uxtheme.dll" section .reloc at 0x2f7264000 off 33000 size 1000 virt bc flags 42000040 0198:019c:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"gdi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=3 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=5 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\uxtheme.dll" 0000000000443880 00000002F7230000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\uxtheme.dll" at 00000002F7230000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\uxtheme.dll" at 00000002F7230000 0198:019c:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - START 0198:019c:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_ATTACH,0000000000000000) 00000002F72424B0 - CALL 0198:019c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C6A0, base 000000000031C698. 0198:019c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0198:019c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031C850, base 000000000031C848. 0198:019c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0198:019c:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000443CF0, dll_characteristics 0000000000000000, name 000000000031CA70, base 000000000031CA08. 0198:019c:trace:module:LdrGetDllHandleEx L"C:\\windows\\resources\\themes\\light\\light.msstyles" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 0198:019c:trace:module:FindResourceExW 0000000000F10001 L"PACKTHEM_VERSION" #0001 0000 0198:019c:trace:module:LoadResource 0000000000F10001 0000000000F15310 0198:019c:trace:module:FindResourceExW 0000000000F10001 L"COLORNAMES" #0001 0000 0198:019c:trace:module:LoadResource 0000000000F10001 0000000000F152F0 0198:019c:trace:module:FindResourceExW 0000000000F10001 L"SIZENAMES" #0001 0000 0198:019c:trace:module:LoadResource 0000000000F10001 0000000000F15320 0198:019c:trace:module:FindResourceExW 0000000000F10001 L"FILERESNAMES" #0001 0000 0198:019c:trace:module:LoadResource 0000000000F10001 0000000000F15300 0198:019c:trace:module:FindResourceExW 0000000000F10001 L"TEXTFILE" L"BLUE_INI" 0000 0198:019c:trace:module:LoadResource 0000000000F10001 0000000000F15330 0198:019c:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0198:019c:trace:module:process_attach (L"uxtheme.dll",0000000000000000) - END 0198:019c:trace:module:load_dll looking for L"winemac.drv" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winemac.drv" for L"winemac.drv" at 0000000078110000, count=2 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f01 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4C0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0009 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFC0. 0198:019c:trace:module:FindResourceExW 00000002BB750000 #000e #0016 0000 0198:019c:trace:module:LoadResource 00000002BB750000 00000002BB8406B0 0198:019c:trace:module:FindResourceExW 00000002BB750000 #0003 #0002 0000 0198:019c:trace:module:LoadResource 00000002BB750000 00000002BB83F310 0198:019c:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031EC50. 0198:019c:trace:module:FindResourceExW 00000002BB750000 #000e #0019 0000 0198:019c:trace:module:LoadResource 00000002BB750000 00000002BB8406C0 0198:019c:trace:module:FindResourceExW 00000002BB750000 #0003 #0003 0000 0198:019c:trace:module:LoadResource 00000002BB750000 00000002BB83F320 0198:019c:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031EC50. 0198:019c:trace:module:FindResourceExW 00000002BB750000 #000e #001c 0000 0198:019c:trace:module:LoadResource 00000002BB750000 00000002BB8406D0 0198:019c:trace:module:FindResourceExW 00000002BB750000 #0003 #0004 0000 0198:019c:trace:module:LoadResource 00000002BB750000 00000002BB83F330 0198:019c:trace:module:LdrGetDllFullName module 00000002BB750000, name 000000000031EC50. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:FindResourceExW 000000023D820000 #000c #7f00 0000 0198:019c:trace:module:LoadResource 000000023D820000 000000023D90A4B0 0198:019c:trace:module:FindResourceExW 000000023D820000 #0001 #0003 0000 0198:019c:trace:module:LdrGetDllFullName module 000000023D820000, name 000000000031EFD0. 0198:019c:trace:module:MODULE_InitDLL (00000002BB750000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0198:019c:trace:module:process_attach (L"comctl32.dll",0000000000000000) - END 0198:019c:trace:module:LdrResolveDelayLoadedAPI (0000000140000000, 000000014000F1B0, 0000000000000000, 000000007B60C498, 00000001400169BC, 0x00000000) 0198:019c:trace:module:load_dll looking for L"shell32.dll" in (null) 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" at 0x1c69e0000-0x1c72fe000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .text at 0x1c69e1000 off 1000 size 89000 virt 88c60 flags 60000060 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .data at 0x1c6a6a000 off 8a000 size 2000 virt 13e0 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rodata at 0x1c6a6c000 off 8c000 size 2000 virt 18ec flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rdata at 0x1c6a6e000 off 8e000 size 29000 virt 28e90 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .pdata at 0x1c6a97000 off b7000 size 6000 virt 5748 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .xdata at 0x1c6a9d000 off bd000 size 6000 virt 5c20 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .bss at 0x1c6aa3000 off 0 size 0 virt 570 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .edata at 0x1c6aa4000 off c3000 size 15000 virt 14070 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .idata at 0x1c6ab9000 off d8000 size 5000 virt 4aa0 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .rsrc at 0x1c6abe000 off dd000 size 83e000 virt 83d918 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" section .reloc at 0x1c72fc000 off 91b000 size 2000 virt 1264 flags 42000040 0198:019c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=4 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"shlwapi.dll" in (null) 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" at 0x2e3540000-0x2e3591000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .text at 0x2e3541000 off 1000 size 1e000 virt 1dac0 flags 60000060 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .data at 0x2e355f000 off 1f000 size 1000 virt 210 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rodata at 0x2e3560000 off 20000 size 2000 virt 18fc flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rdata at 0x2e3562000 off 22000 size b000 virt a290 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .pdata at 0x2e356d000 off 2d000 size 2000 virt 11b8 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .xdata at 0x2e356f000 off 2f000 size 2000 virt 13a8 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .bss at 0x2e3571000 off 0 size 0 virt 1c0 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .edata at 0x2e3572000 off 31000 size 14000 virt 13ab5 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .idata at 0x2e3586000 off 45000 size 5000 virt 442c flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .rsrc at 0x2e358b000 off 4a000 size 5000 virt 4ed0 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" section .reloc at 0x2e3590000 off 4f000 size 1000 virt e0 flags 42000040 0198:019c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=5 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"shcore.dll" in (null) 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" at 0x3126f0000-0x312709000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .text at 0x3126f1000 off 1000 size 9000 virt 8b70 flags 60000020 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .data at 0x3126fa000 off a000 size 1000 virt b0 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rodata at 0x3126fb000 off b000 size 1000 virt fb4 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .rdata at 0x3126fc000 off c000 size 3000 virt 2360 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .pdata at 0x3126ff000 off f000 size 1000 virt 57c flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .xdata at 0x312700000 off 10000 size 1000 virt 61c flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .bss at 0x312701000 off 0 size 0 virt 160 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .edata at 0x312702000 off 11000 size 5000 virt 480e flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .idata at 0x312707000 off 16000 size 1000 virt c74 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" section .reloc at 0x312708000 off 17000 size 1000 virt a8 flags 42000040 0198:019c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ole32.dll" in (null) 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" 0198:019c:trace:module:get_load_order_value got standard key b for L"ole32" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" at 0x2e8f10000-0x2e902b000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .text at 0x2e8f11000 off 1000 size a8000 virt a76a0 flags 60000060 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .data at 0x2e8fb9000 off a9000 size 1000 virt 480 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rodata at 0x2e8fba000 off aa000 size 1000 virt 778 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rdata at 0x2e8fbb000 off ab000 size 1e000 virt 1d750 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .pdata at 0x2e8fd9000 off c9000 size 7000 virt 6b10 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .xdata at 0x2e8fe0000 off d0000 size 7000 virt 67c4 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .bss at 0x2e8fe7000 off 0 size 0 virt 210 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .edata at 0x2e8fe8000 off d7000 size 18000 virt 17412 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .idata at 0x2e9000000 off ef000 size 4000 virt 367c flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .rsrc at 0x2e9004000 off f3000 size 25000 virt 24bc0 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" section .reloc at 0x2e9029000 off 118000 size 2000 virt 1804 flags 42000040 0198:019c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"combase.dll" in (null) 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" 0198:019c:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" at 0x327020000-0x327073000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .text at 0x327021000 off 1000 size 27000 virt 26590 flags 60000060 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .data at 0x327048000 off 28000 size 1000 virt 580 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rodata at 0x327049000 off 29000 size 2000 virt 16c0 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .rdata at 0x32704b000 off 2b000 size d000 virt cf90 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .pdata at 0x327058000 off 38000 size 2000 virt 17a0 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .xdata at 0x32705a000 off 3a000 size 2000 virt 18e4 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .bss at 0x32705c000 off 0 size 0 virt 1a0 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .edata at 0x32705d000 off 3c000 size 13000 virt 12d6e flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .idata at 0x327070000 off 4f000 size 2000 virt 1804 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" section .reloc at 0x327072000 off 51000 size 1000 virt 23c flags 42000040 0198:019c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=6 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ole32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" for L"ole32.dll" at 00000002E8F10000, count=2 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0198:019c:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" 0198:019c:trace:module:get_load_order_value got standard key b for L"rpcrt4" 0198:019c:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0x231ae0000-0x231b62000 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .text at 0x231ae1000 off 1000 size 47000 virt 46400 flags 60000060 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .data at 0x231b28000 off 48000 size 1000 virt 710 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rodata at 0x231b29000 off 49000 size 2000 virt 1b44 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rdata at 0x231b2b000 off 4b000 size 15000 virt 14b90 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .pdata at 0x231b40000 off 60000 size 3000 virt 2334 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .xdata at 0x231b43000 off 63000 size 3000 virt 289c flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .bss at 0x231b46000 off 0 size 0 virt 690 flags c0000080 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .edata at 0x231b47000 off 66000 size 17000 virt 16730 flags 40000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .idata at 0x231b5e000 off 7d000 size 2000 virt 19a8 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .rsrc at 0x231b60000 off 7f000 size 1000 virt 3a8 flags c0000040 0198:019c:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" section .reloc at 0x231b61000 off 80000 size 1000 virt 504 flags 42000040 0198:019c:trace:module:load_dll looking for L"advapi32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" 0000000000476B10 0000000231AE0000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0000000231AE0000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" at 0000000231AE0000 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"user32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=6 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" 0000000000476620 0000000327020000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" at 0000000327020000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\combase.dll" at 0000000327020000 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"gdi32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=7 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernel32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"kernelbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ntdll.dll" in (null) 0198:019c:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"rpcrt4.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\rpcrt4.dll" for L"rpcrt4.dll" at 0000000231AE0000, count=2 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"user32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=7 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" 00000000004761C0 00000002E8F10000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" at 00000002E8F10000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ole32.dll" at 00000002E8F10000 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"user32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=8 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" 0000000000475D50 00000003126F0000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" at 00000003126F0000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shcore.dll" at 00000003126F0000 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"user32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=9 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" 00000000004758A0 00000002E3540000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" at 00000002E3540000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shlwapi.dll" at 00000002E3540000 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:load_dll looking for L"user32.dll" in (null) 0198:019c:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=10 0198:019c:trace:module:import_dll is not hybrid module 0198:019c:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" 0000000000475630 00000001C69E0000 0198:019c:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" at 00000001C69E0000: builtin 0198:019c:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" at 00000001C69E0000 0198:019c:trace:module:process_attach (L"shell32.dll",0000000000000000) - START 0198:019c:trace:module:process_attach (L"shlwapi.dll",0000000000000000) - START 0198:019c:trace:module:process_attach (L"shcore.dll",0000000000000000) - START 0198:019c:trace:module:process_attach (L"ole32.dll",0000000000000000) - START 0198:019c:trace:module:process_attach (L"combase.dll",0000000000000000) - START 0198:019c:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - START 0198:019c:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_ATTACH,0000000000000000) 0000000231B26040 - CALL 0198:019c:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0198:019c:trace:module:process_attach (L"rpcrt4.dll",0000000000000000) - END 0198:019c:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_ATTACH,0000000000000000) 00000003270465C0 - CALL 0198:019c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EE20, base 000000000031EE18. 0198:019c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0198:019c:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0198:019c:trace:module:process_attach (L"combase.dll",0000000000000000) - END 0198:019c:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_ATTACH,0000000000000000) 00000002E8FB74E0 - CALL 0198:019c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EED0, base 000000000031EEC8. 0198:019c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0198:019c:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0198:019c:trace:module:process_attach (L"ole32.dll",0000000000000000) - END 0198:019c:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_ATTACH,0000000000000000) 00000003126F8FD0 - CALL 0198:019c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EF60, base 000000000031EF58. 0198:019c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0198:019c:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0198:019c:trace:module:process_attach (L"shcore.dll",0000000000000000) - END 0198:019c:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_ATTACH,0000000000000000) 00000002E355DE00 - CALL 0198:019c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EFF0, base 000000000031EFE8. 0198:019c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0198:019c:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0198:019c:trace:module:process_attach (L"shlwapi.dll",0000000000000000) - END 0198:019c:trace:module:MODULE_InitDLL (00000001C69E0000 L"shell32.dll",PROCESS_ATTACH,0000000000000000) 00000001C6A688D0 - CALL 0198:019c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F080, base 000000000031F078. 0198:019c:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 0198:019c:trace:module:LdrGetDllFullName module 00000001C69E0000, name 000000000031F5A0. 0198:019c:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\shell32.dll" 0198:019c:trace:module:MODULE_InitDLL (00000001C69E0000,PROCESS_ATTACH,0000000000000000) - RETURN 1 0198:019c:trace:module:process_attach (L"shell32.dll",0000000000000000) - END 0198:019c:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FD50, base 000000000031FD48. 0198:019c:trace:module:LdrGetDllHandleEx L"mscoree" -> 0000000000000000 (load path (null)) 0198:019c:trace:module:LdrShutdownProcess () 0198:019c:trace:module:MODULE_InitDLL (00000001C69E0000 L"shell32.dll",PROCESS_DETACH,0000000000000001) 00000001C6A688D0 - CALL 0198:019c:trace:module:MODULE_InitDLL (00000001C69E0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_DETACH,0000000000000001) 00000002E355DE00 - CALL 0198:019c:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_DETACH,0000000000000001) 00000003126F8FD0 - CALL 0198:019c:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_DETACH,0000000000000001) 00000002E8FB74E0 - CALL 0198:019c:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_DETACH,0000000000000001) 00000003270465C0 - CALL 0198:019c:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_DETACH,0000000000000001) 0000000231B26040 - CALL 0198:019c:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (00000002F7230000 L"uxtheme.dll",PROCESS_DETACH,0000000000000001) 00000002F72424B0 - CALL 0198:019c:trace:module:MODULE_InitDLL (00000002F7230000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (0000000078110000 L"winemac.drv",PROCESS_DETACH,0000000000000001) 0000000078128C10 - CALL 0198:019c:trace:module:MODULE_InitDLL (0000000078110000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (00000002BB750000 L"comctl32.dll",PROCESS_DETACH,0000000000000001) 00000002BB7FDA80 - CALL 0198:019c:trace:module:MODULE_InitDLL (00000002BB750000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 0198:019c:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 0198:019c:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 0198:019c:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (000000006BC60000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006BD09460 - CALL 0198:019c:trace:module:MODULE_InitDLL (000000006BC60000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 0198:019c:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 0198:019c:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 0198:019c:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 0198:019c:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 0198:019c:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 0198:019c:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 0198:019c:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0198:019c:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 0198:019c:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0188:018c:trace:process:NtQueryInformationProcess (0x6c,0x00000000,0x21f1d0,0x00000030,0x0) 0188:018c:trace:module:LdrShutdownProcess () 0188:018c:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_DETACH,0000000000000001) 00000001DD4524D0 - CALL 0188:018c:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0188:018c:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 0188:018c:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 0188:018c:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 0188:018c:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 0188:018c:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 0188:018c:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0188:018c:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 0188:018c:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0188:018c:trace:module:MODULE_InitDLL (000000006C810000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006C8AE460 - CALL 0188:018c:trace:module:MODULE_InitDLL (000000006C810000,PROCESS_DETACH,0000000000000001) - RETURN 1 0188:018c:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_DETACH,0000000000000001) 00000002D4D49C40 - CALL 0188:018c:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_DETACH,0000000000000001) - RETURN 1 0188:018c:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 0188:018c:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 0188:018c:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 0188:018c:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 0188:018c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 0188:018c:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 0188:018c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 0188:018c:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0188:018c:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 0188:018c:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 0188:018c:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 0188:018c:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0188:018c:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 0188:018c:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0190:0194:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FD50, base 000000000031FD48. 