SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (win32ss/user/ntuser/painting.c:1472) err: BP: Another thread invalidated this window (win32ss/user/ntuser/painting.c:1542) err: EP: Another thread invalidated this window (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (win32ss/user/ntuser/msgqueue.c:1266) err: MsqSendMessage timed out 2 Status 102 (win32ss/user/ntuser/painting.c:1472) err: BP: Another thread invalidated this window (win32ss/user/ntuser/painting.c:1542) err: EP: Another thread invalidated this window (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/mm/balance.c:146) MM BALANCER: Removing access bit! (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/mm/balance.c:146) MM BALANCER: Removing access bit! (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/cursoricon.c:1929) err: NtGdiAlphaBlend failed! (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (ntoskrnl/mm/balance.c:146) MM BALANCER: Removing access bit! (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/mm/balance.c:146) MM BALANCER: Removing access bit! (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (win32ss/user/ntuser/painting.c:1472) err: BP: Another thread invalidated this window (win32ss/user/ntuser/painting.c:1542) err: EP: Another thread invalidated this window (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/mm/balance.c:146) MM BALANCER: Removing access bit! (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (ntoskrnl/mm/balance.c:146) MM BALANCER: Removing access bit! (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (win32ss/user/ntuser/message.c:946) err: Message WM_PAINT count 1 Internal Paint Set? FALSE (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/mm/balance.c:146) MM BALANCER: Removing access bit! (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/mm/balance.c:146) MM BALANCER: Removing access bit! (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/mm/balance.c:146) MM BALANCER: Removing access bit! (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/mm/balance.c:146) MM BALANCER: Removing access bit! (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/mm/balance.c:146) MM BALANCER: Removing access bit! (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/mm/balance.c:146) MM BALANCER: Removing access bit! (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (ntoskrnl/se/accesschk.c:708) SepAccessCheck(): Failed to grant access rights. RemainingAccess = 0x00000008 DesiredAccess = 0x00000008 ================== SECURITY DESCRIPTOR DUMP INFO ================== SecurityDescriptor -> 0xE24DDCC0 SecurityDescriptor->Revision -> 1 SecurityDescriptor->Control: SE_DACL_PRESENT SE_SELF_RELATIVE SD Owner SID -> S-1-5-20 SD Group SID -> S-1-5-20 ================== DACL DUMP INFO ================== Acl->AclRevision -> 2 Acl->AclSize -> 48 Acl->AceCount -> 2 ================== 0# ACE DUMP INFO ================== Ace -> 0xE24DDCDC Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-20 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== 1# ACE DUMP INFO ================== Ace -> 0xE24DDCF0 Ace->Header -> 0x00140000 Ace->Header.AceType -> ACCESS_ALLOWED_ACE_TYPE Ace->AccessMask -> 0x000f01ff Ace SID -> S-1-5-18 Ace->Header.AceSize -> 20 Ace->Header.AceFlags: ================== ACCESS TOKEN DUMP INFO ================== Token -> 0xE286C030 Token->ImageFileName -> explorer.exe Token->TokenSource.SourceName -> "User32 " Token->TokenSource.SourceIdentifier -> 0.8152 Token primary group SID -> S-1-5-21-1955263365-1592473226-1724592899-513 Token user and groups SIDs: 0# S-1-5-21-1955263365-1592473226-1724592899-500 1# S-1-5-21-1955263365-1592473226-1724592899-513 2# S-1-5-11 3# S-1-5-5-0-8151 4# S-1-2-0 5# S-1-1-0 6# S-1-5-4 7# S-1-5-32-544 8# S-1-5-32-545 ================== ACCESS CHECK RIGHTS STATISTICS ================== Remaining access rights -> 0x00000008 Granted access rights -> 0x00000000 Denied access rights -> 0x00000000 err:(dll/win32/advapi32/wine/security.c:309) NtOpenProcessToken failed! Status c0000022. (