NtGetContextThread
|
thread_handle:
0x000000ec
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4602464
registers.esp:
311077796
registers.edi:
0
registers.eax:
0
registers.ebp:
1
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000000ec
process_identifier:
3064
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000ec
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000300
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000300
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4602464
registers.esp:
311081136
registers.edi:
0
registers.eax:
0
registers.ebp:
-1027063472
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000310
process_identifier:
3064
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4602464
registers.esp:
311081160
registers.edi:
0
registers.eax:
0
registers.ebp:
0
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000310
process_identifier:
3064
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4602464
registers.esp:
311081160
registers.edi:
0
registers.eax:
0
registers.ebp:
311214944
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000310
process_identifier:
3064
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4602464
registers.esp:
311081160
registers.edi:
0
registers.eax:
0
registers.ebp:
0
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000310
process_identifier:
3064
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000310
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000310
|
1
|
0 |
0
|