Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- CreateProcess called...
- Process: 0x84377d40
- ProcessId: 0xb94
- CreateInfo:
- Parent Process Id: 0x874
- Image File Name: '\??\C:\Windows\system32\notepad.exe'
- Command Line: '"C:\Windows\system32\notepad.exe" '
- Flags: 0x1
- Image loaded...
- Full Image Name: '\Windows\System32\notepad.exe'
- ProcessId: 0x874
- ImageInfo:
- Image Base: 0x3f00000
- Image Selector: 0x0
- Image Size: 0x30000
- Image Section Number: 0x0
- Properties:
- Image Addressing Mode: 0x3
- System Mode Image: 0x0
- Image Mapped To All Pids: 0x0
- Extended Info Present: 0x1
- Reserved: 0x0
- Image loaded...
- Full Image Name: '\Device\HarddiskVolume2\Windows\System32\notepad.exe'
- ProcessId: 0xb94
- ImageInfo:
- Image Base: 0x4a0000
- Image Selector: 0x0
- Image Size: 0x30000
- Image Section Number: 0x0
- Properties:
- Image Addressing Mode: 0x3
- System Mode Image: 0x0
- Image Mapped To All Pids: 0x0
- Extended Info Present: 0x1
- Reserved: 0x0
- Image loaded...
- Full Image Name: '\Windows\System32\notepad.exe'
- ProcessId: 0x874
- ImageInfo:
- Image Base: 0x3f00000
- Image Selector: 0x0
- Image Size: 0x30000
- Image Section Number: 0x0
- Properties:
- Image Addressing Mode: 0x3
- System Mode Image: 0x0
- Image Mapped To All Pids: 0x0
- Extended Info Present: 0x1
- Reserved: 0x0
- Image loaded...
- Full Image Name: '\Windows\System32\notepad.exe'
- ProcessId: 0x874
- ImageInfo:
- Image Base: 0x3f00000
- Image Selector: 0x0
- Image Size: 0x30000
- Image Section Number: 0x0
- Properties:
- Image Addressing Mode: 0x3
- System Mode Image: 0x0
- Image Mapped To All Pids: 0x0
- Extended Info Present: 0x1
- Reserved: 0x0
- Image loaded...
- Full Image Name: '\Windows\System32\notepad.exe'
- ProcessId: 0x874
- ImageInfo:
- Image Base: 0x3f00000
- Image Selector: 0x0
- Image Size: 0x30000
- Image Section Number: 0x0
- Properties:
- Image Addressing Mode: 0x3
- System Mode Image: 0x0
- Image Mapped To All Pids: 0x0
- Extended Info Present: 0x1
- Reserved: 0x0
- Image loaded...
- Full Image Name: '\Windows\System32\notepad.exe'
- ProcessId: 0x874
- ImageInfo:
- Image Base: 0x3f00000
- Image Selector: 0x0
- Image Size: 0x30000
- Image Section Number: 0x0
- Properties:
- Image Addressing Mode: 0x3
- System Mode Image: 0x0
- Image Mapped To All Pids: 0x0
- Extended Info Present: 0x1
- Reserved: 0x0
- Image loaded...
- Full Image Name: '\Windows\System32\notepad.exe'
- ProcessId: 0x874
- ImageInfo:
- Image Base: 0x3f00000
- Image Selector: 0x0
- Image Size: 0x30000
- Image Section Number: 0x0
- Properties:
- Image Addressing Mode: 0x3
- System Mode Image: 0x0
- Image Mapped To All Pids: 0x0
- Extended Info Present: 0x1
- Reserved: 0x0
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement