NtGetContextThread
|
thread_handle:
0x000000f0
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4609776
registers.esp:
181934796
registers.edi:
0
registers.eax:
0
registers.ebp:
30720
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000000f0
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000f0
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000104
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000104
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000104
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000104
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
0
thread_handle:
0x00000000
process_identifier:
0
current_directory:
filepath:
C:\Windows\Boot\PCAT\memtest.exe
track:
0
command_line:
filepath_r:
C:\Windows\Boot\PCAT\memtest.exe
stack_pivoted:
0
creation_flags:
134217732
(CREATE_NO_WINDOW|CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x00000000
|
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4609776
registers.esp:
181935004
registers.edi:
0
registers.eax:
0
registers.ebp:
35113
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000108
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000108
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4609776
registers.esp:
181935052
registers.edi:
0
registers.eax:
0
registers.ebp:
88064
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x0000010c
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4609776
registers.esp:
181935052
registers.edi:
0
registers.eax:
0
registers.ebp:
188416
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x0000010c
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4609776
registers.esp:
181935052
registers.edi:
0
registers.eax:
0
registers.ebp:
267882
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x0000010c
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4609776
registers.esp:
181935052
registers.edi:
0
registers.eax:
0
registers.ebp:
301056
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x0000010c
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000010c
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4609776
registers.esp:
181935052
registers.edi:
0
registers.eax:
0
registers.ebp:
313344
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x0000010c
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000010c
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000f0
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000f0
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000f0
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000f0
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x000000f0
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4609776
registers.esp:
181934796
registers.edi:
0
registers.eax:
0
registers.ebp:
0
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x000000f0
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x000000f0
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000114
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
4609776
registers.esp:
181934844
registers.edi:
0
registers.eax:
0
registers.ebp:
145737
registers.edx:
0
registers.ebx:
0
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000114
process_identifier:
2560
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000114
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000118
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x00000118
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
CreateProcessInternalW
|
thread_identifier:
2956
thread_handle:
0x00000108
process_identifier:
2952
current_directory:
filepath:
C:\Windows\Installer\{1D91F7DA-F517-4727-9E62-B7EA978BE980}\ARPPRODUCTICON.exe
track:
1
command_line:
filepath_r:
C:\Windows\Installer\{1D91F7DA-F517-4727-9E62-B7EA978BE980}\ARPPRODUCTICON.exe
stack_pivoted:
0
creation_flags:
134217732
(CREATE_NO_WINDOW|CREATE_SUSPENDED)
inherit_handles:
0
process_handle:
0x00000118
|
1
|
1 |
0
|
NtGetContextThread
|
thread_handle:
0x0000011c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000011c
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x00000108
|
1
|
0 |
0
|
NtAllocateVirtualMemory
|
process_identifier:
2952
region_size:
139264
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
base_address:
0x00400000
allocation_type:
12288
(MEM_COMMIT|MEM_RESERVE)
process_handle:
0x00000118
|
1
|
0 |
0
|
NtGetContextThread
|
thread_handle:
0x0000011c
|
1
|
0 |
0
|
NtResumeThread
|
thread_handle:
0x0000011c
suspend_count:
1
process_identifier:
2560
|
1
|
0 |
0
|
NtSetContextThread
|
registers.eip:
0
registers.esp:
0
registers.edi:
0
registers.eax:
4279515
registers.ebp:
0
registers.edx:
0
registers.ebx:
2130567168
registers.esi:
0
registers.ecx:
0
thread_handle:
0x00000108
process_identifier:
2952
|
1
|
0 |
0
|