CreateProcessInternalW
|
thread_identifier:
2424
thread_handle:
0x00000224
process_identifier:
2420
current_directory:
filepath:
C:\Users\test22\AppData\Local\Temp\maxfile.exe
track:
1
command_line:
"C:\Users\test22\AppData\Local\Temp\maxfile.exe"
filepath_r:
C:\Users\test22\AppData\Local\Temp\maxfile.exe
stack_pivoted:
0
creation_flags:
134217732
(CREATE_NO_WINDOW|CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x00000228
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x00000224
|
1
|
0 |
0
|
NtAllocateVirtualMemory
|
process_identifier:
2420
region_size:
192512
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00400000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0x00000228
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
1999372740
registers.esp:
1638384
registers.edi:
0
registers.eax:
4321456
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000224
process_identifier:
2420
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
0
thread_handle:
0x00000000
process_identifier:
0
current_directory:
filepath:
C:\Windows\SysWOW64\autofmt.exe
track:
0
command_line:
filepath_r:
C:\Windows\SysWOW64\autofmt.exe
stack_pivoted:
0
creation_flags:
134217740
(CREATE_NO_WINDOW|CREATE_SUSPENDED|DETACHED_PROCESS)
inherit_handles:
0
process_handle:
0x00000000
|
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
0
thread_handle:
0x00000000
process_identifier:
0
current_directory:
filepath:
C:\Windows\SysWOW64\autofmt.exe
track:
0
command_line:
filepath_r:
C:\Windows\SysWOW64\autofmt.exe
stack_pivoted:
0
creation_flags:
134217740
(CREATE_NO_WINDOW|CREATE_SUSPENDED|DETACHED_PROCESS)
inherit_handles:
0
process_handle:
0x00000000
|
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
0
thread_handle:
0x00000000
process_identifier:
0
current_directory:
filepath:
C:\Windows\SysWOW64\autofmt.exe
track:
0
command_line:
filepath_r:
C:\Windows\SysWOW64\autofmt.exe
stack_pivoted:
0
creation_flags:
134217740
(CREATE_NO_WINDOW|CREATE_SUSPENDED|DETACHED_PROCESS)
inherit_handles:
0
process_handle:
0x00000000
|
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
0
thread_handle:
0x00000000
process_identifier:
0
current_directory:
filepath:
C:\Windows\SysWOW64\autofmt.exe
track:
0
command_line:
filepath_r:
C:\Windows\SysWOW64\autofmt.exe
stack_pivoted:
0
creation_flags:
134217740
(CREATE_NO_WINDOW|CREATE_SUSPENDED|DETACHED_PROCESS)
inherit_handles:
0
process_handle:
0x00000000
|
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
0
thread_handle:
0x00000000
process_identifier:
0
current_directory:
filepath:
C:\Windows\SysWOW64\autofmt.exe
track:
0
command_line:
filepath_r:
C:\Windows\SysWOW64\autofmt.exe
stack_pivoted:
0
creation_flags:
134217740
(CREATE_NO_WINDOW|CREATE_SUSPENDED|DETACHED_PROCESS)
inherit_handles:
0
process_handle:
0x00000000
|
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2620
thread_handle:
0x000000b0
process_identifier:
2616
current_directory:
filepath:
C:\Windows\SysWOW64\msdt.exe
track:
1
command_line:
filepath_r:
C:\Windows\SysWOW64\msdt.exe
stack_pivoted:
0
creation_flags:
134217740
(CREATE_NO_WINDOW|CREATE_SUSPENDED|DETACHED_PROCESS)
inherit_handles:
0
process_handle:
0x00000094
|
1
|
1 |
0
|
CreateProcessInternalW
|
thread_identifier:
2668
thread_handle:
0x000000ec
process_identifier:
2664
current_directory:
filepath:
C:\Windows\SysWOW64\cmd.exe
track:
1
command_line:
/c del "C:\Users\test22\AppData\Local\Temp\maxfile.exe"
filepath_r:
C:\Windows\SysWOW64\cmd.exe
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
inherit_handles:
1
process_handle:
0x0000013c
|
1
|
1 |
0
|