0190:0194:trace:module:LdrGetDllHandleEx L"mscoree" -> 0000000000000000 (load path (null)) 0190:0194:trace:module:LdrShutdownProcess () 0190:0194:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 0190:0194:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0190:0194:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 0190:0194:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 0190:0194:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 0190:0194:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 0190:0194:trace:module:MODULE_InitDLL (000000006AC60000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006AD09460 - CALL 0190:0194:trace:module:MODULE_InitDLL (000000006AC60000,PROCESS_DETACH,0000000000000001) - RETURN 1 0190:0194:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 0190:0194:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0190:0194:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 0190:0194:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 0190:0194:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 0190:0194:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 0190:0194:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 0190:0194:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 0190:0194:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 0190:0194:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0190:0194:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 0190:0194:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 0190:0194:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 0190:0194:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0190:0194:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 0190:0194:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 -> rc=0 (took 0.553975105285645 seconds) CXConfig->read(/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/etc/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) -> rc=0 (took 18.6816251277924 seconds) CXRWConfig->new(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) CXRWConfig->write(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) 5395: Releasing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock 5395: Grabbing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock 5395: Got the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) 5395: Releasing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock Bottle environment variables: CX_BOTTLE_CREATOR_APPID -> com.codeweavers.c4.206 Running '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/cxmenu' '--install' '--scope' 'private' ***** Sat Jan 21 17:38:12 2023 Starting: '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/cxmenu' '--install' '--scope' 'private' CXConfig->read(/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/etc/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/CrossOver.conf) 5474: Grabbing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock 5474: Got the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) 5474: Releasing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock Bottle environment variables: CX_BOTTLE_CREATOR_APPID -> com.codeweavers.c4.206 5474: Grabbing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock 5474: Got the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock CXRWConfig->new(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) CXRWConfig->write(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) 5474: Releasing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock -> rc=0 (took 0.0339601039886475 seconds) Running '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/cxassoc' '--install' '--scope' 'private' ***** Sat Jan 21 17:38:12 2023 Starting: '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/cxassoc' '--install' '--scope' 'private' CXConfig->read(/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/etc/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/CrossOver.conf) 5475: Grabbing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock 5475: Got the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) 5475: Releasing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock Bottle environment variables: CX_BOTTLE_CREATOR_APPID -> com.codeweavers.c4.206 5475: Grabbing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock 5475: Got the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock CXRWConfig->new(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) CXRWConfig->write(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) 5475: Releasing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock -> rc=0 (took 0.0333280563354492 seconds) ***** Sat Jan 21 17:38:12 2023 Starting: '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/cxassoc' '--bottle' 'SteamAMDWin10Test' '--sync' CXConfig->read(/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/etc/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/CrossOver.conf) 5476: Grabbing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock 5476: Got the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) 5476: Releasing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock Bottle environment variables: CX_BOTTLE_CREATOR_APPID -> com.codeweavers.c4.206 5476: Grabbing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b-cxassoc.conf.lock' lock 5476: Got the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b-cxassoc.conf.lock' lock CXConfig->read("/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wine" --scope private --no-convert --wl-app assocscan.exe --scan --icon-dir "/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/windata/Associations" |) ***** Sat Jan 21 17:38:12 2023 Starting: '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wine' '--scope' 'private' '--no-convert' '--wl-app' 'assocscan.exe' '--scan' '--icon-dir' '/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/windata/Associations' 5478: Grabbing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock 5478: Got the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock CXConfig->read(/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/etc/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/CrossOver.conf) Product version=22.1.0.35656 CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) Mode = 'private' Bottle environment variables: CX_BOTTLE_CREATOR_APPID -> com.codeweavers.c4.206 Environment: CX_ROOT = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver" CX_BOTTLE = "SteamAMDWin10Test" WINEPREFIX = "/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test" CX_WINDOWS_VERSION = PATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin:/usr/local/opt/docker-virtualbox/bin:/usr/local/sbin:/Users/hoshi/opt/local/bin:/usr/local/bin:/System/Cryptexes/App/usr/bin:/usr/bin:/bin:/usr/sbin:/sbin:/Applications/VMware Fusion.app/Contents/Public:/usr/local/share/dotnet:/opt/X11/bin:~/.dotnet/tools:/Library/Apple/usr/bin:/Library/Frameworks/Mono.framework/Versions/Current/Commands" DYLD_LIBRARY_PATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib64" WINEDLLPATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine" WINEDLLOVERRIDES = LD_PRELOAD = LD_ASSUME_KERNEL = WINELOADER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64" WINESERVER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineserver" WINEDEBUG = "+pid,+process,+module,+loaddll,+seh,+threadname" WINEWRAPPER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe" CX_LOG = "/Users/hoshi/crossover-beta-wine10-amd.cxlog" CX_DEBUGMSG = "+pid,+process,+module,+loaddll,+seh,+threadname" DISPLAY = "/private/tmp/com.apple.launchd.EjtXTmJGw9/org.xquartz:0" VKD3D_DEBUG = VKD3D_SHADER_DEBUG = 5478: Releasing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b.lock' lock CXConfig->read(/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/etc/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) Command: /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64 /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe --no-convert --run -- /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/assocscan.exe --scan --icon-dir /Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/windata/Associations ** Sat Jan 21 17:38:12 2023 Starting '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64' '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe' '--no-convert' '--run' '--' '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/assocscan.exe' '--scan' '--icon-dir' '/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/windata/Associations' preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 01a0:01a4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 01a0:01a4:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 01a0:01a4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 01a0:01a4:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 01a0:01a4:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" is a fake Wine dll 01a0:01a4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 01a0:01a4:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x321000 01a0:01a4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x21fa70,0x00000040,0x0) 01a0:01a4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0000000000332D60 0000000068A70000 01a0:01a4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" at 0000000068A70000: builtin 01a0:01a4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a0:01a4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 01a0:01a4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 01a0:01a4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 01a0:01a4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01a0:01a4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 01a0:01a4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 01a0:01a4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 01a0:01a4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 0000000000333610 000000007B000000 01a0:01a4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000: builtin 01a0:01a4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 00000000003331A0 000000007B600000 01a0:01a4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000: builtin 01a0:01a4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000 01a0:01a4:trace:module:load_dll looking for L"advapi32.dll" in (null) 01a0:01a4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 01a0:01a4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 01a0:01a4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 01a0:01a4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"msvcrt.dll" in (null) 01a0:01a4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 01a0:01a4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 01a0:01a4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 01a0:01a4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0000000000330380 00000001C8DB0000 01a0:01a4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000: builtin 01a0:01a4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"sechost.dll" in (null) 01a0:01a4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 01a0:01a4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 01a0:01a4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 01a0:01a4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01a0:01a4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 01a0:01a4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 01a0:01a4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 01a0:01a4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0000000000330A60 00000003AF670000 01a0:01a4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000: builtin 01a0:01a4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 00000000003307F0 000000032A700000 01a0:01a4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000: builtin 01a0:01a4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 00000000003315B0 0000000330260000 01a0:01a4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000: builtin 01a0:01a4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"crypt32.dll" in (null) 01a0:01a4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" 01a0:01a4:trace:module:get_load_order_value got app defaults b for L"crypt32" 01a0:01a4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 0x1dd3f0000-0x1dd4be000 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .text at 0x1dd3f1000 off 1000 size 63000 virt 62550 flags 60000060 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .data at 0x1dd454000 off 64000 size 3000 virt 2640 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rodata at 0x1dd457000 off 67000 size 1000 virt 74c flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rdata at 0x1dd458000 off 68000 size 12000 virt 11830 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .pdata at 0x1dd46a000 off 7a000 size 3000 virt 2958 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .xdata at 0x1dd46d000 off 7d000 size 4000 virt 3260 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .bss at 0x1dd471000 off 0 size 0 virt 32d0 flags c0000080 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .edata at 0x1dd475000 off 81000 size 5000 virt 4c9c flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .idata at 0x1dd47a000 off 86000 size 2000 virt 1650 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rsrc at 0x1dd47c000 off 88000 size 41000 virt 40f48 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .reloc at 0x1dd4bd000 off c9000 size 1000 virt 514 flags 42000040 01a0:01a4:trace:module:load_dll looking for L"advapi32.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"bcrypt.dll" in (null) 01a0:01a4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 01a0:01a4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 01a0:01a4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 0x2d4d40000-0x2d4d57000 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .text at 0x2d4d41000 off 1000 size a000 virt 97c0 flags 60000020 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .data at 0x2d4d4b000 off b000 size 1000 virt 70 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rodata at 0x2d4d4c000 off c000 size 1000 virt 3b8 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rdata at 0x2d4d4d000 off d000 size 2000 virt 1c40 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .pdata at 0x2d4d4f000 off f000 size 1000 virt 420 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .xdata at 0x2d4d50000 off 10000 size 1000 virt 52c flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .bss at 0x2d4d51000 off 0 size 0 virt 170 flags c0000080 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .edata at 0x2d4d52000 off 11000 size 2000 virt 1317 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .idata at 0x2d4d54000 off 13000 size 1000 virt 6cc flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rsrc at 0x2d4d55000 off 14000 size 1000 virt 3c0 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .reloc at 0x2d4d56000 off 15000 size 1000 virt 44 flags 42000040 01a0:01a4:trace:module:load_dll looking for L"advapi32.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 0000000000331980 00000002D4D40000 01a0:01a4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 00000002D4D40000: builtin 01a0:01a4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 00000002D4D40000 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"user32.dll" in (null) 01a0:01a4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 01a0:01a4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 01a0:01a4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 01a0:01a4:trace:module:load_dll looking for L"advapi32.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=4 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"gdi32.dll" in (null) 01a0:01a4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 01a0:01a4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 01a0:01a4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 01a0:01a4:trace:module:load_dll looking for L"advapi32.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=5 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"user32.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"win32u.dll" in (null) 01a0:01a4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 01a0:01a4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 01a0:01a4:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" is a fake Wine dll 01a0:01a4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0000000000337430 000000006AB60000 01a0:01a4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006AB60000: builtin 01a0:01a4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006AB60000 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0000000000336F50 000000026B4C0000 01a0:01a4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000: builtin 01a0:01a4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"sechost.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"version.dll" in (null) 01a0:01a4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 01a0:01a4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 01a0:01a4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 01a0:01a4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=11 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=13 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=6 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 00000000003378A0 00000002F1FA0000 01a0:01a4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000: builtin 01a0:01a4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"win32u.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" for L"win32u.dll" at 000000006AB60000, count=2 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0000000000336D40 000000023D820000 01a0:01a4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000: builtin 01a0:01a4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" 0000000000330C30 00000001DD3F0000 01a0:01a4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 00000001DD3F0000: builtin 01a0:01a4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 00000001DD3F0000 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=12 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a0:01a4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=14 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:process_attach (L"ntdll.dll",000000000021FB00) - START 01a0:01a4:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000021FB00) 0000000170065B80 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01a0:01a4:trace:module:process_attach (L"ntdll.dll",000000000021FB00) - END 01a0:01a4:trace:module:process_attach (L"kernel32.dll",000000000021FB00) - START 01a0:01a4:trace:module:process_attach (L"kernelbase.dll",000000000021FB00) - START 01a0:01a4:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000021FB00) 000000007B03CAD0 - CALL 01a0:01a4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x21f618,0x00000008,0x0) 01a0:01a4:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000021F2A0 85) 01a0:01a4:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 01a0:01a4:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 00000000003342F0 17) 01a0:01a4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000339C20, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021EFE8. 01a0:01a4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01a0:01a4:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 01a0:01a4:trace:module:get_load_order got hardcoded default for L"tzres.dll" 01a0:01a4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 01a0:01a4:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 01a0:01a4:trace:module:LoadResource 0000000010000002 00000000100077D8 01a0:01a4:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 01a0:01a4:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 00000000003342F0 17) 01a0:01a4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000339C20, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021EFE8. 01a0:01a4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01a0:01a4:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 01a0:01a4:trace:module:get_load_order got hardcoded default for L"tzres.dll" 01a0:01a4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 01a0:01a4:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 01a0:01a4:trace:module:LoadResource 0000000010000002 00000000100077D8 01a0:01a4:trace:process:CreateProcessInternalW app L"C:\\windows\\system32\\conhost.exe" cmdline L"\"C:\\windows\\system32\\conhost.exe\" --unix --width 0 --height 0 --server 0x34" 01a0:01a4:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\conhost.exe" image L"C:\\windows\\system32\\conhost.exe" cmdline L"\"C:\\windows\\system32\\conhost.exe\" --unix --width 0 --height 0 --server 0x34" parent 0x0 01a0:01a4:trace:process:send_to_cx_loader loader (null) wineserversocket 7 stdin_fd 12 stdout_fd -1 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 01a0:01a4:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 01a8:01ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\conhost.exe" 01a8:01ac:trace:module:get_load_order got hardcoded default for L"conhost.exe" 01a8:01ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\conhost.exe" 01a8:01ac:trace:module:get_load_order got hardcoded default for L"conhost.exe" 01a8:01ac:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\conhost.exe" at 0x140000000-0x14003b000 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .text at 0x140001000 off 1000 size 11000 virt 100d0 flags 60000060 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .data at 0x140012000 off 12000 size 1000 virt f0 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .rdata at 0x140013000 off 13000 size 2000 virt 18f0 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .pdata at 0x140015000 off 15000 size 1000 virt 5f4 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .xdata at 0x140016000 off 16000 size 1000 virt 69c flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .bss at 0x140017000 off 0 size 0 virt 1340 flags c0000080 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .idata at 0x140019000 off 17000 size 2000 virt 199c flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .rsrc at 0x14001b000 off 19000 size 1f000 virt 1eaf0 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .reloc at 0x14003a000 off 38000 size 1000 virt bc flags 42000040 01a8:01ac:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 01a8:01ac:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 01a0:01a4:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\conhost.exe" pid 01a8 tid 01ac handles 0x44/0x48 01a0:01a4:trace:process:CreateProcessInternalW started process pid 01a8 tid 01ac 01a0:01a4:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01a0:01a4:trace:module:process_attach (L"kernelbase.dll",000000000021FB00) - END 01a0:01a4:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000021FB00) 000000007B631530 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01a0:01a4:trace:module:process_attach (L"kernel32.dll",000000000021FB00) - END 01a0:01a4:trace:module:process_attach (L"advapi32.dll",000000000021FB00) - START 01a0:01a4:trace:module:process_attach (L"msvcrt.dll",000000000021FB00) - START 01a0:01a4:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000021FB00) 00000001C8E1AB00 - CALL 01a0:01a4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F3B0. 