viewer9 documentation | Index Home |
ProcessStart PML Operation
This is the first event of the newly created process and is generally preceeded by a ProcessCreate event in the parent process.
ParentPid indicates the parent process. It should match the ProcParentPid shown in the process fields on the right. Also on the right will be a parentproc value and link, if the parent process was captured.
CmdLine shows the way the process was launched including the pathname used to call it and the arguments passed.
Env lists the environment variables of the process.
Example from 64-bit PML
Hover over field values like Time, ResultCode, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.
ProcessStart opcode=1,7
ev=84547
Time: | 2022-05-17 19:41:53.7281411 |
Duration: | 0.0000000 |
ResultCode: | SUCCESS |
Tid: | 7868 |
ParentPid: | 3772 |
CmdLine: | "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCopyAccelerator.exe" |
CurDirectory: | C:\WINDOWS\system32\ |
Env: | ALLUSERSPROFILE=C:\ProgramData APPDATA=C:\WINDOWS\system32\config\systemprofile\AppData\Roaming CommonProgramFiles=C:\Program Files\Common Files CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files CommonProgramW6432=C:\Program Files\Common Files COMPUTERNAME=WIN10X64-VM ComSpec=C:\WINDOWS\system32\cmd.exe DriverData=C:\Windows\System32\Drivers\DriverData LOCALAPPDATA=C:\WINDOWS\system32\config\systemprofile\AppData\Local NUMBER_OF_PROCESSORS=4 OS=Windows_NT Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\WindowsApps PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC PROCESSOR_ARCHITECTURE=AMD64 PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 94 Stepping 3, GenuineIntel PROCESSOR_LEVEL=6 PROCESSOR_REVISION=5e03 ProgramData=C:\ProgramData ProgramFiles=C:\Program Files ProgramFiles(x86)=C:\Program Files (x86) ProgramW6432=C:\Program Files PSModulePath=%ProgramFiles%\WindowsPowerShell\Modules;C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules PUBLIC=C:\Users\Public SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\WINDOWS\TEMP TMP=C:\WINDOWS\TEMP USERDOMAIN=WORKGROUP USERNAME=WIN10X64-VM$ USERPROFILE=C:\WINDOWS\system32\config\systemprofile windir=C:\WINDOWS |
evdata[0-2895] file offset 40982764
0 | bc 0e 00 00 58 00 14 00 | ....X... |
8 | 36 05 00 00 22 00 43 00 | 6...".C. |
16 | 3a 00 5c 00 50 00 72 00 | :.\.P.r. |
24 | 6f 00 67 00 72 00 61 00 | o.g.r.a. |
32 | 6d 00 44 00 61 00 74 00 | m.D.a.t. |
40 | 61 00 5c 00 4d 00 69 00 | a.\.M.i. |
48 | 63 00 72 00 6f 00 73 00 | c.r.o.s. |
56 | 6f 00 66 00 74 00 5c 00 | o.f.t.\. |
64 | 57 00 69 00 6e 00 64 00 | W.i.n.d. |
72 | 6f 00 77 00 73 00 20 00 | o.w.s. . |
80 | 44 00 65 00 66 00 65 00 | D.e.f.e. |
88 | 6e 00 64 00 65 00 72 00 | n.d.e.r. |
96 | 5c 00 50 00 6c 00 61 00 | \.P.l.a. |
