PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x43c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00100e22c40, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580f0
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b1e044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00100e22c40, ret_val_ptr_out = 0x800d
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x44c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110c163b0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580ef
|
ObQueryNameString
|
Object_ptr = 0xffffc00110c163b0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b1f044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110c163b0, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x5a8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b51350, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580ee
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b51350, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b21044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b51350, ret_val_ptr_out = 0x7fff
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x5f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101a80530, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580ed
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b22044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101a80530, ret_val_ptr_out = 0x800e
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x5f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b51490, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580ec
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b51490, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b26044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b51490, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x658, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101a84a20, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580eb
|
ObQueryNameString
|
Object_ptr = 0xffffe00101a84a20, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b27044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101a84a20, ret_val_ptr_out = 0x7ff2
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x65c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b714f0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580ea
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b714f0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102ad27c4, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b714f0, ret_val_ptr_out = 0x3fff8
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x694, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b5d200, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580e9
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b5d200, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102a7d044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b5d200, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101a85d90, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580e8
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b11044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101a85d90, ret_val_ptr_out = 0x800d
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x6f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b5b250, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580e7
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b5b250, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b15044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b5b250, ret_val_ptr_out = 0x7fff
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x7a8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b714f0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580e6
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b714f0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102add044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b714f0, ret_val_ptr_out = 0x3fff7
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x7b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b714f0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580e5
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b714f0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102aeb044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b714f0, ret_val_ptr_out = 0x3fff6
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x7e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00117420350, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580e4
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102aef044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00117420350, ret_val_ptr_out = 0x800d
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x7e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b88940, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580e3
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b88940, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102ae87c4, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b88940, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x7e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101a98480, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580e2
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b13044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101a98480, ret_val_ptr_out = 0x800d
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x7ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b8b9c0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580e1
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b8b9c0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102ae6044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b8b9c0, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x7f0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe001174204c0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580e0
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102ad27c4, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe001174204c0, ret_val_ptr_out = 0x800d
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x7f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b8d610, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580df
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b8d610, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102a7d044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b8d610, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x814, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b714f0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580de
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b714f0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b4a7c4, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b714f0, ret_val_ptr_out = 0x3fff5
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x818, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b714f0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580dd
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b714f0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b11044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b714f0, ret_val_ptr_out = 0x3fff4
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x828, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00100ae28a0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580dc
|
ObQueryNameString
|
Object_ptr = 0xffffe00100ae28a0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b15044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00100ae28a0, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x834, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00100ae2090, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580db
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102add044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00100ae2090, ret_val_ptr_out = 0x800d
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x838, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b30430, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580da
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b30430, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b4f7c4, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b30430, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x83c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101a9a990, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580d9
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102aeb044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101a9a990, ret_val_ptr_out = 0x800d
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x840, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b90790, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580d8
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b90790, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102aef044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b90790, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x85c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b714f0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580d7
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b714f0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102ae87c4, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b714f0, ret_val_ptr_out = 0x3fff3
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x868, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101a9b750, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580d6
|
ObQueryNameString
|
Object_ptr = 0xffffe00101a9b750, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b13044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101a9b750, ret_val_ptr_out = 0x7fff
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x884, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101ab7b00, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580d5
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b27044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101ab7b00, ret_val_ptr_out = 0x800d
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x88c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b714f0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580d4
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b714f0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102070044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b714f0, ret_val_ptr_out = 0x3fff2
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x8a8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b714f0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580d3
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b714f0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102ad27c4, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b714f0, ret_val_ptr_out = 0x3fff1
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x8d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc001109d0060, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580d2
|
ObQueryNameString
|
Object_ptr = 0xffffc001109d0060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102a7d044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc001109d0060, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x8fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101a4e090, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580d1
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b4a7c4, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101a4e090, ret_val_ptr_out = 0x800d
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x90c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc0010ff10330, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580d0
|
ObQueryNameString
|
Object_ptr = 0xffffc0010ff10330, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b11044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc0010ff10330, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x910, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101a4eca0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580cf
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b15044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101a4eca0, ret_val_ptr_out = 0x800d
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x92c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00100e22690, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580ce
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102add044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00100e22690, ret_val_ptr_out = 0x7ffc