01a8:01ac:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 01a0:01a4:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 01a0:01a4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F400. 01a0:01a4:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 01a0:01a4:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 01a8:01ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\conhost.exe" 0000000000432900 0000000140000000 01a0:01a4:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01a8:01ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\conhost.exe" at 0000000140000000: builtin 01a0:01a4:trace:module:process_attach (L"msvcrt.dll",000000000021FB00) - END 01a8:01ac:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a0:01a4:trace:module:process_attach (L"sechost.dll",000000000021FB00) - START 01a0:01a4:trace:module:process_attach (L"ucrtbase.dll",000000000021FB00) - START 01a0:01a4:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000021FB00) 00000003AF6F1C30 - CALL 01a0:01a4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F320. 01a8:01ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernel32.dll" 01a0:01a4:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 01a0:01a4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F370. 01a0:01a4:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 01a0:01a4:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01a0:01a4:trace:module:process_attach (L"ucrtbase.dll",000000000021FB00) - END 01a8:01ac:trace:module:get_load_order got hardcoded default for L"kernel32.dll" 01a0:01a4:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000021FB00) 000000032A716FC0 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01a0:01a4:trace:module:process_attach (L"sechost.dll",000000000021FB00) - END 01a0:01a4:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000021FB00) 0000000330283EC0 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01a0:01a4:trace:module:process_attach (L"advapi32.dll",000000000021FB00) - END 01a0:01a4:trace:module:process_attach (L"crypt32.dll",000000000021FB00) - START 01a0:01a4:trace:module:process_attach (L"bcrypt.dll",000000000021FB00) - START 01a0:01a4:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_ATTACH,000000000021FB00) 00000002D4D49C40 - CALL 01a0:01a4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F570, base 000000000021F568. 01a0:01a4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01a8:01ac:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 01a8:01ac:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01a8:01ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernelbase.dll" 01a8:01ac:trace:module:get_load_order got hardcoded default for L"kernelbase.dll" 01a8:01ac:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 01a8:01ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 0000000000432FF0 000000007B000000 01a8:01ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 01a8:01ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 01a0:01a4:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01a8:01ac:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:process_attach (L"bcrypt.dll",000000000021FB00) - END 01a8:01ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000432D00 000000007B600000 01a0:01a4:trace:module:process_attach (L"user32.dll",000000000021FB00) - START 01a8:01ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 01a0:01a4:trace:module:process_attach (L"gdi32.dll",000000000021FB00) - START 01a8:01ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 01a0:01a4:trace:module:process_attach (L"win32u.dll",000000000021FB00) - START 01a0:01a4:trace:module:MODULE_InitDLL (000000006AB60000 L"win32u.dll",PROCESS_ATTACH,000000000021FB00) 000000006AC09460 - CALL 01a8:01ac:trace:module:load_dll looking for L"advapi32.dll" in (null) 01a8:01ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\advapi32.dll" 01a8:01ac:trace:module:get_load_order got hardcoded default for L"advapi32.dll" 01a8:01ac:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 01a8:01ac:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"msvcrt.dll" in (null) 01a8:01ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvcrt.dll" 01a8:01ac:trace:module:get_load_order got hardcoded default for L"msvcrt.dll" 01a8:01ac:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 01a8:01ac:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 0000000000433500 00000001C8DB0000 01a8:01ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 01a8:01ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"sechost.dll" in (null) 01a8:01ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\sechost.dll" 01a8:01ac:trace:module:get_load_order got hardcoded default for L"sechost.dll" 01a8:01ac:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 01a8:01ac:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01a8:01ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\ucrtbase.dll" 01a8:01ac:trace:module:get_load_order got hardcoded default for L"ucrtbase.dll" 01a8:01ac:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 01a8:01ac:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 0000000000433AE0 00000003AF670000 01a8:01ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 01a8:01ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 00000000004337D0 000000032A700000 01a8:01ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 01a8:01ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 00000000004332F0 0000000330260000 01a8:01ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 01a8:01ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"gdi32.dll" in (null) 01a8:01ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\gdi32.dll" 01a8:01ac:trace:module:get_load_order got hardcoded default for L"gdi32.dll" 01a8:01ac:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 01a8:01ac:trace:module:load_dll looking for L"advapi32.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"user32.dll" in (null) 01a8:01ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\user32.dll" 01a8:01ac:trace:module:get_load_order got hardcoded default for L"user32.dll" 01a8:01ac:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 01a8:01ac:trace:module:load_dll looking for L"advapi32.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"gdi32.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"sechost.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"version.dll" in (null) 01a8:01ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\version.dll" 01a8:01ac:trace:module:get_load_order got hardcoded default for L"version.dll" 01a8:01ac:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 01a8:01ac:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 0000000000434490 00000002F1FA0000 01a8:01ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 00000002F1FA0000: builtin 01a8:01ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 00000002F1FA0000 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"win32u.dll" in (null) 01a8:01ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\win32u.dll" 01a8:01ac:trace:module:get_load_order got hardcoded default for L"win32u.dll" 01a8:01ac:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\win32u.dll" is a fake Wine dll 01a8:01ac:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\win32u.dll" 00000000004347E0 000000006BC60000 01a8:01ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\win32u.dll" at 000000006BC60000: builtin 01a8:01ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\win32u.dll" at 000000006BC60000 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\user32.dll" 0000000000434080 000000023D820000 01a8:01ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\user32.dll" at 000000023D820000: builtin 01a8:01ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\user32.dll" at 000000023D820000 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"win32u.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006BC60000, count=2 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\gdi32.dll" 0000000000433DD0 000000026B4C0000 01a8:01ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000: builtin 01a8:01ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"kernel32.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"ntdll.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"user32.dll" in (null) 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 01a8:01ac:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01a8:01ac:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 01a8:01ac:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 01a8:01ac:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 01a8:01ac:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 01a8:01ac:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 01a8:01ac:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 01a8:01ac:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 01a8:01ac:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000436C10 17) 01a8:01ac:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000436D20, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 01a8:01ac:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01a8:01ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 01a8:01ac:trace:module:get_load_order got hardcoded default for L"tzres.dll" 01a8:01ac:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 01a8:01ac:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 01a8:01ac:trace:module:LoadResource 0000000010000002 00000000100077D8 01a8:01ac:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 01a8:01ac:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000436C60 17) 01a8:01ac:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000436E40, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 01a8:01ac:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01a8:01ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 01a8:01ac:trace:module:get_load_order got hardcoded default for L"tzres.dll" 01a8:01ac:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 01a8:01ac:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 01a8:01ac:trace:module:LoadResource 0000000010000002 00000000100077D8 01a8:01ac:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01a8:01ac:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 01a8:01ac:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01a8:01ac:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 01a8:01ac:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 01a8:01ac:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 01a8:01ac:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 01a8:01ac:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F3B0. 01a8:01ac:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 01a8:01ac:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F400. 01a8:01ac:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 01a8:01ac:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 01a8:01ac:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01a8:01ac:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 01a8:01ac:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 01a8:01ac:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 01a8:01ac:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 01a8:01ac:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 01a8:01ac:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 01a8:01ac:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 01a8:01ac:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 01a8:01ac:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01a8:01ac:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 01a8:01ac:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01a8:01ac:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 01a8:01ac:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01a8:01ac:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 01a8:01ac:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - START 01a8:01ac:trace:module:process_attach (L"user32.dll",000000000031FB00) - START 01a8:01ac:trace:module:process_attach (L"version.dll",000000000031FB00) - START 01a8:01ac:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000031FB00) 00000002F1FA2510 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01a8:01ac:trace:module:process_attach (L"version.dll",000000000031FB00) - END 01a8:01ac:trace:module:process_attach (L"win32u.dll",000000000031FB00) - START 01a8:01ac:trace:module:MODULE_InitDLL (000000006BC60000 L"win32u.dll",PROCESS_ATTACH,000000000031FB00) 000000006BD09460 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (000000006AB60000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01a0:01a4:trace:module:process_attach (L"win32u.dll",000000000021FB00) - END 01a0:01a4:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000021FB00) 000000026B509F00 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01a0:01a4:trace:module:process_attach (L"gdi32.dll",000000000021FB00) - END 01a0:01a4:trace:module:process_attach (L"version.dll",000000000021FB00) - START 01a0:01a4:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000021FB00) 00000002F1FA2510 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01a0:01a4:trace:module:process_attach (L"version.dll",000000000021FB00) - END 01a0:01a4:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000021FB00) 000000023D8C5690 - CALL 01a0:01a4:trace:module:load_dll looking for L"imm32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01a0:01a4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 01a0:01a4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 01a0:01a4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 01a0:01a4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 01a0:01a4:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01a0:01a4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01a0:01a4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 01a0:01a4:trace:module:import_dll is not hybrid module 01a0:01a4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0000000000342040 00000003AFD00000 01a0:01a4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000: builtin 01a0:01a4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000 01a0:01a4:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 01a0:01a4:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 01a0:01a4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021EBB0, base 000000000021EBA8. 01a0:01a4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01a0:01a4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021F048. 01a0:01a4:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 01a0:01a4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021EB60, base 000000000021EB58. 01a0:01a4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01a0:01a4:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 01a0:01a4:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 01a0:01a4:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01a0:01a4:trace:module:process_attach (L"user32.dll",000000000021FB00) - END 01a0:01a4:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_ATTACH,000000000021FB00) 00000001DD4524D0 - CALL 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01a0:01a4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01a0:01a4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01a0:01a4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F600, base 000000000021F5F8. 01a0:01a4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01a0:01a4:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01a0:01a4:trace:module:process_attach (L"crypt32.dll",000000000021FB00) - END 01a0:01a4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x21f8b8,0x00000008,0x0) 01a8:01ac:trace:module:MODULE_InitDLL (000000006BC60000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01a8:01ac:trace:module:process_attach (L"win32u.dll",000000000031FB00) - END 01a8:01ac:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000031FB00) 000000023D8C5690 - CALL 01a8:01ac:trace:module:load_dll looking for L"imm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01a8:01ac:trace:module:get_load_order looking for L"C:\\windows\\system32\\imm32.dll" 01a8:01ac:trace:module:get_load_order got hardcoded default for L"imm32.dll" 01a8:01ac:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 01a8:01ac:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 01a8:01ac:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01a8:01ac:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 01a8:01ac:trace:module:import_dll is not hybrid module 01a8:01ac:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imm32.dll" 000000000043E8D0 00000003AFD00000 01a8:01ac:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imm32.dll" at 00000003AFD00000: builtin 01a8:01ac:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imm32.dll" at 00000003AFD00000 01a8:01ac:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 01a8:01ac:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 01a8:01ac:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EBB0, base 000000000031EBA8. 01a8:01ac:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01a8:01ac:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031F048. 01a8:01ac:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 01a8:01ac:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EB60, base 000000000031EB58. 01a8:01ac:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01a8:01ac:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 01a8:01ac:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 01a8:01ac:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01a8:01ac:trace:module:process_attach (L"user32.dll",000000000031FB00) - END 01a8:01ac:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000031FB00) 000000026B509F00 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01a8:01ac:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - END 01a8:01ac:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 01a8:01ac:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FA50, base 000000000031FA48. 01a8:01ac:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01a8:01ac:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F5E0, base 000000000031F5D8. 01a8:01ac:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01a0:01a4:trace:process:CreateProcessInternalW app (null) cmdline L"/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/assocscan.exe --scan --icon-dir \"/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/windata/Associations\"" 01a0:01a4:trace:process:find_exe_file looking for L"/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/assocscan.exe" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;.;C:\\windows\\system32;C:\\windows\\system;C:\\windows;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01a0:01a4:trace:process:NtCreateUserProcess L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\assocscan.exe" image L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\assocscan.exe" cmdline L"/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/assocscan.exe --scan --icon-dir \"/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/windata/Associations\"" parent 0x0 01a0:01a4:trace:process:send_to_cx_loader loader (null) wineserversocket 11 stdin_fd 0 stdout_fd 13 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 01a0:01a4:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 01b0:01b4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\assocscan.exe" 01b0:01b4:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\assocscan.exe" 01b0:01b4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\assocscan.exe" 01b0:01b4:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\assocscan.exe" 01b0:01b4:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\assocscan.exe" is a fake Wine dll 01b0:01b4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 01b0:01b4:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x321000 01a0:01a4:trace:process:NtCreateUserProcess L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\assocscan.exe" pid 01b0 tid 01b4 handles 0x6c/0x70 01a0:01a4:trace:process:CreateProcessInternalW started process pid 01b0 tid 01b4 01b0:01b4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x21fa70,0x00000040,0x0) 01b0:01b4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\assocscan.exe" 0000000000332CF0 0000000068950000 01b0:01b4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\assocscan.exe" at 0000000068950000: builtin 01b0:01b4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01b0:01b4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 01b0:01b4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 01b0:01b4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 01b0:01b4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01b0:01b4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 01b0:01b4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 01b0:01b4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 01b0:01b4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 00000000003335A0 000000007B000000 01b0:01b4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000: builtin 01b0:01b4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0000000000333130 000000007B600000 01b0:01b4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000: builtin 01b0:01b4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000 01b0:01b4:trace:module:load_dll looking for L"advapi32.dll" in (null) 01b0:01b4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 01b0:01b4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 01b0:01b4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 01b0:01b4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"msvcrt.dll" in (null) 01b0:01b4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 01b0:01b4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 01b0:01b4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 01b0:01b4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0000000000333B60 00000001C8DB0000 01b0:01b4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000: builtin 01b0:01b4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"sechost.dll" in (null) 01b0:01b4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 01b0:01b4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 01b0:01b4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 01b0:01b4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01b0:01b4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 01b0:01b4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 01b0:01b4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 01b0:01b4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 00000000003342F0 00000003AF670000 01b0:01b4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000: builtin 01b0:01b4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 0000000000333FD0 000000032A700000 01b0:01b4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000: builtin 01b0:01b4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0000000000333700 0000000330260000 01b0:01b4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000: builtin 01b0:01b4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"user32.dll" in (null) 01b0:01b4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 01b0:01b4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 01b0:01b4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 01b0:01b4:trace:module:load_dll looking for L"advapi32.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"gdi32.dll" in (null) 01b0:01b4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 01b0:01b4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 01b0:01b4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 01b0:01b4:trace:module:load_dll looking for L"advapi32.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"user32.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"win32u.dll" in (null) 01b0:01b4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 01b0:01b4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 01b0:01b4:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" is a fake Wine dll 01b0:01b4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0000000000334DA0 000000006AA60000 01b0:01b4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006AA60000: builtin 01b0:01b4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006AA60000 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 00000000003348C0 000000026B4C0000 01b0:01b4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000: builtin 01b0:01b4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"sechost.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"version.dll" in (null) 01b0:01b4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 01b0:01b4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 01b0:01b4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 01b0:01b4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0000000000335210 00000002F1FA0000 01b0:01b4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000: builtin 01b0:01b4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"win32u.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" for L"win32u.dll" at 000000006AA60000, count=2 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0000000000334760 000000023D820000 01b0:01b4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000: builtin 01b0:01b4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"version.dll" in (null) 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" for L"version.dll" at 00000002F1FA0000, count=2 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:process_attach (L"ntdll.dll",000000000021FB00) - START 01b0:01b4:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000021FB00) 0000000170065B80 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01b0:01b4:trace:module:process_attach (L"ntdll.dll",000000000021FB00) - END 01b0:01b4:trace:module:process_attach (L"kernel32.dll",000000000021FB00) - START 01b0:01b4:trace:module:process_attach (L"kernelbase.dll",000000000021FB00) - START 01b0:01b4:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000021FB00) 000000007B03CAD0 - CALL 01b0:01b4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x21f618,0x00000008,0x0) 01b0:01b4:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000021F2A0 85) 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000334570 17) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003375F0, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021EFE8. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 01b0:01b4:trace:module:get_load_order got hardcoded default for L"tzres.dll" 01b0:01b4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 01b0:01b4:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 01b0:01b4:trace:module:LoadResource 0000000010000002 00000000100077D8 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000334570 17) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003376B0, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021EFE8. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 01b0:01b4:trace:module:get_load_order got hardcoded default for L"tzres.dll" 01b0:01b4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 01b0:01b4:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 01b0:01b4:trace:module:LoadResource 0000000010000002 00000000100077D8 01b0:01b4:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01b0:01b4:trace:module:process_attach (L"kernelbase.dll",000000000021FB00) - END 01b0:01b4:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000021FB00) 000000007B631530 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01b0:01b4:trace:module:process_attach (L"kernel32.dll",000000000021FB00) - END 01b0:01b4:trace:module:process_attach (L"advapi32.dll",000000000021FB00) - START 01b0:01b4:trace:module:process_attach (L"msvcrt.dll",000000000021FB00) - START 01b0:01b4:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000021FB00) 00000001C8E1AB00 - CALL 01b0:01b4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F3B0. 01b0:01b4:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\assocscan.exe" 01b0:01b4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F400. 01b0:01b4:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\assocscan.exe" 01b0:01b4:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 01b0:01b4:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01b0:01b4:trace:module:process_attach (L"msvcrt.dll",000000000021FB00) - END 01b0:01b4:trace:module:process_attach (L"sechost.dll",000000000021FB00) - START 01b0:01b4:trace:module:process_attach (L"ucrtbase.dll",000000000021FB00) - START 01b0:01b4:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000021FB00) 00000003AF6F1C30 - CALL 01b0:01b4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F320. 01b0:01b4:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\assocscan.exe" 01b0:01b4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F370. 01b0:01b4:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\assocscan.exe" 01b0:01b4:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01b0:01b4:trace:module:process_attach (L"ucrtbase.dll",000000000021FB00) - END 01b0:01b4:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000021FB00) 000000032A716FC0 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01b0:01b4:trace:module:process_attach (L"sechost.dll",000000000021FB00) - END 01b0:01b4:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000021FB00) 0000000330283EC0 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01b0:01b4:trace:module:process_attach (L"advapi32.dll",000000000021FB00) - END 01b0:01b4:trace:module:process_attach (L"user32.dll",000000000021FB00) - START 01b0:01b4:trace:module:process_attach (L"gdi32.dll",000000000021FB00) - START 01b0:01b4:trace:module:process_attach (L"win32u.dll",000000000021FB00) - START 01b0:01b4:trace:module:MODULE_InitDLL (000000006AA60000 L"win32u.dll",PROCESS_ATTACH,000000000021FB00) 000000006AB09460 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (000000006AA60000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01b0:01b4:trace:module:process_attach (L"win32u.dll",000000000021FB00) - END 01b0:01b4:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000021FB00) 000000026B509F00 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01b0:01b4:trace:module:process_attach (L"gdi32.dll",000000000021FB00) - END 01b0:01b4:trace:module:process_attach (L"version.dll",000000000021FB00) - START 01b0:01b4:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000021FB00) 00000002F1FA2510 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01b0:01b4:trace:module:process_attach (L"version.dll",000000000021FB00) - END 01b0:01b4:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000021FB00) 000000023D8C5690 - CALL 01b0:01b4:trace:module:load_dll looking for L"imm32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01b0:01b4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 01b0:01b4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 01b0:01b4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 01b0:01b4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 01b0:01b4:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01b0:01b4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01b0:01b4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 01b0:01b4:trace:module:import_dll is not hybrid module 01b0:01b4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 000000000033F760 00000003AFD00000 01b0:01b4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000: builtin 01b0:01b4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000 01b0:01b4:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 01b0:01b4:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021EC40, base 000000000021EC38. 01b0:01b4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F0E0, base 000000000021F0D8. 01b0:01b4:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021EBF0, base 000000000021EBE8. 01b0:01b4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01b0:01b4:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 01b0:01b4:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 01b0:01b4:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01b0:01b4:trace:module:process_attach (L"user32.dll",000000000021FB00) - END 01b0:01b4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x21f8b8,0x00000008,0x0) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F8C0, base 000000000021F8B8. 01b0:01b4:trace:module:LdrGetDllHandleEx L"kernel32" -> 000000007B600000 (load path (null)) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342160, dll_characteristics 0000000000000000, name 000000000021F900, base 000000000021F898. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\hh.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:EnumResourceNamesExA 0000000000DE0001 #000e 0000000068955480 21fa98 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #000e #0065 0000 01b0:01b4:trace:module:LoadResource 0000000000DE0001 0000000000DE6278 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0003 #000a 0000 01b0:01b4:trace:module:LoadResource 0000000000DE0001 0000000000DE6268 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0003 #0009 0000 01b0:01b4:trace:module:LoadResource 0000000000DE0001 0000000000DE6258 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0003 #0008 0000 01b0:01b4:trace:module:LoadResource 0000000000DE0001 0000000000DE6248 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0003 #0007 0000 01b0:01b4:trace:module:LoadResource 0000000000DE0001 0000000000DE6238 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0003 #0006 0000 01b0:01b4:trace:module:LoadResource 0000000000DE0001 0000000000DE6228 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0003 #0005 0000 01b0:01b4:trace:module:LoadResource 0000000000DE0001 0000000000DE6218 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0003 #0004 0000 01b0:01b4:trace:module:LoadResource 0000000000DE0001 0000000000DE6208 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0003 #0003 0000 01b0:01b4:trace:module:LoadResource 0000000000DE0001 0000000000DE61F8 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0003 #0002 0000 01b0:01b4:trace:module:LoadResource 0000000000DE0001 0000000000DE61E8 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0003 #0001 0000 01b0:01b4:trace:module:LoadResource 0000000000DE0001 0000000000DE61D8 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342160, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\hh.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342160, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"rundll32.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342160, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"rundll32.exe.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000000000 0) 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000342200 100) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342330, dll_characteristics 0000000000000000, name 000000000021F900, base 000000000021F898. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\Program Files\\Internet Explorer\\iexplore.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:EnumResourceNamesExA 0000000000DE0001 #000e 0000000068955480 21fa98 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003421E0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\winebrowser.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003422D0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\winhlp32.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000000000 0) 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000342350 100) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003424D0, dll_characteristics 0000000000000000, name 000000000021F900, base 000000000021F898. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\Program Files\\Internet Explorer\\iexplore.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:EnumResourceNamesExA 0000000000DE0001 #000e 0000000068955480 21fa98 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000000000 0) 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000342430 100) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342560, dll_characteristics 0000000000000000, name 000000000021F900, base 000000000021F898. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\Program Files\\Internet Explorer\\iexplore.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:EnumResourceNamesExA 0000000000DE0001 #000e 0000000068955480 21fa98 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342420, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\winebrowser.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003424A0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"rundll32.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003424F0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"rundll32.exe.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000000000 0) 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000342480 100) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342600, dll_characteristics 0000000000000000, name 000000000021F900, base 000000000021F898. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\Program Files\\Internet Explorer\\iexplore.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:EnumResourceNamesExA 0000000000DE0001 #000e 0000000068955480 21fa98 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000000000 0) 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000342560 100) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342690, dll_characteristics 0000000000000000, name 000000000021F900, base 000000000021F898. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\Program Files\\Internet Explorer\\iexplore.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:EnumResourceNamesExA 0000000000DE0001 #000e 0000000068955480 21fa98 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342550, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\winebrowser.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003425A0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"rundll32.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003425F0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"rundll32.exe.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342750, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\rundll32.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003427A0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\notepad.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342810, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\notepad.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342930, dll_characteristics 0000000000000000, name 000000000021F900, base 000000000021F898. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\itss.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:EnumResourceNamesExA 0000000000DE0001 #000e 0000000068955480 21fa98 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000000000 0) 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000342970 100) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342AA0, dll_characteristics 0000000000000000, name 000000000021F900, base 000000000021F898. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\Program Files\\Internet Explorer\\iexplore.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:EnumResourceNamesExA 0000000000DE0001 #000e 0000000068955480 21fa98 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003428C0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\winebrowser.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000000000 0) 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000342A20 100) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342B50, dll_characteristics 0000000000000000, name 000000000021F900, base 000000000021F898. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\Program Files\\Internet Explorer\\iexplore.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:EnumResourceNamesExA 0000000000DE0001 #000e 0000000068955480 21fa98 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342970, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\winebrowser.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000000000 0) 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000342AD0 100) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342C00, dll_characteristics 0000000000000000, name 000000000021F900, base 000000000021F898. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\Program Files\\Internet Explorer\\iexplore.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:EnumResourceNamesExA 0000000000DE0001 #000e 0000000068955480 21fa98 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342A20, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\winebrowser.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000000000 0) 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000342B80 100) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342CB0, dll_characteristics 0000000000000000, name 000000000021F900, base 000000000021F898. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\Program Files\\Internet Explorer\\iexplore.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:EnumResourceNamesExA 0000000000DE0001 #000e 0000000068955480 21fa98 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342AD0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\winebrowser.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000000000 0) 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000342C80 100) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342DB0, dll_characteristics 0000000000000000, name 000000000021F900, base 000000000021F898. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\Program Files\\Internet Explorer\\iexplore.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:EnumResourceNamesExA 0000000000DE0001 #000e 0000000068955480 21fa98 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000000000 0) 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000342CD0 100) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342E00, dll_characteristics 0000000000000000, name 000000000021F900, base 000000000021F898. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\Program Files\\Internet Explorer\\iexplore.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:EnumResourceNamesExA 0000000000DE0001 #000e 0000000068955480 21fa98 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342E50, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\msiexec.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000343560, dll_characteristics 0000000000000000, name 000000000021F820, base 000000000021F7B8. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\msiexec.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LoadResource 0000000000DE0001 0000000000DEC2C0 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342EC0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\msiexec.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003435D0, dll_characteristics 0000000000000000, name 000000000021F820, base 000000000021F7B8. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\msiexec.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LoadResource 0000000000DE0001 0000000000DEC2C0 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342F30, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\msiexec.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000343640, dll_characteristics 0000000000000000, name 000000000021F820, base 000000000021F7B8. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\msiexec.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LoadResource 0000000000DE0001 0000000000DEC2C0 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000342F90, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\msiexec.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003436A0, dll_characteristics 0000000000000000, name 000000000021F820, base 000000000021F7B8. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\msiexec.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LoadResource 0000000000DE0001 0000000000DEC2C0 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000343000, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\winebrowser.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000000000 0) 01b0:01b4:trace:process:ExpandEnvironmentStringsW (L"C:\\Program Files\\Internet Explorer\\iexplore.exe,1" 0000000000343160 100) 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000343290, dll_characteristics 0000000000000000, name 000000000021F900, base 000000000021F898. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\Program Files\\Internet Explorer\\iexplore.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:EnumResourceNamesExA 0000000000DE0001 #000e 0000000068955480 21fa98 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003430B0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\winebrowser.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000343220, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\Program Files\\Windows NT\\Accessories\\wordpad.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000343280, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\Program Files\\Windows NT\\Accessories\\wordpad.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003433F0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\notepad.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000343460, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\notepad.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000343570, dll_characteristics 0000000000000000, name 000000000021F900, base 000000000021F898. 01b0:01b4:trace:module:LdrGetDllHandleEx L"url.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:EnumResourceNamesExA 0000000000DE0001 #000e 0000000068955480 21fa98 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000343600, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"rundll32.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000343650, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"rundll32.exe.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000343670, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"rundll32.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003436C0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"rundll32.exe.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003436E0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\wscript.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000343730, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\notepad.