104 | 74 00 66 00 6f 00 72 00 | t.f.o.r. |
112 | 6d 00 5c 00 34 00 2e 00 | m.\.4... |
120 | 31 00 38 00 2e 00 32 00 | 1.8...2. |
128 | 32 00 30 00 33 00 2e 00 | 2.0.3... |
136 | 35 00 2d 00 30 00 5c 00 | 5.-.0.\. |
144 | 4d 00 70 00 43 00 6f 00 | M.p.C.o. |
152 | 70 00 79 00 41 00 63 00 | p.y.A.c. |
160 | 63 00 65 00 6c 00 65 00 | c.e.l.e. |
168 | 72 00 61 00 74 00 6f 00 | r.a.t.o. |
176 | 72 00 2e 00 65 00 78 00 | r...e.x. |
184 | 65 00 22 00 43 00 3a 00 | e.".C.:. |
192 | 5c 00 57 00 49 00 4e 00 | \.W.I.N. |
200 | 44 00 4f 00 57 00 53 00 | D.O.W.S. |
208 | 5c 00 73 00 79 00 73 00 | \.s.y.s. |
216 | 74 00 65 00 6d 00 33 00 | t.e.m.3. |
224 | 32 00 5c 00 41 00 4c 00 | 2.\.A.L. |
232 | 4c 00 55 00 53 00 45 00 | L.U.S.E. |
240 | 52 00 53 00 50 00 52 00 | R.S.P.R. |
248 | 4f 00 46 00 49 00 4c 00 | O.F.I.L. |
256 | 45 00 3d 00 43 00 3a 00 | E.=.C.:. |
264 | 5c 00 50 00 72 00 6f 00 | \.P.r.o. |
272 | 67 00 72 00 61 00 6d 00 | g.r.a.m. |
280 | 44 00 61 00 74 00 61 00 | D.a.t.a. |
288 | 00 00 41 00 50 00 50 00 | ..A.P.P. |
296 | 44 00 41 00 54 00 41 00 | D.A.T.A. |
304 | 3d 00 43 00 3a 00 5c 00 | =.C.:.\. |
312 | 57 00 49 00 4e 00 44 00 | W.I.N.D. |
320 | 4f 00 57 00 53 00 5c 00 | O.W.S.\. |
328 | 73 00 79 00 73 00 74 00 | s.y.s.t. |
336 | 65 00 6d 00 33 00 32 00 | e.m.3.2. |
344 | 5c 00 63 00 6f 00 6e 00 | \.c.o.n. |
352 | 66 00 69 00 67 00 5c 00 | f.i.g.\. |
360 | 73 00 79 00 73 00 74 00 | s.y.s.t. |
368 | 65 00 6d 00 70 00 72 00 | e.m.p.r. |
376 | 6f 00 66 00 69 00 6c 00 | o.f.i.l. |
384 | 65 00 5c 00 41 00 70 00 | e.\.A.p. |
392 | 70 00 44 00 61 00 74 00 | p.D.a.t. |
400 | 61 00 5c 00 52 00 6f 00 | a.\.R.o. |
408 | 61 00 6d 00 69 00 6e 00 | a.m.i.n. |
416 | 67 00 00 00 43 00 6f 00 | g...C.o. |
424 | 6d 00 6d 00 6f 00 6e 00 | m.m.o.n. |
432 | 50 00 72 00 6f 00 67 00 | P.r.o.g. |
440 | 72 00 61 00 6d 00 46 00 | r.a.m.F. |
448 | 69 00 6c 00 65 00 73 00 | i.l.e.s. |
456 | 3d 00 43 00 3a 00 5c 00 | =.C.:.\. |
464 | 50 00 72 00 6f 00 67 00 | P.r.o.g. |
472 | 72 00 61 00 6d 00 20 00 | r.a.m. . |
480 | 46 00 69 00 6c 00 65 00 | F.i.l.e. |
488 | 73 00 5c 00 43 00 6f 00 | s.\.C.o. |
496 | 6d 00 6d 00 6f 00 6e 00 | m.m.o.n. |
504 | 20 00 46 00 69 00 6c 00 | .F.i.l. |
512 | 65 00 73 00 00 00 43 00 | e.s...C. |
520 | 6f 00 6d 00 6d 00 6f 00 | o.m.m.o. |
528 | 6e 00 50 00 72 00 6f 00 | n.P.r.o. |
536 | 67 00 72 00 61 00 6d 00 | g.r.a.m. |
544 | 46 00 69 00 6c 00 65 00 | F.i.l.e. |
552 | 73 00 28 00 78 00 38 00 | s.(.x.8. |
560 | 36 00 29 00 3d 00 43 00 | 6.).=.C. |
568 | 3a 00 5c 00 50 00 72 00 | :.\.P.r. |
576 | 6f 00 67 00 72 00 61 00 | o.g.r.a. |
584 | 6d 00 20 00 46 00 69 00 | m. .F.i. |
592 | 6c 00 65 00 73 00 20 00 | l.e.s. . |
600 | 28 00 78 00 38 00 36 00 | (.x.8.6. |
608 | 29 00 5c 00 43 00 6f 00 | ).\.C.o. |
