NtResumeThread
|
thread_handle:
0x00000000000000ac
suspend_count:
1
process_identifier:
1684
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000000000000b0
suspend_count:
1
process_identifier:
1684
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000000000000bc
suspend_count:
1
process_identifier:
1684
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000000000000e0
suspend_count:
1
process_identifier:
1684
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000108
suspend_count:
1
process_identifier:
1684
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000108
|
1
|
0 |
0
|
NtSetContextThread
|
registers.r14:
0
registers.r15:
0
registers.rcx:
0
registers.rsi:
0
registers.r10:
0
registers.rbx:
0
registers.rsp:
824634308656
registers.r11:
0
registers.r8:
0
registers.r9:
0
registers.rip:
3681792
registers.rdx:
0
registers.r12:
0
registers.rbp:
0
registers.rdi:
0
registers.rax:
0
registers.r13:
0
thread_handle:
0x0000000000000108
process_identifier:
1684
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000108
suspend_count:
1
process_identifier:
1684
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000108
suspend_count:
1
process_identifier:
1684
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000118
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000118
suspend_count:
1
process_identifier:
1684
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000000000011c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000000000011c
suspend_count:
1
process_identifier:
1684
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000118
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000118
suspend_count:
1
process_identifier:
1684
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2236
thread_handle:
0x0000000000000134
process_identifier:
2252
current_directory:
filepath:
C:\Windows\System32\cmd.exe
track:
1
command_line:
cmd ver
filepath_r:
C:\Windows\system32\cmd.exe
stack_pivoted:
0
creation_flags:
1024
(CREATE_UNICODE_ENVIRONMENT)
inherit_handles:
1
process_handle:
0x0000000000000138
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000124
suspend_count:
1
process_identifier:
1684
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000120
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000120
suspend_count:
1
process_identifier:
1684
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2908
thread_handle:
0x0000000000000150
process_identifier:
1460
current_directory:
filepath:
C:\Windows\System32\eventvwr.exe
track:
1
command_line:
eventvwr.exe
filepath_r:
C:\Windows\system32\eventvwr.exe
stack_pivoted:
0
creation_flags:
1024
(CREATE_UNICODE_ENVIRONMENT)
inherit_handles:
1
process_handle:
0x0000000000000154
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000000000001b0
suspend_count:
1
process_identifier:
1460
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2840
thread_handle:
0x00000000000001c8
process_identifier:
1632
current_directory:
C:\Users\test22\AppData\Local\Temp
filepath:
C:\Users\test22\AppData\Roaming\WindowsDefender\WindowsDefender.exe
track:
1
command_line:
"C:\Users\test22\AppData\Roaming\WindowsDefender\WindowsDefender.exe"
filepath_r:
C:\Users\test22\AppData\Roaming\WindowsDefender\WindowsDefender.exe
stack_pivoted:
0
creation_flags:
67634192
(CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
0
process_handle:
0x00000000000001d8
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000000000000ac
suspend_count:
1
process_identifier:
1632
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000000000000b0
suspend_count:
1
process_identifier:
1632
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000000000000b4
suspend_count:
1
process_identifier:
1632
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000000000000d4
suspend_count:
1
process_identifier:
1632
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000000000000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000000000000108
suspend_count:
1
process_identifier:
1632
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000000000011c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000000000011c
suspend_count:
1
process_identifier:
1632
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000000000016c
suspend_count:
1
process_identifier:
1632
|
1
|
0 |
0
|