@ stdcall CloseTrace(int64) advapi32.CloseTrace
@ stdcall -ret64 OpenTraceW(ptr) advapi32.OpenTraceW
@ stdcall ProcessTrace(ptr long ptr ptr) advapi32.ProcessTrace