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003437A0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\cscript.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003437F0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\notepad.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000343880, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\Program Files\\Windows NT\\Accessories\\wordpad.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003438E0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\Program Files\\Windows NT\\Accessories\\wordpad.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrGetDllHandleEx flags 0, load_path 00000000003439C0, dll_characteristics 0000000000000000, name 000000000021F970, base 000000000021F908. 01b0:01b4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\winebrowser.exe" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01b0:01b4:trace:module:FindResourceExW 0000000000DE0001 #0010 #0001 0000 01b0:01b4:trace:module:LdrShutdownProcess () 01b0:01b4:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 01b0:01b4:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 01b0:01b4:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 01b0:01b4:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 01b0:01b4:trace:module:MODULE_InitDLL (000000006AA60000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006AB09460 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (000000006AA60000,PROCESS_DETACH,0000000000000001) - RETURN 1 01b0:01b4:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 01b0:01b4:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 01b0:01b4:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 01b0:01b4:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 01b0:01b4:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 01b0:01b4:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 01b0:01b4:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 01b0:01b4:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a0:01a4:trace:process:NtQueryInformationProcess (0x6c,0x00000000,0x21f1d0,0x00000030,0x0) 01a0:01a4:trace:module:LdrShutdownProcess () 01a0:01a4:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_DETACH,0000000000000001) 00000001DD4524D0 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a0:01a4:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a0:01a4:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a0:01a4:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a0:01a4:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a0:01a4:trace:module:MODULE_InitDLL (000000006AB60000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006AC09460 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (000000006AB60000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a0:01a4:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_DETACH,0000000000000001) 00000002D4D49C40 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a0:01a4:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a0:01a4:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a0:01a4:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a0:01a4:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a0:01a4:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a0:01a4:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a0:01a4:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 01a0:01a4:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a8:01ac:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FD50, base 000000000031FD48. 01a8:01ac:trace:module:LdrGetDllHandleEx L"mscoree" -> 0000000000000000 (load path (null)) 01a8:01ac:trace:module:LdrShutdownProcess () 01a8:01ac:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a8:01ac:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a8:01ac:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a8:01ac:trace:module:MODULE_InitDLL (000000006BC60000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006BD09460 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (000000006BC60000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a8:01ac:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a8:01ac:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a8:01ac:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a8:01ac:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a8:01ac:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a8:01ac:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a8:01ac:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 01a8:01ac:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 01a8:01ac:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 -> rc=0 (took 0.520523071289062 seconds) .chm .cpl//cplopen MIME-only entry '.dll' -> ignored .gif .hlp .htm -> ignored .htm//print -> ignored .html -> ignored .html//print -> ignored .inf//install .ini .ini//print MIME-only entry '.its' -> ignored .jfif .jpe .jpeg .jpg MIME-only entry '.js' -> ignored MIME-only entry '.mht' -> ignored MIME-only entry '.mhtml' -> ignored .msi .msi//repair .msi//uninstall .msp .pdf .png .rtf .rtf//print .txt -> ignored .txt//print -> ignored .url -> ignored .url//print -> ignored .vbs .vbs//edit .vbs//open2 .vbs//print .wri .wri//print .xml MIME-only entry '.xsl' -> ignored CXRWConfig->write(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxassoc.conf) 5476: Releasing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-1000014-cee713b-cxassoc.conf.lock' lock ***** Sat Jan 21 17:38:13 2023 Starting: '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wine' '--no-convert' '--bottle' 'SteamAMDWin10Test' '--wait-children' 'Y:\Library\Application Support\CrossOver\installers\ddca80018c86ae60c185f1db3c283788.arial32.exe' '/T:C:\users\crossover\Temp\tmposz1e95z' '/C' 5490: Grabbing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-0-0.lock' lock 5490: Got the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-0-0.lock' lock CXConfig->read(/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/etc/CrossOver.conf) CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/CrossOver.conf) Product version=22.1.0.35656 CXConfig->read(/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test/cxbottle.conf) Mode = 'private' Bottle environment variables: CX_BOTTLE_CREATOR_APPID -> com.codeweavers.c4.206 Environment: CX_ROOT = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver" CX_BOTTLE = "SteamAMDWin10Test" WINEPREFIX = "/Users/hoshi/Library/Application Support/CrossOver/Bottles/SteamAMDWin10Test" CX_WINDOWS_VERSION = PATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin:/usr/local/opt/docker-virtualbox/bin:/usr/local/sbin:/Users/hoshi/opt/local/bin:/usr/local/bin:/System/Cryptexes/App/usr/bin:/usr/bin:/bin:/usr/sbin:/sbin:/Applications/VMware Fusion.app/Contents/Public:/usr/local/share/dotnet:/opt/X11/bin:~/.dotnet/tools:/Library/Apple/usr/bin:/Library/Frameworks/Mono.framework/Versions/Current/Commands" DYLD_LIBRARY_PATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib64" WINEDLLPATH = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine" WINEDLLOVERRIDES = LD_PRELOAD = LD_ASSUME_KERNEL = WINELOADER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64" WINESERVER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineserver" WINEDEBUG = "+pid,+process,+module,+loaddll,+seh,+threadname" WINEWRAPPER = "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe" CX_LOG = "/Users/hoshi/crossover-beta-wine10-amd.cxlog" CX_DEBUGMSG = "+pid,+process,+module,+loaddll,+seh,+threadname" DISPLAY = "/private/tmp/com.apple.launchd.EjtXTmJGw9/org.xquartz:0" VKD3D_DEBUG = VKD3D_SHADER_DEBUG = 5490: Releasing the '/var/folders/9l/h4bgjqrs6d3d769fjkx2twgw0000gn/T//.wine-501/bottle-0-0.lock' lock Command: /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64 /Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe --wait-children --no-convert --run -- Y:\Library\Application Support\CrossOver\installers\ddca80018c86ae60c185f1db3c283788.arial32.exe /T:C:\users\crossover\Temp\tmposz1e95z /C ** Sat Jan 21 17:38:13 2023 Starting '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/bin/wineloader64' '/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_64-windows/winewrapper.exe' '--wait-children' '--no-convert' '--run' '--' 'Y:\Library\Application Support\CrossOver\installers\ddca80018c86ae60c185f1db3c283788.arial32.exe' '/T:C:\users\crossover\Temp\tmposz1e95z' '/C' preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 01d0:01d4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 01d0:01d4:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 01d0:01d4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 01d0:01d4:trace:module:get_load_order got main exe default n,b for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 01d0:01d4:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" is a fake Wine dll 01d0:01d4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 01d0:01d4:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x321000 01d0:01d4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x21fa70,0x00000040,0x0) 01d0:01d4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 0000000000332D30 0000000068A70000 01d0:01d4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" at 0000000068A70000: builtin 01d0:01d4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d0:01d4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 01d0:01d4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 01d0:01d4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 01d0:01d4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01d0:01d4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 01d0:01d4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 01d0:01d4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 01d0:01d4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" 00000000003335E0 000000007B000000 01d0:01d4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000: builtin 01d0:01d4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 000000007B000000 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" 0000000000333170 000000007B600000 01d0:01d4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000: builtin 01d0:01d4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 000000007B600000 01d0:01d4:trace:module:load_dll looking for L"advapi32.dll" in (null) 01d0:01d4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 01d0:01d4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 01d0:01d4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 01d0:01d4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"msvcrt.dll" in (null) 01d0:01d4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 01d0:01d4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 01d0:01d4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 01d0:01d4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" 0000000000330380 00000001C8DB0000 01d0:01d4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000: builtin 01d0:01d4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 00000001C8DB0000 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"sechost.dll" in (null) 01d0:01d4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 01d0:01d4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 01d0:01d4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 01d0:01d4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01d0:01d4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 01d0:01d4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 01d0:01d4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 01d0:01d4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" 0000000000330A60 00000003AF670000 01d0:01d4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000: builtin 01d0:01d4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 00000003AF670000 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" 00000000003307F0 000000032A700000 01d0:01d4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000: builtin 01d0:01d4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 000000032A700000 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" 0000000000331540 0000000330260000 01d0:01d4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000: builtin 01d0:01d4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0000000330260000 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"crypt32.dll" in (null) 01d0:01d4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" 01d0:01d4:trace:module:get_load_order_value got app defaults b for L"crypt32" 01d0:01d4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 0x1dd3f0000-0x1dd4be000 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .text at 0x1dd3f1000 off 1000 size 63000 virt 62550 flags 60000060 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .data at 0x1dd454000 off 64000 size 3000 virt 2640 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rodata at 0x1dd457000 off 67000 size 1000 virt 74c flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rdata at 0x1dd458000 off 68000 size 12000 virt 11830 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .pdata at 0x1dd46a000 off 7a000 size 3000 virt 2958 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .xdata at 0x1dd46d000 off 7d000 size 4000 virt 3260 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .bss at 0x1dd471000 off 0 size 0 virt 32d0 flags c0000080 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .edata at 0x1dd475000 off 81000 size 5000 virt 4c9c flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .idata at 0x1dd47a000 off 86000 size 2000 virt 1650 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .rsrc at 0x1dd47c000 off 88000 size 41000 virt 40f48 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" section .reloc at 0x1dd4bd000 off c9000 size 1000 virt 514 flags 42000040 01d0:01d4:trace:module:load_dll looking for L"advapi32.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"bcrypt.dll" in (null) 01d0:01d4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 01d0:01d4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 01d0:01d4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 0x2d4d40000-0x2d4d57000 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .text at 0x2d4d41000 off 1000 size a000 virt 97c0 flags 60000020 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .data at 0x2d4d4b000 off b000 size 1000 virt 70 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rodata at 0x2d4d4c000 off c000 size 1000 virt 3b8 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rdata at 0x2d4d4d000 off d000 size 2000 virt 1c40 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .pdata at 0x2d4d4f000 off f000 size 1000 virt 420 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .xdata at 0x2d4d50000 off 10000 size 1000 virt 52c flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .bss at 0x2d4d51000 off 0 size 0 virt 170 flags c0000080 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .edata at 0x2d4d52000 off 11000 size 2000 virt 1317 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .idata at 0x2d4d54000 off 13000 size 1000 virt 6cc flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .rsrc at 0x2d4d55000 off 14000 size 1000 virt 3c0 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" section .reloc at 0x2d4d56000 off 15000 size 1000 virt 44 flags 42000040 01d0:01d4:trace:module:load_dll looking for L"advapi32.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" 0000000000331910 00000002D4D40000 01d0:01d4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 00000002D4D40000: builtin 01d0:01d4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" at 00000002D4D40000 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"user32.dll" in (null) 01d0:01d4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 01d0:01d4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 01d0:01d4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 01d0:01d4:trace:module:load_dll looking for L"advapi32.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=4 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"gdi32.dll" in (null) 01d0:01d4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 01d0:01d4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 01d0:01d4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 01d0:01d4:trace:module:load_dll looking for L"advapi32.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=5 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"user32.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"win32u.dll" in (null) 01d0:01d4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 01d0:01d4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 01d0:01d4:trace:module:load_builtin L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" is a fake Wine dll 01d0:01d4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" 0000000000337400 000000006AB60000 01d0:01d4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006AB60000: builtin 01d0:01d4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" at 000000006AB60000 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" 0000000000336F20 000000026B4C0000 01d0:01d4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000: builtin 01d0:01d4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 000000026B4C0000 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"sechost.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"version.dll" in (null) 01d0:01d4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 01d0:01d4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 01d0:01d4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 01d0:01d4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=11 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=13 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=6 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" 0000000000337870 00000002F1FA0000 01d0:01d4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000: builtin 01d0:01d4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 00000002F1FA0000 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"win32u.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\win32u.dll" for L"win32u.dll" at 000000006AB60000, count=2 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" 0000000000331D80 000000023D820000 01d0:01d4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000: builtin 01d0:01d4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 000000023D820000 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" 0000000000330C30 00000001DD3F0000 01d0:01d4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 00000001DD3F0000: builtin 01d0:01d4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" at 00000001DD3F0000 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=12 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d0:01d4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=14 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:process_attach (L"ntdll.dll",000000000021FB00) - START 01d0:01d4:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000021FB00) 0000000170065B80 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01d0:01d4:trace:module:process_attach (L"ntdll.dll",000000000021FB00) - END 01d0:01d4:trace:module:process_attach (L"kernel32.dll",000000000021FB00) - START 01d0:01d4:trace:module:process_attach (L"kernelbase.dll",000000000021FB00) - START 01d0:01d4:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000021FB00) 000000007B03CAD0 - CALL 01d0:01d4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x21f618,0x00000008,0x0) 01d0:01d4:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000021F2A0 85) 01d0:01d4:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 01d0:01d4:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 00000000003342C0 17) 01d0:01d4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000339BF0, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021EFE8. 01d0:01d4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01d0:01d4:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 01d0:01d4:trace:module:get_load_order got hardcoded default for L"tzres.dll" 01d0:01d4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 01d0:01d4:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 01d0:01d4:trace:module:LoadResource 0000000010000002 00000000100077D8 01d0:01d4:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 01d0:01d4:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 00000000003342C0 17) 01d0:01d4:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000339BF0, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021EFE8. 01d0:01d4:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01d0:01d4:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 01d0:01d4:trace:module:get_load_order got hardcoded default for L"tzres.dll" 01d0:01d4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 01d0:01d4:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 01d0:01d4:trace:module:LoadResource 0000000010000002 00000000100077D8 01d0:01d4:trace:process:CreateProcessInternalW app L"C:\\windows\\system32\\conhost.exe" cmdline L"\"C:\\windows\\system32\\conhost.exe\" --unix --width 80 --height 24 --server 0x34" 01d0:01d4:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\conhost.exe" image L"C:\\windows\\system32\\conhost.exe" cmdline L"\"C:\\windows\\system32\\conhost.exe\" --unix --width 80 --height 24 --server 0x34" parent 0x0 01d0:01d4:trace:process:send_to_cx_loader loader (null) wineserversocket 7 stdin_fd 12 stdout_fd 14 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 01d0:01d4:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 01d8:01dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\conhost.exe" 01d8:01dc:trace:module:get_load_order got hardcoded default for L"conhost.exe" 01d8:01dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\conhost.exe" 01d8:01dc:trace:module:get_load_order got hardcoded default for L"conhost.exe" 01d8:01dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\conhost.exe" at 0x140000000-0x14003b000 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .text at 0x140001000 off 1000 size 11000 virt 100d0 flags 60000060 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .data at 0x140012000 off 12000 size 1000 virt f0 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .rdata at 0x140013000 off 13000 size 2000 virt 18f0 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .pdata at 0x140015000 off 15000 size 1000 virt 5f4 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .xdata at 0x140016000 off 16000 size 1000 virt 69c flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .bss at 0x140017000 off 0 size 0 virt 1340 flags c0000080 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .idata at 0x140019000 off 17000 size 2000 virt 199c flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .rsrc at 0x14001b000 off 19000 size 1f000 virt 1eaf0 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\conhost.exe" section .reloc at 0x14003a000 off 38000 size 1000 virt bc flags 42000040 01d8:01dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 01d8:01dc:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x421000 01d0:01d4:trace:process:NtCreateUserProcess L"\\??