CreateProcessInternalW
|
thread_identifier:
2428
thread_handle:
0x00000204
process_identifier:
2076
current_directory:
filepath:
C:\Users\test22\AppData\Local\Temp\vbc.exe
track:
1
command_line:
"C:\Users\test22\AppData\Local\Temp\vbc.exe"
filepath_r:
C:\Users\test22\AppData\Local\Temp\vbc.exe
stack_pivoted:
0
creation_flags:
134217732
(CREATE_NO_WINDOW|CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x00000208
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x00000204
|
1
|
0 |
0
|
NtAllocateVirtualMemory
|
process_identifier:
2076
region_size:
307200
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00400000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0x00000208
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
2000355780
registers.esp:
1638384
registers.edi:
0
registers.eax:
4200587
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000204
process_identifier:
2076
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2288
thread_handle:
0x00000084
process_identifier:
2892
current_directory:
C:\Users\test22\AppData\Local\Temp
filepath:
C:\Windows\System32\schtasks.exe
track:
1
command_line:
schtasks /create /f /sc onlogon /rl highest /tn "Abdobe" /tr '"C:\Users\test22\AppData\Roaming\Abdobe.exe"'
filepath_r:
C:\Windows\system32\schtasks.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x00000088
|
1
|
1 |
0
|
CreateProcessInternalW
|
thread_identifier:
2776
thread_handle:
0x00000084
process_identifier:
2740
current_directory:
C:\Users\test22\AppData\Local\Temp
filepath:
C:\Windows\System32\timeout.exe
track:
1
command_line:
timeout 3
filepath_r:
C:\Windows\system32\timeout.exe
stack_pivoted:
0
creation_flags:
524288
(EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x0000008c
|
1
|
1 |
0
|
CreateProcessInternalW
|
thread_identifier:
3024
thread_handle:
0x00000088
process_identifier:
872
current_directory:
filepath:
C:\Users\test22\AppData\Roaming\Abdobe.exe
track:
1
command_line:
"C:\Users\test22\AppData\Roaming\Abdobe.exe"
filepath_r:
C:\Users\test22\AppData\Roaming\Abdobe.exe
stack_pivoted:
0
creation_flags:
525328
(CREATE_NEW_CONSOLE|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles:
1
process_handle:
0x0000008c
|
1
|
1 |
0
|
NtResumeThread
|
thread_handle:
0x00000088
suspend_count:
0
process_identifier:
872
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2164
thread_handle:
0x00000208
process_identifier:
596
current_directory:
filepath:
C:\Users\test22\AppData\Roaming\Abdobe.exe
track:
1
command_line:
"C:\Users\test22\AppData\Roaming\Abdobe.exe"
filepath_r:
C:\Users\test22\AppData\Roaming\Abdobe.exe
stack_pivoted:
0
creation_flags:
134217732
(CREATE_NO_WINDOW|CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x0000020c
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x00000208
|
1
|
0 |
0
|
NtAllocateVirtualMemory
|
process_identifier:
596
region_size:
307200
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00400000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0x0000020c
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
2000355780
registers.esp:
1638384
registers.edi:
0
registers.eax:
4200587
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000208
process_identifier:
596
|
1
|
0 |
0
|