NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4602128
registers.esp:
311082412
registers.edi:
0
registers.eax:
0
registers.ebp:
960494
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000108
process_identifier:
2052
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4602128
registers.esp:
311082412
registers.edi:
0
registers.eax:
0
registers.ebp:
756736149
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x0000010c
process_identifier:
2052
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4602128
registers.esp:
311082412
registers.edi:
0
registers.eax:
0
registers.ebp:
98792432
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x0000010c
process_identifier:
2052
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4602128
registers.esp:
311082412
registers.edi:
0
registers.eax:
0
registers.ebp:
756736149
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x0000010c
process_identifier:
2052
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2052
|
1
|
0 |
0
|