__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffdf000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffdf000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffd8000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffd8000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffdf000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffdf000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffd8000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffd8000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffdb000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffdb000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffda000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffda000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffdb000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffdb000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffd9000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffd9000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffdf000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffdf000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffd7000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffd7000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffd6000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffd6000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffd3000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffd3000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffd6000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffd6000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffdf000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffdf000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffda000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffda000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffdf000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffdf000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffdb000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffdb000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffdf000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffdf000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffdb000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffdb000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffd4000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffd4000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffdc000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffdc000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffd3000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffd3000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffdc000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffdc000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|
__exception__
|
stacktrace:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895 @ 0x77210895
stacktrace+0x84 memdup-0x1af @ 0x72e10470
hook_in_monitor+0x45 lde-0x133 @ 0x72e042ea
New_ntdll_NtProtectVirtualMemory+0x34 New_ntdll_NtQueryAttributesFile-0x151 @ 0x72e23603
VirtualProtectEx+0x33 MapViewOfFile-0x2d kernelbase+0x13243 @ 0x7fefd6e3243
VirtualProtect+0x1b VirtualProtectEx-0x15 kernelbase+0x131fb @ 0x7fefd6e31fb
driver+0x53a27b @ 0x93a27b
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0x83cfff @ 0xc3cfff
GetProcessAffinityMask+0x80 SetThreadContext-0x20 kernel32+0x2ef0 @ 0x76e42ef0
driver+0xc3e000 @ 0x103e000
driver+0x1000 @ 0x401000
driver+0x833d42 @ 0xc33d42
0x7fffffd4000
driver+0xc3f2ca @ 0x103f2ca
0x7fffffd4000
exception.instruction_r:
0f ae 81 00 01 00 00 0f 29 81 a0 01 00 00 0f 29
exception.symbol:
RtlCaptureContext+0x85 RtlRestoreContext-0xaa ntdll+0x50895
exception.address:
0x77210895
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
329877
registers.r14:
0
registers.r15:
0
registers.rcx:
2291256
registers.rsi:
17031168
registers.r10:
0
registers.rbx:
1994665712
registers.rsp:
2293576
registers.r11:
514
registers.r8:
64
registers.r9:
4
registers.rdx:
2292600
registers.r12:
0
registers.rbp:
0
registers.rdi:
4194671
registers.rax:
2290936
registers.r13:
0
|
1
|
0 |
0
|