\\C:\\windows\\system32\\conhost.exe" pid 01d8 tid 01dc handles 0x44/0x48 01d0:01d4:trace:process:CreateProcessInternalW started process pid 01d8 tid 01dc 01d0:01d4:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01d0:01d4:trace:module:process_attach (L"kernelbase.dll",000000000021FB00) - END 01d0:01d4:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000021FB00) 000000007B631530 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01d0:01d4:trace:module:process_attach (L"kernel32.dll",000000000021FB00) - END 01d0:01d4:trace:module:process_attach (L"advapi32.dll",000000000021FB00) - START 01d0:01d4:trace:module:process_attach (L"msvcrt.dll",000000000021FB00) - START 01d0:01d4:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000021FB00) 00000001C8E1AB00 - CALL 01d8:01dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x31fa70,0x00000040,0x0) 01d8:01dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\conhost.exe" 0000000000432970 0000000140000000 01d8:01dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\conhost.exe" at 0000000140000000: builtin 01d8:01dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d0:01d4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F3B0. 01d0:01d4:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 01d0:01d4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F400. 01d0:01d4:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 01d0:01d4:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 01d0:01d4:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01d0:01d4:trace:module:process_attach (L"msvcrt.dll",000000000021FB00) - END 01d0:01d4:trace:module:process_attach (L"sechost.dll",000000000021FB00) - START 01d0:01d4:trace:module:process_attach (L"ucrtbase.dll",000000000021FB00) - START 01d0:01d4:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000021FB00) 00000003AF6F1C30 - CALL 01d8:01dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernel32.dll" 01d8:01dc:trace:module:get_load_order got hardcoded default for L"kernel32.dll" 01d0:01d4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F320. 01d0:01d4:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 01d0:01d4:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000021F370. 01d0:01d4:trace:module:GetModuleFileNameW L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\winewrapper.exe" 01d0:01d4:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01d0:01d4:trace:module:process_attach (L"ucrtbase.dll",000000000021FB00) - END 01d0:01d4:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000021FB00) 000000032A716FC0 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01d0:01d4:trace:module:process_attach (L"sechost.dll",000000000021FB00) - END 01d0:01d4:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000021FB00) 0000000330283EC0 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01d0:01d4:trace:module:process_attach (L"advapi32.dll",000000000021FB00) - END 01d0:01d4:trace:module:process_attach (L"crypt32.dll",000000000021FB00) - START 01d0:01d4:trace:module:process_attach (L"bcrypt.dll",000000000021FB00) - START 01d0:01d4:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_ATTACH,000000000021FB00) 00000002D4D49C40 - CALL 01d0:01d4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F570, base 000000000021F568. 01d0:01d4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01d8:01dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" at 0x7b600000-0x7b65e000 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .text at 0x7b601000 off 1000 size 31000 virt 308d0 flags 60000020 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .data at 0x7b632000 off 32000 size 1000 virt 280 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rodata at 0x7b633000 off 33000 size 2000 virt 1ce0 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rdata at 0x7b635000 off 35000 size 4000 virt 3780 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .pdata at 0x7b639000 off 39000 size 2000 virt 171c flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .xdata at 0x7b63b000 off 3b000 size 2000 virt 1774 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .bss at 0x7b63d000 off 0 size 0 virt 260 flags c0000080 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .edata at 0x7b63e000 off 3d000 size e000 virt d9c6 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .idata at 0x7b64c000 off 4b000 size 9000 virt 8ff8 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .rsrc at 0x7b655000 off 54000 size 8000 virt 7e00 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" section .reloc at 0x7b65d000 off 5c000 size 1000 virt 38 flags 42000040 01d8:01dc:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01d8:01dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\kernelbase.dll" 01d8:01dc:trace:module:get_load_order got hardcoded default for L"kernelbase.dll" 01d8:01dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" at 0x7b000000-0x7b24e000 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .text at 0x7b001000 off 1000 size 81000 virt 80430 flags 60000020 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .data at 0x7b082000 off 82000 size 2000 virt 1dc0 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rodata at 0x7b084000 off 84000 size 2000 virt 1d74 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rdata at 0x7b086000 off 86000 size 1f000 virt 1e4b0 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .pdata at 0x7b0a5000 off a5000 size 5000 virt 4020 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .xdata at 0x7b0aa000 off aa000 size 5000 virt 4288 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .bss at 0x7b0af000 off 0 size 0 virt 28e0 flags c0000080 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .edata at 0x7b0b2000 off af000 size 20000 virt 1f7c4 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .idata at 0x7b0d2000 off cf000 size 5000 virt 43c8 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .rsrc at 0x7b0d7000 off d4000 size 176000 virt 1757f0 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernelbase.dll" section .reloc at 0x7b24d000 off 24a000 size 1000 virt 1b0 flags 42000040 01d8:01dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernelbase.dll" 0000000000433060 000000007B000000 01d8:01dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernelbase.dll" at 000000007B000000: builtin 01d8:01dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernelbase.dll" at 000000007B000000 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\kernel32.dll" 0000000000432D70 000000007B600000 01d8:01dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\kernel32.dll" at 000000007B600000: builtin 01d8:01dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\kernel32.dll" at 000000007B600000 01d0:01d4:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01d0:01d4:trace:module:process_attach (L"bcrypt.dll",000000000021FB00) - END 01d0:01d4:trace:module:process_attach (L"user32.dll",000000000021FB00) - START 01d0:01d4:trace:module:process_attach (L"gdi32.dll",000000000021FB00) - START 01d0:01d4:trace:module:process_attach (L"win32u.dll",000000000021FB00) - START 01d0:01d4:trace:module:MODULE_InitDLL (000000006AB60000 L"win32u.dll",PROCESS_ATTACH,000000000021FB00) 000000006AC09460 - CALL 01d8:01dc:trace:module:load_dll looking for L"advapi32.dll" in (null) 01d8:01dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\advapi32.dll" 01d8:01dc:trace:module:get_load_order got hardcoded default for L"advapi32.dll" 01d8:01dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" at 0x330260000-0x33029f000 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .text at 0x330261000 off 1000 size 24000 virt 23e50 flags 60000060 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .data at 0x330285000 off 25000 size 1000 virt 1a0 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rodata at 0x330286000 off 26000 size 1000 virt e2c flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rdata at 0x330287000 off 27000 size 6000 virt 5d20 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .pdata at 0x33028d000 off 2d000 size 2000 virt 1224 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .xdata at 0x33028f000 off 2f000 size 2000 virt 1470 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .bss at 0x330291000 off 0 size 0 virt da0 flags c0000080 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .edata at 0x330292000 off 31000 size 8000 virt 73db flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .idata at 0x33029a000 off 39000 size 3000 virt 2f08 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .rsrc at 0x33029d000 off 3c000 size 1000 virt 3c8 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" section .reloc at 0x33029e000 off 3d000 size 1000 virt 138 flags 42000040 01d8:01dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=2 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=2 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"msvcrt.dll" in (null) 01d8:01dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\msvcrt.dll" 01d8:01dc:trace:module:get_load_order got hardcoded default for L"msvcrt.dll" 01d8:01dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" at 0x1c8db0000-0x1c8e47000 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .text at 0x1c8db1000 off 1000 size 6b000 virt 6a3a0 flags 60000060 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .data at 0x1c8e1c000 off 6c000 size 2000 virt 1850 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rodata at 0x1c8e1e000 off 6e000 size 2000 virt 1394 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rdata at 0x1c8e20000 off 70000 size b000 virt a550 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .pdata at 0x1c8e2b000 off 7b000 size 5000 virt 4344 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .xdata at 0x1c8e30000 off 80000 size 4000 virt 3f04 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .bss at 0x1c8e34000 off 0 size 0 virt 1c60 flags c0000080 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .edata at 0x1c8e36000 off 84000 size d000 virt ca71 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .idata at 0x1c8e43000 off 91000 size 2000 virt 1864 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .rsrc at 0x1c8e45000 off 93000 size 1000 virt 398 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\msvcrt.dll" section .reloc at 0x1c8e46000 off 94000 size 1000 virt 258 flags 42000040 01d8:01dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=3 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=4 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\msvcrt.dll" 0000000000433570 00000001C8DB0000 01d8:01dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000: builtin 01d8:01dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\msvcrt.dll" at 00000001C8DB0000 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=5 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"sechost.dll" in (null) 01d8:01dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\sechost.dll" 01d8:01dc:trace:module:get_load_order got hardcoded default for L"sechost.dll" 01d8:01dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" at 0x32a700000-0x32a729000 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .text at 0x32a701000 off 1000 size 17000 virt 16e40 flags 60000060 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .data at 0x32a718000 off 18000 size 1000 virt 170 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rodata at 0x32a719000 off 19000 size 1000 virt ef0 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .rdata at 0x32a71a000 off 1a000 size 4000 virt 3830 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .pdata at 0x32a71e000 off 1e000 size 1000 virt bc4 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .xdata at 0x32a71f000 off 1f000 size 1000 virt bf0 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .bss at 0x32a720000 off 0 size 0 virt 1a0 flags c0000080 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .edata at 0x32a721000 off 20000 size 5000 virt 46ae flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .idata at 0x32a726000 off 25000 size 2000 virt 1238 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\sechost.dll" section .reloc at 0x32a728000 off 27000 size 1000 virt f8 flags 42000040 01d8:01dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=4 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=3 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=6 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01d8:01dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\ucrtbase.dll" 01d8:01dc:trace:module:get_load_order got hardcoded default for L"ucrtbase.dll" 01d8:01dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" at 0x3af670000-0x3af730000 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .text at 0x3af671000 off 1000 size 82000 virt 81530 flags 60000060 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .data at 0x3af6f3000 off 83000 size 2000 virt 1ac0 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rodata at 0x3af6f5000 off 85000 size 4000 virt 3988 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rdata at 0x3af6f9000 off 89000 size d000 virt c470 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .pdata at 0x3af706000 off 96000 size 5000 virt 4ddc flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .xdata at 0x3af70b000 off 9b000 size 5000 virt 4834 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .bss at 0x3af710000 off 0 size 0 virt 20c0 flags c0000080 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .edata at 0x3af713000 off a0000 size 19000 virt 186cd flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .idata at 0x3af72c000 off b9000 size 2000 virt 1a80 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .rsrc at 0x3af72e000 off bb000 size 1000 virt 3c8 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" section .reloc at 0x3af72f000 off bc000 size 1000 virt 294 flags 42000040 01d8:01dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=5 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=7 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\ucrtbase.dll" 0000000000433B50 00000003AF670000 01d8:01dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000: builtin 01d8:01dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\ucrtbase.dll" at 00000003AF670000 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\sechost.dll" 0000000000433840 000000032A700000 01d8:01dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\sechost.dll" at 000000032A700000: builtin 01d8:01dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\sechost.dll" at 000000032A700000 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\advapi32.dll" 0000000000433360 0000000330260000 01d8:01dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\advapi32.dll" at 0000000330260000: builtin 01d8:01dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\advapi32.dll" at 0000000330260000 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"gdi32.dll" in (null) 01d8:01dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\gdi32.dll" 01d8:01dc:trace:module:get_load_order got hardcoded default for L"gdi32.dll" 01d8:01dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" at 0x26b4c0000-0x26b53b000 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .text at 0x26b4c1000 off 1000 size 4a000 virt 49d90 flags 60000060 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .data at 0x26b50b000 off 4b000 size 1000 virt 960 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rodata at 0x26b50c000 off 4c000 size 1000 virt d88 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rdata at 0x26b50d000 off 4d000 size 15000 virt 14820 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .pdata at 0x26b522000 off 62000 size 3000 virt 2298 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .xdata at 0x26b525000 off 65000 size 3000 virt 261c flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .bss at 0x26b528000 off 0 size 0 virt 1c0 flags c0000080 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .edata at 0x26b529000 off 68000 size 9000 virt 8565 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .idata at 0x26b532000 off 71000 size 3000 virt 2928 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .rsrc at 0x26b535000 off 74000 size 5000 virt 4230 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\gdi32.dll" section .reloc at 0x26b53a000 off 79000 size 1000 virt 4a4 flags 42000040 01d8:01dc:trace:module:load_dll looking for L"advapi32.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=2 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=6 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=8 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=2 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"user32.dll" in (null) 01d8:01dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\user32.dll" 01d8:01dc:trace:module:get_load_order got hardcoded default for L"user32.dll" 01d8:01dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" at 0x23d820000-0x23d9ec000 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .text at 0x23d821000 off 1000 size a6000 virt a5840 flags 60000060 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .data at 0x23d8c7000 off a7000 size 1000 virt 780 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rodata at 0x23d8c8000 off a8000 size 1000 virt ed0 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rdata at 0x23d8c9000 off a9000 size 19000 virt 189f0 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .pdata at 0x23d8e2000 off c2000 size 6000 virt 528c flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .xdata at 0x23d8e8000 off c8000 size 6000 virt 5668 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .bss at 0x23d8ee000 off 0 size 0 virt 410 flags c0000080 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .edata at 0x23d8ef000 off ce000 size 12000 virt 110f3 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .idata at 0x23d901000 off e0000 size 5000 virt 4e5c flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .rsrc at 0x23d906000 off e5000 size e5000 virt e4818 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" section .reloc at 0x23d9eb000 off 1ca000 size 1000 virt 2dc flags 42000040 01d8:01dc:trace:module:load_dll looking for L"advapi32.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=3 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"gdi32.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\gdi32.dll" for L"gdi32.dll" at 000000026B4C0000, count=2 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=7 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=4 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=9 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"sechost.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\sechost.dll" for L"sechost.dll" at 000000032A700000, count=2 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=3 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"version.dll" in (null) 01d8:01dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\version.dll" 01d8:01dc:trace:module:get_load_order got hardcoded default for L"version.dll" 01d8:01dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" at 0x2f1fa0000-0x2f1fad000 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .text at 0x2f1fa1000 off 1000 size 2000 virt 1fd0 flags 60000020 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .data at 0x2f1fa3000 off 3000 size 1000 virt 70 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rodata at 0x2f1fa4000 off 4000 size 1000 virt 84 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rdata at 0x2f1fa5000 off 5000 size 1000 virt 260 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .pdata at 0x2f1fa6000 off 6000 size 1000 virt f0 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .xdata at 0x2f1fa7000 off 7000 size 1000 virt 10c flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .bss at 0x2f1fa8000 off 0 size 0 virt 140 flags c0000080 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .edata at 0x2f1fa9000 off 8000 size 1000 virt 327 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .idata at 0x2f1faa000 off 9000 size 1000 virt 7a4 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .rsrc at 0x2f1fab000 off a000 size 1000 virt 3b8 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\version.dll" section .reloc at 0x2f1fac000 off b000 size 1000 virt 20 flags 42000040 01d8:01dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=8 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"kernelbase.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernelbase.dll" for L"kernelbase.dll" at 000000007B000000, count=5 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=10 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=4 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\version.dll" 0000000000434500 00000002F1FA0000 01d8:01dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\version.dll" at 00000002F1FA0000: builtin 01d8:01dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\version.dll" at 00000002F1FA0000 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"win32u.dll" in (null) 01d8:01dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\win32u.dll" 01d8:01dc:trace:module:get_load_order got hardcoded default for L"win32u.dll" 01d8:01dc:trace:module:load_builtin L"\\??\\C:\\windows\\system32\\win32u.dll" is a fake Wine dll 01d8:01dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=9 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=11 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\win32u.dll" 0000000000434850 000000006AD60000 01d8:01dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\win32u.dll" at 000000006AD60000: builtin 01d8:01dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\win32u.dll" at 000000006AD60000 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\user32.dll" 00000000004340F0 000000023D820000 01d8:01dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\user32.dll" at 000000023D820000: builtin 01d8:01dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\user32.dll" at 000000023D820000 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"win32u.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\win32u.dll" for L"win32u.dll" at 000000006AD60000, count=2 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\gdi32.dll" 0000000000433E40 000000026B4C0000 01d8:01dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000: builtin 01d8:01dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\gdi32.dll" at 000000026B4C0000 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"kernel32.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=10 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"ntdll.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=12 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"ucrtbase.