NtGetContextThread
|
thread_handle:
0x000000f0
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000f0
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4602464
registers.esp:
311113904
registers.edi:
0
registers.eax:
0
registers.ebp:
752297169
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000320
process_identifier:
3064
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4602464
registers.esp:
311114028
registers.edi:
0
registers.eax:
0
registers.ebp:
15568
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000320
process_identifier:
3064
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000320
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000320
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000324
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000324
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000324
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000324
suspend_count:
1
process_identifier:
3064
|
1
|
0 |
0
|