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x938, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc0010f9b2250, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580cd
|
ObQueryNameString
|
Object_ptr = 0xffffc0010f9b2250, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b4f7c4, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc0010f9b2250, ret_val_ptr_out = 0x11ffde
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x93c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101a4e7d0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580cc
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102aeb044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101a4e7d0, ret_val_ptr_out = 0x800d
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x940, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc0010f725550, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580cb
|
ObQueryNameString
|
Object_ptr = 0xffffc0010f725550, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102aef044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc0010f725550, ret_val_ptr_out = 0x117fde
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x948, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110c0d9c0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580ca
|
ObQueryNameString
|
Object_ptr = 0xffffc00110c0d9c0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102ae87c4, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110c0d9c0, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x95c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101ad05c0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580c9
|
ObQueryNameString
|
Object_ptr = 0xffffe00101ad05c0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b13044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101ad05c0, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0x998, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe001013ae630, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580c8
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102ae6044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe001013ae630, ret_val_ptr_out = 0x7fff
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xaac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110c8ba30, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580c7
|
ObQueryNameString
|
Object_ptr = 0xffffc00110c8ba30, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b12044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110c8ba30, ret_val_ptr_out = 0xfffd
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xac8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b2ba10, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580c6
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b2ba10, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b20044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b2ba10, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xae4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101363d30, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580c5
|
ObQueryNameString
|
Object_ptr = 0xffffe00101363d30, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b18044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101363d30, ret_val_ptr_out = 0x800d
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xaf4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110c55b10, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580c4
|
ObQueryNameString
|
Object_ptr = 0xffffc00110c55b10, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b25044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110c55b10, ret_val_ptr_out = 0xfffd
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xb50, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101390ce0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580c3
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b28044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101390ce0, ret_val_ptr_out = 0x8002
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xb54, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110c245b0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580c2
|
ObQueryNameString
|
Object_ptr = 0xffffc00110c245b0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00101ed8044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110c245b0, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xb58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe001013789a0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580c1
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102ab2044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe001013789a0, ret_val_ptr_out = 0x8002
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xb5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110c21fc0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580c0
|
ObQueryNameString
|
Object_ptr = 0xffffc00110c21fc0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102ae9044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110c21fc0, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xb60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe0010111e190, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580bf
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102aea044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010111e190, ret_val_ptr_out = 0x8003
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xb64, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110c2b520, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580be
|
ObQueryNameString
|
Object_ptr = 0xffffc00110c2b520, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102aee044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110c2b520, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xb68, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101ae1320, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580bd
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102af0044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101ae1320, ret_val_ptr_out = 0x8003
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xb6c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110c30890, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580bc
|
ObQueryNameString
|
Object_ptr = 0xffffc00110c30890, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b10044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110c30890, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xb70, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101ae1a50, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580bb
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b14044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101ae1a50, ret_val_ptr_out = 0x8003
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xb74, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110c30110, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580ba
|
ObQueryNameString
|
Object_ptr = 0xffffc00110c30110, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b1a044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110c30110, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xb78, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe001016a11b0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580b9
|
ObQueryNameString
|
Object_ptr = 0xffffe001016a11b0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b1c044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe001016a11b0, ret_val_ptr_out = 0x800d
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xb84, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101867f20, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580b8
|
ObQueryNameString
|
Object_ptr = 0xffffe00101867f20, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b1d044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101867f20, ret_val_ptr_out = 0x7fff
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xbc4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00100bf5e50, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580b7
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b1e044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00100bf5e50, ret_val_ptr_out = 0x8003
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xbf0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc00110b403d0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580b6
|
ObQueryNameString
|
Object_ptr = 0xffffc00110b403d0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b1f044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc00110b403d0, ret_val_ptr_out = 0xffff
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xc2c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00100bf5ce0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580b5
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b21044, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00100bf5ce0, ret_val_ptr_out = 0x7fff
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xc50, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc0011068fbf0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580b4
|
ObQueryNameString
|
Object_ptr = 0xffffc0011068fbf0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102070044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc0011068fbf0, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xc54, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe001013947a0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580b3
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102ad27c4, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe001013947a0, ret_val_ptr_out = 0x7ffa
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xc58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc001109ed3e0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580b2
|
ObQueryNameString
|
Object_ptr = 0xffffc001109ed3e0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102a7d044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc001109ed3e0, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xc5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101397960, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580b1
|
ObQueryNameString
|
Object_ptr = 0xffffe00100a3e060, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b4a7c4, ReturnLength_ptr_out = 0xffffd000b7d7b338, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101397960, ret_val_ptr_out = 0x8003
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xc64, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffc0010ff818c0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580b0
|
ObQueryNameString
|
Object_ptr = 0xffffc0010ff818c0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b11044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffc0010ff818c0, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xc68, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101397300, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580af
|
ObQueryNameString
|
Object_ptr = 0xffffe00101397300, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b15044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101397300, ret_val_ptr_out = 0x7fd6
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xc6c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe001013977f0, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580ae
|
ObQueryNameString
|
Object_ptr = 0xffffe001013977f0, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102add044, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe001013977f0, ret_val_ptr_out = 0x7ffe
|
PsLookupProcessByProcessId
|
ProcessId_unk = 0xb7c, Process_unk_out = 0xffffd000b7d7b388, ret_val_out = 0x0
|
PsAcquireProcessExitSynchronization
|
ret_val_out = 0x0
|
KeStackAttachProcess
|
PROCESS_unk = 0xffffe0010177d840, PROCESS_unk_out = 0xffffe0010177d840, ApcState_unk_out = 0xffffd000b7d7b400
|
ObReferenceObjectByHandle
|
Handle_unk = 0xee4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xffffd000b7d7b378, Object_out = 0xffffe00101ae2f20, HandleInformation_unk_out = 0x0, ret_val_out = 0x0
|
KeUnstackDetachProcess
|
ApcState_unk = 0xffffd000b7d7b400
|
PsReleaseProcessExitSynchronization
|
ret_val_out = 0x2
|
ObfDereferenceObject
|
Object_ptr = 0xffffe0010177d840, ret_val_ptr_out = 0x580ad
|
ObQueryNameString
|
Object_ptr = 0xffffe00101ae2f20, Length = 0x800, ObjectNameInfo_unk_out = 0xffffe00102b4f7c4, ReturnLength_ptr_out = 0xffffd000b7d7b380, ret_val_out = 0x0
|
ObfDereferenceObject
|
Object_ptr = 0xffffe00101ae2f20, ret_val_ptr_out = 0x7ffe
|