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=5 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"user32.dll" in (null) 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=2 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - START 01d8:01dc:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_ATTACH,000000000031FB00) 0000000170065B80 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01d8:01dc:trace:module:process_attach (L"ntdll.dll",000000000031FB00) - END 01d8:01dc:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - START 01d8:01dc:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - START 01d8:01dc:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_ATTACH,000000000031FB00) 000000007B03CAD0 - CALL 01d8:01dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x0000001a,0x31f618,0x00000008,0x0) 01d8:01dc:trace:process:GetEnvironmentVariableW (L"WINEUNIXCP" 000000000031F2A0 85) 01d8:01dc:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000000000 0) 01d8:01dc:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4896" 0000000000436C80 17) 01d8:01dc:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000436D90, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 01d8:01dc:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01d8:01dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 01d8:01dc:trace:module:get_load_order got hardcoded default for L"tzres.dll" 01d8:01dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 01d8:01dc:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 01d8:01dc:trace:module:LoadResource 0000000010000002 00000000100077D8 01d8:01dc:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000000000 0) 01d8:01dc:trace:process:ExpandEnvironmentStringsW (L"@tzres.dll,-4897" 0000000000436CD0 17) 01d8:01dc:trace:module:LdrGetDllHandleEx flags 0, load_path 0000000000436EB0, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031EFE8. 01d8:01dc:trace:module:LdrGetDllHandleEx L"C:\\windows\\system32\\tzres.dll" -> 0000000000000000 (load path L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0") 01d8:01dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\tzres.dll" 01d8:01dc:trace:module:get_load_order got hardcoded default for L"tzres.dll" 01d8:01dc:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\tzres.dll" at 0x10000000-0x10073000 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\tzres.dll" section .rsrc at 0x10001000 off 1000 size 72000 virt 71d74 flags 40000040 01d8:01dc:trace:module:FindResourceExW 0000000010000002 #0006 #0133 0000 01d8:01dc:trace:module:LoadResource 0000000010000002 00000000100077D8 01d8:01dc:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01d8:01dc:trace:module:process_attach (L"kernelbase.dll",000000000031FB00) - END 01d8:01dc:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_ATTACH,000000000031FB00) 000000007B631530 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01d8:01dc:trace:module:process_attach (L"kernel32.dll",000000000031FB00) - END 01d8:01dc:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - START 01d8:01dc:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - START 01d8:01dc:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_ATTACH,000000000031FB00) 00000001C8E1AB00 - CALL 01d8:01dc:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F3B0. 01d8:01dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 01d8:01dc:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F400. 01d8:01dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 01d8:01dc:trace:module:LdrAddRefDll (L"msvcrt.dll") ldr.LoadCount: -1 01d8:01dc:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01d8:01dc:trace:module:process_attach (L"msvcrt.dll",000000000031FB00) - END 01d8:01dc:trace:module:process_attach (L"sechost.dll",000000000031FB00) - START 01d8:01dc:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - START 01d8:01dc:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_ATTACH,000000000031FB00) 00000003AF6F1C30 - CALL 01d8:01dc:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F320. 01d8:01dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 01d8:01dc:trace:module:LdrGetDllFullName module 0000000000000000, name 000000000031F370. 01d8:01dc:trace:module:GetModuleFileNameW L"C:\\windows\\system32\\conhost.exe" 01d8:01dc:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01d8:01dc:trace:module:process_attach (L"ucrtbase.dll",000000000031FB00) - END 01d8:01dc:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_ATTACH,000000000031FB00) 000000032A716FC0 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01d8:01dc:trace:module:process_attach (L"sechost.dll",000000000031FB00) - END 01d8:01dc:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_ATTACH,000000000031FB00) 0000000330283EC0 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01d8:01dc:trace:module:process_attach (L"advapi32.dll",000000000031FB00) - END 01d8:01dc:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - START 01d8:01dc:trace:module:process_attach (L"user32.dll",000000000031FB00) - START 01d8:01dc:trace:module:process_attach (L"version.dll",000000000031FB00) - START 01d8:01dc:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000031FB00) 00000002F1FA2510 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01d8:01dc:trace:module:process_attach (L"version.dll",000000000031FB00) - END 01d8:01dc:trace:module:process_attach (L"win32u.dll",000000000031FB00) - START 01d8:01dc:trace:module:MODULE_InitDLL (000000006AD60000 L"win32u.dll",PROCESS_ATTACH,000000000031FB00) 000000006AE09460 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (000000006AB60000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01d0:01d4:trace:module:process_attach (L"win32u.dll",000000000021FB00) - END 01d0:01d4:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000021FB00) 000000026B509F00 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01d0:01d4:trace:module:process_attach (L"gdi32.dll",000000000021FB00) - END 01d0:01d4:trace:module:process_attach (L"version.dll",000000000021FB00) - START 01d0:01d4:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_ATTACH,000000000021FB00) 00000002F1FA2510 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01d0:01d4:trace:module:process_attach (L"version.dll",000000000021FB00) - END 01d0:01d4:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000021FB00) 000000023D8C5690 - CALL 01d0:01d4:trace:module:load_dll looking for L"imm32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d0:01d4:trace:module:get_load_order looking for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 01d0:01d4:trace:module:get_load_order got hardcoded default for L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 01d0:01d4:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 01d0:01d4:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d0:01d4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"user32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:build_module loaded L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" 0000000000342050 00000003AFD00000 01d0:01d4:trace:loaddll:build_module Loaded L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000: builtin 01d0:01d4:trace:module:load_dll Loaded module L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 00000003AFD00000 01d0:01d4:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 01d0:01d4:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 01d0:01d4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021EBB0, base 000000000021EBA8. 01d0:01d4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01d0:01d4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F050, base 000000000021F048. 01d0:01d4:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 01d0:01d4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021EB60, base 000000000021EB58. 01d0:01d4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01d0:01d4:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 01d0:01d4:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 01d0:01d4:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01d0:01d4:trace:module:process_attach (L"user32.dll",000000000021FB00) - END 01d0:01d4:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_ATTACH,000000000021FB00) 00000001DD4524D0 - CALL 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #003f 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D0D0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0040 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D2C0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0041 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D4B0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0042 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D6A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0043 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47D8A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0044 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DAB0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0046 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DE90 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0047 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E080 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0045 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47DCA0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01d0:01d4:trace:module:FindResourceExW 00000001DD3F0000 #0006 #0048 0000 01d0:01d4:trace:module:LoadResource 00000001DD3F0000 00000001DD47E2A0 01d0:01d4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021F600, base 000000000021F5F8. 01d0:01d4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01d0:01d4:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_ATTACH,000000000021FB00) - RETURN 1 01d0:01d4:trace:module:process_attach (L"crypt32.dll",000000000021FB00) - END 01d0:01d4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x21f8b8,0x00000008,0x0) 01d0:01d4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021C4E0, base 000000000021C4D8. 01d0:01d4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01d0:01d4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021C1F0, base 000000000021C1E8. 01d0:01d4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01d0:01d4:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\rsaenh.dll" 0000000000000000 0) 01d0:01d4:trace:process:ExpandEnvironmentStringsW (L"C:\\windows\\system32\\rsaenh.dll" 0000000000341E30 31) 01d0:01d4:trace:module:load_dll looking for L"C:\\windows\\system32\\rsaenh.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d0:01d4:trace:module:get_load_order looking for L"C:\\windows\\system32\\rsaenh.dll" 01d0:01d4:trace:module:get_load_order_value got app defaults b for L"rsaenh" 01d0:01d4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\rsaenh.dll" at 0x2de970000-0x2de9a2000 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .text at 0x2de971000 off 1000 size 16000 virt 15700 flags 60000020 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .data at 0x2de987000 off 17000 size 1000 virt 80 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .rodata at 0x2de988000 off 18000 size 1000 virt 8c flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .rdata at 0x2de989000 off 19000 size 12000 virt 114e0 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .pdata at 0x2de99b000 off 2b000 size 1000 virt 840 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .xdata at 0x2de99c000 off 2c000 size 1000 virt a8c flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .bss at 0x2de99d000 off 0 size 0 virt 190 flags c0000080 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .edata at 0x2de99e000 off 2d000 size 1000 virt df8 flags 40000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .idata at 0x2de99f000 off 2e000 size 1000 virt adc flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .rsrc at 0x2de9a0000 off 2f000 size 1000 virt fc8 flags c0000040 01d0:01d4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\rsaenh.dll" section .reloc at 0x2de9a1000 off 30000 size 1000 virt 24 flags 42000040 01d0:01d4:trace:module:load_dll looking for L"advapi32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"bcrypt.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\bcrypt.dll" for L"bcrypt.dll" at 00000002D4D40000, count=-1 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"crypt32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\crypt32.dll" for L"crypt32.dll" at 00000001DD3F0000, count=-1 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"kernel32.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ntdll.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d0:01d4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:load_dll looking for L"ucrtbase.dll" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d0:01d4:trace:module:load_dll Found L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 01d0:01d4:trace:module:import_dll is not hybrid module 01d0:01d4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\rsaenh.dll" 000000000033F980 00000002DE970000 01d0:01d4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\rsaenh.dll" at 00000002DE970000: builtin 01d0:01d4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\rsaenh.dll" at 00000002DE970000 01d0:01d4:trace:module:process_attach (L"rsaenh.dll",0000000000000000) - START 01d0:01d4:trace:module:MODULE_InitDLL (00000002DE970000 L"rsaenh.dll",PROCESS_ATTACH,0000000000000000) 00000002DE9858F0 - CALL 01d0:01d4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021BB80, base 000000000021BB78. 01d0:01d4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01d0:01d4:trace:module:MODULE_InitDLL (00000002DE970000,PROCESS_ATTACH,0000000000000000) - RETURN 1 01d0:01d4:trace:module:process_attach (L"rsaenh.dll",0000000000000000) - END 01d0:01d4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021C2D0, base 000000000021C2C8. 01d0:01d4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01d0:01d4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021BFC0, base 000000000021BFB8. 01d0:01d4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01d0:01d4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021C4E0, base 000000000021C4D8. 01d0:01d4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01d0:01d4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000021C1E0, base 000000000021C1D8. 01d0:01d4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01d0:01d4:trace:module:LdrUnloadDll (00000002DE970000) 01d0:01d4:trace:module:LdrUnloadDll (L"rsaenh.dll") - START 01d0:01d4:trace:module:MODULE_DecRefCount (L"rsaenh.dll") ldr.LoadCount: 0 01d0:01d4:trace:module:MODULE_InitDLL (00000002DE970000 L"rsaenh.dll",PROCESS_DETACH,0000000000000000) 00000002DE9858F0 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (00000002DE970000,PROCESS_DETACH,0000000000000000) - RETURN 1 01d0:01d4:trace:module:free_modref unloading L"C:\\windows\\system32\\rsaenh.dll" 01d0:01d4:trace:module:LdrUnloadDll END 01d8:01dc:trace:module:MODULE_InitDLL (000000006AD60000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01d8:01dc:trace:module:process_attach (L"win32u.dll",000000000031FB00) - END 01d8:01dc:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_ATTACH,000000000031FB00) 000000023D8C5690 - CALL 01d8:01dc:trace:module:load_dll looking for L"imm32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d8:01dc:trace:module:get_load_order looking for L"C:\\windows\\system32\\imm32.dll" 01d8:01dc:trace:module:get_load_order got hardcoded default for L"imm32.dll" 01d8:01dc:trace:module:map_image_into_view mapping PE file L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" at 0x3afd00000-0x3afd1a000 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .text at 0x3afd01000 off 1000 size c000 virt b430 flags 60000060 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .data at 0x3afd0d000 off d000 size 1000 virt 120 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rodata at 0x3afd0e000 off e000 size 1000 virt 3ec flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rdata at 0x3afd0f000 off f000 size 2000 virt 1c90 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .pdata at 0x3afd11000 off 11000 size 1000 virt 60c flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .xdata at 0x3afd12000 off 12000 size 1000 virt 6ec flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .bss at 0x3afd13000 off 0 size 0 virt 160 flags c0000080 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .edata at 0x3afd14000 off 13000 size 3000 virt 2b29 flags 40000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .idata at 0x3afd17000 off 16000 size 1000 virt cd8 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .rsrc at 0x3afd18000 off 17000 size 1000 virt 3a8 flags c0000040 01d8:01dc:trace:module:map_image_into_view mapping L"\\??\\Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows\\imm32.dll" section .reloc at 0x3afd19000 off 18000 size 1000 virt 50 flags 42000040 01d8:01dc:trace:module:load_dll looking for L"advapi32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\advapi32.dll" for L"advapi32.dll" at 0000000330260000, count=-1 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"kernel32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\kernel32.dll" for L"kernel32.dll" at 000000007B600000, count=-1 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"ntdll.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=-1 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"ucrtbase.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\ucrtbase.dll" for L"ucrtbase.dll" at 00000003AF670000, count=-1 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:load_dll looking for L"user32.dll" in L"C:\\windows\\system32;C:\\windows\\system32;C:\\windows\\system;C:\\windows;.;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d8:01dc:trace:module:load_dll Found L"C:\\windows\\system32\\user32.dll" for L"user32.dll" at 000000023D820000, count=-1 01d8:01dc:trace:module:import_dll is not hybrid module 01d8:01dc:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\imm32.dll" 000000000043EAC0 00000003AFD00000 01d8:01dc:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\imm32.dll" at 00000003AFD00000: builtin 01d8:01dc:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\imm32.dll" at 00000003AFD00000 01d8:01dc:trace:module:process_attach (L"imm32.dll",0000000000000000) - START 01d8:01dc:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_ATTACH,0000000000000000) 00000003AFD0B870 - CALL 01d8:01dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EBB0, base 000000000031EBA8. 01d8:01dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01d8:01dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F050, base 000000000031F048. 01d8:01dc:trace:module:LdrGetDllHandleEx L"imm32.dll" -> 00000003AFD00000 (load path (null)) 01d8:01dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031EB60, base 000000000031EB58. 01d8:01dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01d8:01dc:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_ATTACH,0000000000000000) - RETURN 1 01d8:01dc:trace:module:process_attach (L"imm32.dll",0000000000000000) - END 01d8:01dc:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01d8:01dc:trace:module:process_attach (L"user32.dll",000000000031FB00) - END 01d8:01dc:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_ATTACH,000000000031FB00) 000000026B509F00 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_ATTACH,000000000031FB00) - RETURN 1 01d8:01dc:trace:module:process_attach (L"gdi32.dll",000000000031FB00) - END 01d8:01dc:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000007,0x31f8b8,0x00000008,0x0) 01d8:01dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FA50, base 000000000031FA48. 01d8:01dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01d8:01dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031F5E0, base 000000000031F5D8. 01d8:01dc:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01d0:01d4:trace:process:CreateProcessInternalW app (null) cmdline L"\"Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe\" /T:C:\\users\\crossover\\Temp\\tmposz1e95z /C" 01d0:01d4:trace:process:find_exe_file looking for L"Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe" in L"Z:\\Volumes\\HackNVMe\\Applications\\CrossOver.app\\Contents\\SharedSupport\\CrossOver\\lib\\wine\\x86_64-windows;.;C:\\windows\\system32;C:\\windows\\system;C:\\windows;C:\\windows\\system32;C:\\windows;C:\\windows\\system32\\wbem;C:\\windows\\system32\\WindowsPowershell\\v1.0" 01d0:01d4:trace:process:NtCreateUserProcess L"\\??\\Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe" image L"Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe" cmdline L"\"Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe\" /T:C:\\users\\crossover\\Temp\\tmposz1e95z /C" parent 0x0 01d0:01d4:trace:process:send_to_cx_loader loader (null) wineserversocket 12 stdin_fd 0 stdout_fd 1 unixdir (null) winedebug "WINEDEBUG=+pid,+process,+module,+loaddll,+seh,+threadname" wineloader (null) 01d0:01d4:trace:process:send_to_cx_loader CX_ALT_LOADER_SOCKET is not set; nothing to do preloader: Warning: failed to reserve range 0000000000010000-0000000000110000 01e0:01e4:trace:module:get_load_order looking for L"Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe" 01e0:01e4:trace:module:get_load_order got main exe default n,b for L"Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe" 01e0:01e4:trace:module:get_load_order looking for L"Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe" 01e0:01e4:trace:module:get_load_order got main exe default n,b for L"Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe" 01e0:01e4:trace:module:map_image_into_view mapping PE file L"\\??\\Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe" at 0x1000000-0x1089000 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe" section .text at 0x1001000 off 1000 size 9000 virt 8e48 flags 60000020 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe" section .data at 0x100a000 off a000 size 400 virt 1c0c flags c0000040 01e0:01e4:trace:module:map_image_into_view clearing 0x100a400 - 0x100b000 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe" section .rsrc at 0x100c000 off a400 size 7c600 virt 7d000 flags 40000040 01e0:01e4:trace:module:map_image_into_view clearing 0x1088600 - 0x1089000 01e0:01e4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\ntdll.dll" at 0x170000000-0x17009d000 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .text at 0x170001000 off 1000 size 65000 virt 64f30 flags 60000020 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .data at 0x170066000 off 66000 size 1000 virt e80 flags c0000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rodata at 0x170067000 off 67000 size 2000 virt 1f40 flags c0000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rdata at 0x170069000 off 69000 size 12000 virt 11d50 flags 40000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .pdata at 0x17007b000 off 7b000 size 4000 virt 31a4 flags 40000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .xdata at 0x17007f000 off 7f000 size 4000 virt 33b0 flags 40000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .bss at 0x170083000 off 0 size 0 virt 34f0 flags c0000080 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .edata at 0x170087000 off 83000 size 13000 virt 120bf flags 40000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .idata at 0x17009a000 off 96000 size 1000 virt 14 flags c0000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .rsrc at 0x17009b000 off 97000 size 1000 virt 3b0 flags c0000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\ntdll.dll" section .reloc at 0x17009c000 off 98000 size 1000 virt 184 flags 42000040 01e0:01e4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\syswow64\\ntdll.dll" at 0x7bc00000-0x7bc97000 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .text at 0x7bc01000 off 1000 size 66000 virt 652b8 flags 60000020 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .data at 0x7bc67000 off 67000 size 1000 virt b60 flags c0000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .rodata at 0x7bc68000 off 68000 size 2000 virt 1ff4 flags c0000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .rdata at 0x7bc6a000 off 6a000 size 11000 virt 10568 flags 40000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .bss at 0x7bc7b000 off 0 size 0 virt 24e4 flags c0000080 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .edata at 0x7bc7e000 off 7b000 size 13000 virt 12769 flags 40000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .idata at 0x7bc91000 off 8e000 size 1000 virt 14 flags c0000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .rsrc at 0x7bc92000 off 8f000 size 1000 virt 3ac flags c0000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\syswow64\\ntdll.dll" section .reloc at 0x7bc93000 off 90000 size 4000 virt 3e18 flags 42000040 01e0:01e4:trace:module:load_wow64_ntdll loaded L"\\??