NtGetContextThread
|
thread_handle:
0x000000f4
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4605808
registers.esp:
182141780
registers.edi:
0
registers.eax:
0
registers.ebp:
14336
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000000f4
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000f4
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
0
thread_handle:
0x00000000
process_identifier:
0
current_directory:
filepath:
C:\Windows\Boot\PCAT\memtest.exe
track:
0
command_line:
filepath_r:
C:\Windows\Boot\PCAT\memtest.exe
stack_pivoted:
0
creation_flags:
134217732
(CREATE_NO_WINDOW|CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x00000000
|
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4605808
registers.esp:
182141988
registers.edi:
0
registers.eax:
0
registers.ebp:
55902
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x0000010c
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4605808
registers.esp:
182141988
registers.edi:
0
registers.eax:
0
registers.ebp:
1
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x0000010c
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4605808
registers.esp:
182141988
registers.edi:
0
registers.eax:
0
registers.ebp:
4
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x0000010c
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4605808
registers.esp:
182142032
registers.edi:
0
registers.eax:
0
registers.ebp:
48917
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000108
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4605808
registers.esp:
182142032
registers.edi:
0
registers.eax:
0
registers.ebp:
93296
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000108
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4605808
registers.esp:
182142032
registers.edi:
0
registers.eax:
0
registers.ebp:
7
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000108
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4605808
registers.esp:
182142032
registers.edi:
0
registers.eax:
0
registers.ebp:
605499
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000108
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4605808
registers.esp:
182141780
registers.edi:
0
registers.eax:
0
registers.ebp:
133843
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000108
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|