\\C:\\windows\\syswow64\\ntdll.dll" at 0x7bc00000 01e0:01e4:fixme:module:dlopen_32on64_opengl32 loaded "/Volumes/HackNVMe/Applications/CrossOver.app/Contents/SharedSupport/CrossOver/lib/wine/x86_32on64-unix/opengl32.dll.so" early @ 0x6b22c000 01e0:01e4:trace:module:load_apiset_dll loaded L"\\??\\C:\\windows\\system32\\apisetschema.dll" apiset at 0x431000 01d0:01d4:trace:process:NtCreateUserProcess L"\\??\\Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe" pid 01e0 tid 01e4 handles 0x70/0x74 01d0:01d4:trace:process:CreateProcessInternalW started process pid 01e0 tid 01e4 01e0:01e4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x32f790,0x00000040,0x0) 01e0:01e4:warn:module:alloc_module disabling no-exec because of L"ddca80018c86ae60c185f1db3c283788.arial32.exe" 01e0:01e4:trace:module:build_module loaded L"\\??\\Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe" 0000000000442BD0 0000000001000000 01e0:01e4:trace:loaddll:build_module Loaded L"Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe" at 0000000001000000: native 01e0:01e4:trace:module:load_dll looking for L"C:\\windows\\system32\\wow64.dll" in (null) 01e0:01e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\wow64.dll" 01e0:01e4:trace:module:get_load_order got hardcoded default for L"wow64.dll" 01e0:01e4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\wow64.dll" at 0x6f000000-0x6f026000 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .text at 0x6f001000 off 1000 size 12000 virt 11ab0 flags 60000020 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .data at 0x6f013000 off 13000 size 1000 virt 840 flags c0000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .rodata at 0x6f014000 off 14000 size 1000 virt 2a8 flags c0000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .rdata at 0x6f015000 off 15000 size 3000 virt 2c70 flags 40000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .pdata at 0x6f018000 off 18000 size 1000 virt d68 flags 40000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .xdata at 0x6f019000 off 19000 size 1000 virt d5c flags 40000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .bss at 0x6f01a000 off 0 size 0 virt 4160 flags c0000080 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .edata at 0x6f01f000 off 1a000 size 3000 virt 2c2c flags 40000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .idata at 0x6f022000 off 1d000 size 3000 virt 2908 flags c0000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64.dll" section .reloc at 0x6f025000 off 20000 size 1000 virt 3f8 flags 42000040 01e0:01e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01e0:01e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=2 01e0:01e4:trace:module:import_dll is not hybrid module 01e0:01e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wow64.dll" 0000000000443060 000000006F000000 01e0:01e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wow64.dll" at 000000006F000000: builtin 01e0:01e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wow64.dll" at 000000006F000000 01e0:01e4:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000032F3C0, base 000000000032F3B0. 01e0:01e4:trace:module:LdrGetDllHandleEx L"ntdll.dll" -> 0000000170000000 (load path (null)) 01e0:01e4:trace:module:load_dll looking for L"\\??\\C:\\windows\\system32\\wow64cpu.dll" in (null) 01e0:01e4:trace:module:get_load_order looking for L"C:\\windows\\system32\\wow64cpu.dll" 01e0:01e4:trace:module:get_load_order got hardcoded default for L"wow64cpu.dll" 01e0:01e4:trace:module:map_image_into_view mapping PE file L"\\??\\C:\\windows\\system32\\wow64cpu.dll" at 0x6f100000-0x6f10c000 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .text at 0x6f101000 off 1000 size 1000 virt 7c0 flags 60000020 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .data at 0x6f102000 off 2000 size 1000 virt 40 flags c0000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .rodata at 0x6f103000 off 3000 size 1000 virt 24 flags c0000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .rdata at 0x6f104000 off 4000 size 1000 virt a0 flags 40000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .pdata at 0x6f105000 off 5000 size 1000 virt 84 flags 40000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .xdata at 0x6f106000 off 6000 size 1000 virt 5c flags 40000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .bss at 0x6f107000 off 0 size 0 virt 2000 flags c0000080 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .edata at 0x6f109000 off 7000 size 1000 virt 21e flags 40000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .idata at 0x6f10a000 off 8000 size 1000 virt 21c flags c0000040 01e0:01e4:trace:module:map_image_into_view mapping L"\\??\\C:\\windows\\system32\\wow64cpu.dll" section .reloc at 0x6f10b000 off 9000 size 1000 virt 1c flags 42000040 01e0:01e4:trace:module:load_dll looking for L"ntdll.dll" in (null) 01e0:01e4:trace:module:load_dll Found L"C:\\windows\\system32\\ntdll.dll" for L"ntdll.dll" at 0000000170000000, count=3 01e0:01e4:trace:module:import_dll is not hybrid module 01e0:01e4:trace:module:load_dll looking for L"wow64.dll" in (null) 01e0:01e4:trace:module:load_dll Found L"C:\\windows\\system32\\wow64.dll" for L"wow64.dll" at 000000006F000000, count=2 01e0:01e4:trace:module:import_dll is not hybrid module 01e0:01e4:trace:module:build_module loaded L"\\??\\C:\\windows\\system32\\wow64cpu.dll" 0000000000443290 000000006F100000 01e0:01e4:trace:loaddll:build_module Loaded L"C:\\windows\\system32\\wow64cpu.dll" at 000000006F100000: builtin 01e0:01e4:trace:module:load_dll Loaded module L"\\??\\C:\\windows\\system32\\wow64cpu.dll" at 000000006F100000 01e0:01e4:trace:module:process_attach (L"wow64cpu.dll",0000000000000000) - START 01e0:01e4:trace:module:process_attach (L"wow64.dll",0000000000000000) - START 01e0:01e4:trace:module:MODULE_InitDLL (000000006F000000 L"wow64.dll",PROCESS_ATTACH,0000000000000000) 000000006F012780 - CALL 01e0:01e4:trace:module:MODULE_InitDLL (000000006F000000,PROCESS_ATTACH,0000000000000000) - RETURN 1 01e0:01e4:trace:module:process_attach (L"wow64.dll",0000000000000000) - END 01e0:01e4:trace:module:MODULE_InitDLL (000000006F100000 L"wow64cpu.dll",PROCESS_ATTACH,0000000000000000) 000000006F101790 - CALL 01e0:01e4:trace:module:MODULE_InitDLL (000000006F100000,PROCESS_ATTACH,0000000000000000) - RETURN 1 01e0:01e4:trace:module:process_attach (L"wow64cpu.dll",0000000000000000) - END 01e0:01e4:trace:process:NtQueryInformationProcess (0xffffffffffffffff,0x00000025,0x32ef70,0x00000040,0x0) 01e0:01e4:warn:module:alloc_module disabling no-exec because of L"ddca80018c86ae60c185f1db3c283788.arial32.exe" 01e0:01e4:trace:module:build_module loaded L"\\??\\Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe" 00552950 01000000 01e0:01e4:trace:loaddll:build_module Loaded L"Y:\\Library\\Application Support\\CrossOver\\installers\\ddca80018c86ae60c185f1db3c283788.arial32.exe" at 01000000: native 01e0:01e4:trace:module:load_dll looking for L"kernel32.dll" in (null) 01e0:01e4:warn:module:load_dll Failed to load module L"kernel32.dll"; status=c0000135 wine: could not load kernel32.dll, status c0000135 01d0:01d4:trace:process:NtQueryInformationProcess (0x70,0x00000000,0x21f1d0,0x00000030,0x0) 01d0:01d4:trace:module:LdrShutdownProcess () 01d0:01d4:trace:module:MODULE_InitDLL (00000001DD3F0000 L"crypt32.dll",PROCESS_DETACH,0000000000000001) 00000001DD4524D0 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (00000001DD3F0000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d0:01d4:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d0:01d4:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d0:01d4:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d0:01d4:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d0:01d4:trace:module:MODULE_InitDLL (000000006AB60000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006AC09460 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (000000006AB60000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d0:01d4:trace:module:MODULE_InitDLL (00000002D4D40000 L"bcrypt.dll",PROCESS_DETACH,0000000000000001) 00000002D4D49C40 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (00000002D4D40000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d0:01d4:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d0:01d4:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d0:01d4:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d0:01d4:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d0:01d4:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d0:01d4:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d0:01d4:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 01d0:01d4:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d8:01dc:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FD50, base 000000000031FD48. 01d8:01dc:trace:module:LdrGetDllHandleEx L"mscoree" -> 0000000000000000 (load path (null)) 01d8:01dc:trace:module:LdrShutdownProcess () 01d8:01dc:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d8:01dc:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d8:01dc:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d8:01dc:trace:module:MODULE_InitDLL (000000006AD60000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006AE09460 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (000000006AD60000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d8:01dc:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d8:01dc:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d8:01dc:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d8:01dc:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d8:01dc:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d8:01dc:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d8:01dc:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 01d8:01dc:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 01d8:01dc:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:LdrShutdownProcess () 0094:0098:trace:module:MODULE_InitDLL (00000001D0830000 L"actxprxy.dll",PROCESS_DETACH,0000000000000001) 00000001D09254B0 - CALL 0094:0098:trace:module:MODULE_InitDLL (00000001D0830000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (00000002739C0000 L"oleaut32.dll",PROCESS_DETACH,0000000000000001) 0000000273A6A370 - CALL 0094:0098:trace:module:MODULE_InitDLL (00000002739C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (00000001C69E0000 L"shell32.dll",PROCESS_DETACH,0000000000000001) 00000001C6A688D0 - CALL 0094:0098:trace:module:MODULE_InitDLL (00000001C69E0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (00000002E3540000 L"shlwapi.dll",PROCESS_DETACH,0000000000000001) 00000002E355DE00 - CALL 0094:0098:trace:module:MODULE_InitDLL (00000002E3540000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (00000003126F0000 L"shcore.dll",PROCESS_DETACH,0000000000000001) 00000003126F8FD0 - CALL 0094:0098:trace:module:MODULE_InitDLL (00000003126F0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (00000002E8F10000 L"ole32.dll",PROCESS_DETACH,0000000000000001) 00000002E8FB74E0 - CALL 0094:0098:trace:module:MODULE_InitDLL (00000002E8F10000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (0000000327020000 L"combase.dll",PROCESS_DETACH,0000000000000001) 00000003270465C0 - CALL 00a8:01e8:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 00a8:01e8:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:01e8:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 00a8:01e8:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 00a8:01e8:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 00a8:01e8:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (0000000327020000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (000000006DD10000 L"winemac.drv",PROCESS_DETACH,0000000000000001) 000000006DD28C10 - CALL 0094:0098:trace:module:MODULE_InitDLL (000000006DD10000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_DETACH,0000000000000001) 0000000231B26040 - CALL 0094:0098:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (000000026B4C0000 L"gdi32.dll",PROCESS_DETACH,0000000000000001) 000000026B509F00 - CALL 0094:0098:trace:module:MODULE_InitDLL (000000026B4C0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (00000003AFD00000 L"imm32.dll",PROCESS_DETACH,0000000000000001) 00000003AFD0B870 - CALL 0094:0098:trace:module:MODULE_InitDLL (00000003AFD00000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (000000023D820000 L"user32.dll",PROCESS_DETACH,0000000000000001) 000000023D8C5690 - CALL 0094:0098:trace:module:MODULE_InitDLL (000000023D820000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (000000006AB60000 L"win32u.dll",PROCESS_DETACH,0000000000000001) 000000006AC09460 - CALL 0094:0098:trace:module:MODULE_InitDLL (000000006AB60000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 0094:0098:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 0094:0098:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 0094:0098:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 0094:0098:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 0094:0098:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 0094:0098:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 0094:0098:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0094:0098:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 0094:0098:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1 00a8:00c4:trace:module:LdrShutdownThread () 00a8:00c4:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_DETACH,0000000000000000) 0000000231B26040 - CALL 00a8:00c4:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_DETACH,0000000000000000) - RETURN 1 00a8:00c4:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_DETACH,0000000000000000) 00000003AF6F1C30 - CALL 00a8:00c4:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_DETACH,0000000000000000) - RETURN 1 00a8:00c4:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_DETACH,0000000000000000) 00000001C8E1AB00 - CALL 00a8:00c4:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_DETACH,0000000000000000) - RETURN 1 0044:0048:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266D4, 0x00000000) 005c:0060:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266D4, 0x00000000) 00a8:00ac:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266D4, 0x00000000) 0074:0078:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266D4, 0x00000000) 00fc:0100:trace:module:LdrResolveDelayLoadedAPI (000000032A700000, 000000032A717E00, 0000000000000000, 000000007B60C498, 000000032A7266D4, 0x00000000) 0030:004c:trace:module:LdrShutdownThread () 0030:004c:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_DETACH,0000000000000000) 0000000231B26040 - CALL 0030:004c:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:004c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_DETACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:004c:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:004c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_DETACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:004c:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:01ec:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:01ec:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:007c:trace:module:LdrShutdownThread () 0030:01ec:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:01ec:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:01ec:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:01ec:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:007c:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_DETACH,0000000000000000) 0000000231B26040 - CALL 0030:007c:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:007c:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_DETACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:007c:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:007c:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_DETACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:007c:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:01f0:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:01f0:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:01f0:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:01f0:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:01f0:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:01f0:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:01f4:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:01f4:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:01f4:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:01f4:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:00b0:trace:module:LdrShutdownThread () 0030:01f4:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:0104:trace:module:LdrShutdownThread () 0030:01f4:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:00b0:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_DETACH,0000000000000000) 0000000231B26040 - CALL 0030:00b0:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:00b0:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_DETACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:00b0:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:00b0:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_DETACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:00b0:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:0064:trace:module:LdrShutdownThread () 0030:0104:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_DETACH,0000000000000000) 0000000231B26040 - CALL 0030:0104:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:0104:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_DETACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:0104:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:0104:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_DETACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:0104:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:01f8:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_ATTACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:01f8:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:01f8:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_ATTACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:01f8:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:01f8:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_ATTACH,0000000000000000) 0000000231B26040 - CALL 0030:01f8:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_ATTACH,0000000000000000) - RETURN 1 0030:0064:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_DETACH,0000000000000000) 0000000231B26040 - CALL 0030:0064:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:0064:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_DETACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:0064:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:0064:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_DETACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:0064:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:0038:trace:module:LdrShutdownThread () 0030:0038:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",THREAD_DETACH,0000000000000000) 0000000231B26040 - CALL 0030:0038:trace:module:MODULE_InitDLL (0000000231AE0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:0038:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",THREAD_DETACH,0000000000000000) 00000003AF6F1C30 - CALL 0030:0038:trace:module:MODULE_InitDLL (00000003AF670000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:0038:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",THREAD_DETACH,0000000000000000) 00000001C8E1AB00 - CALL 0030:0038:trace:module:MODULE_InitDLL (00000001C8DB0000,THREAD_DETACH,0000000000000000) - RETURN 1 0030:0034:trace:module:LdrGetDllHandleEx flags 0x1, load_path 0000000000000000, dll_characteristics 0000000000000000, name 000000000031FD50, base 000000000031FD48. 0030:0034:trace:module:LdrGetDllHandleEx L"mscoree" -> 0000000000000000 (load path (null)) 0030:0034:trace:module:LdrShutdownProcess () 0030:0034:trace:module:MODULE_InitDLL (0000000388E20000 L"userenv.dll",PROCESS_DETACH,0000000000000001) 0000000388E23A50 - CALL 0030:0034:trace:module:MODULE_InitDLL (0000000388E20000,PROCESS_DETACH,0000000000000001) - RETURN 1 0030:0034:trace:module:MODULE_InitDLL (000000021A7E0000 L"setupapi.dll",PROCESS_DETACH,0000000000000001) 000000021A816860 - CALL 0030:0034:trace:module:MODULE_InitDLL (000000021A7E0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0030:0034:trace:module:MODULE_InitDLL (00000002F1FA0000 L"version.dll",PROCESS_DETACH,0000000000000001) 00000002F1FA2510 - CALL 0030:0034:trace:module:MODULE_InitDLL (00000002F1FA0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0030:0034:trace:module:MODULE_InitDLL (0000000231AE0000 L"rpcrt4.dll",PROCESS_DETACH,0000000000000001) 0000000231B26040 - CALL 0030:0034:trace:module:MODULE_InitDLL (0000000231AE0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0030:0034:trace:module:MODULE_InitDLL (0000000330260000 L"advapi32.dll",PROCESS_DETACH,0000000000000001) 0000000330283EC0 - CALL 0030:0034:trace:module:MODULE_InitDLL (0000000330260000,PROCESS_DETACH,0000000000000001) - RETURN 1 0030:0034:trace:module:MODULE_InitDLL (000000032A700000 L"sechost.dll",PROCESS_DETACH,0000000000000001) 000000032A716FC0 - CALL 0030:0034:trace:module:MODULE_InitDLL (000000032A700000,PROCESS_DETACH,0000000000000001) - RETURN 1 0030:0034:trace:module:MODULE_InitDLL (00000003AF670000 L"ucrtbase.dll",PROCESS_DETACH,0000000000000001) 00000003AF6F1C30 - CALL 0030:0034:trace:module:MODULE_InitDLL (00000003AF670000,PROCESS_DETACH,0000000000000001) - RETURN 1 0030:0034:trace:module:MODULE_InitDLL (00000001C8DB0000 L"msvcrt.dll",PROCESS_DETACH,0000000000000001) 00000001C8E1AB00 - CALL 0030:0034:trace:module:MODULE_InitDLL (00000001C8DB0000,PROCESS_DETACH,0000000000000001) - RETURN 1 0030:0034:trace:module:MODULE_InitDLL (000000007B600000 L"kernel32.dll",PROCESS_DETACH,0000000000000001) 000000007B631530 - CALL 0030:0034:trace:module:MODULE_InitDLL (000000007B600000,PROCESS_DETACH,0000000000000001) - RETURN 1 0030:0034:trace:module:MODULE_InitDLL (000000007B000000 L"kernelbase.dll",PROCESS_DETACH,0000000000000001) 000000007B03CAD0 - CALL 0030:0034:trace:module:MODULE_InitDLL (000000007B000000,PROCESS_DETACH,0000000000000001) - RETURN 1 0030:0034:trace:module:MODULE_InitDLL (0000000170000000 L"ntdll.dll",PROCESS_DETACH,0000000000000001) 0000000170065B80 - CALL 0030:0034:trace:module:MODULE_InitDLL (0000000170000000,PROCESS_DETACH,0000000000000001) - RETURN 1