616 | 6d 00 6d 00 6f 00 6e 00 | m.m.o.n. |
624 | 20 00 46 00 69 00 6c 00 | .F.i.l. |
632 | 65 00 73 00 00 00 43 00 | e.s...C. |
640 | 6f 00 6d 00 6d 00 6f 00 | o.m.m.o. |
648 | 6e 00 50 00 72 00 6f 00 | n.P.r.o. |
656 | 67 00 72 00 61 00 6d 00 | g.r.a.m. |
664 | 57 00 36 00 34 00 33 00 | W.6.4.3. |
672 | 32 00 3d 00 43 00 3a 00 | 2.=.C.:. |
680 | 5c 00 50 00 72 00 6f 00 | \.P.r.o. |
688 | 67 00 72 00 61 00 6d 00 | g.r.a.m. |
696 | 20 00 46 00 69 00 6c 00 | .F.i.l. |
704 | 65 00 73 00 5c 00 43 00 | e.s.\.C. |
712 | 6f 00 6d 00 6d 00 6f 00 | o.m.m.o. |
720 | 6e 00 20 00 46 00 69 00 | n. .F.i. |
728 | 6c 00 65 00 73 00 00 00 | l.e.s... |
736 | 43 00 4f 00 4d 00 50 00 | C.O.M.P. |
744 | 55 00 54 00 45 00 52 00 | U.T.E.R. |
752 | 4e 00 41 00 4d 00 45 00 | N.A.M.E. |
760 | 3d 00 57 00 49 00 4e 00 | =.W.I.N. |
768 | 31 00 30 00 58 00 36 00 | 1.0.X.6. |
776 | 34 00 2d 00 56 00 4d 00 | 4.-.V.M. |
784 | 00 00 43 00 6f 00 6d 00 | ..C.o.m. |
792 | 53 00 70 00 65 00 63 00 | S.p.e.c. |
800 | 3d 00 43 00 3a 00 5c 00 | =.C.:.\. |
808 | 57 00 49 00 4e 00 44 00 | W.I.N.D. |
816 | 4f 00 57 00 53 00 5c 00 | O.W.S.\. |
824 | 73 00 79 00 73 00 74 00 | s.y.s.t. |
832 | 65 00 6d 00 33 00 32 00 | e.m.3.2. |
840 | 5c 00 63 00 6d 00 64 00 | \.c.m.d. |
848 | 2e 00 65 00 78 00 65 00 | ..e.x.e. |
856 | 00 00 44 00 72 00 69 00 | ..D.r.i. |
864 | 76 00 65 00 72 00 44 00 | v.e.r.D. |
872 | 61 00 74 00 61 00 3d 00 | a.t.a.=. |
880 | 43 00 3a 00 5c 00 57 00 | C.:.\.W. |
888 | 69 00 6e 00 64 00 6f 00 | i.n.d.o. |
896 | 77 00 73 00 5c 00 53 00 | w.s.\.S. |
904 | 79 00 73 00 74 00 65 00 | y.s.t.e. |
912 | 6d 00 33 00 32 00 5c 00 | m.3.2.\. |
920 | 44 00 72 00 69 00 76 00 | D.r.i.v. |
928 | 65 00 72 00 73 00 5c 00 | e.r.s.\. |
936 | 44 00 72 00 69 00 76 00 | D.r.i.v. |
944 | 65 00 72 00 44 00 61 00 | e.r.D.a. |
952 | 74 00 61 00 00 00 4c 00 | t.a...L. |
960 | 4f 00 43 00 41 00 4c 00 | O.C.A.L. |
968 | 41 00 50 00 50 00 44 00 | A.P.P.D. |
976 | 41 00 54 00 41 00 3d 00 | A.T.A.=. |
984 | 43 00 3a 00 5c 00 57 00 | C.:.\.W. |
992 | 49 00 4e 00 44 00 4f 00 | I.N.D.O. |
1000 | 57 00 53 00 5c 00 73 00 | W.S.\.s. |
1008 | 79 00 73 00 74 00 65 00 | y.s.t.e. |
1016 | 6d 00 33 00 32 00 5c 00 | m.3.2.\. |
1024 | 63 00 6f 00 6e 00 66 00 | c.o.n.f. |
1032 | 69 00 67 00 5c 00 73 00 | i.g.\.s. |
1040 | 79 00 73 00 74 00 65 00 | y.s.t.e. |
1048 | 6d 00 70 00 72 00 6f 00 | m.p.r.o. |
1056 | 66 00 69 00 6c 00 65 00 | f.i.l.e. |
1064 | 5c 00 41 00 70 00 70 00 | \.A.p.p. |
1072 | 44 00 61 00 74 00 61 00 | D.a.t.a. |
1080 | 5c 00 4c 00 6f 00 63 00 | \.L.o.c. |
1088 | 61 00 6c 00 00 00 4e 00 | a.l...N. |
1096 | 55 00 4d 00 42 00 45 00 | U.M.B.E. |
1104 | 52 00 5f 00 4f 00 46 00 | R._.O.F. |
1112 | 5f 00 50 00 52 00 4f 00 | _.P.R.O. |
1120 | 43 00 45 00 53 00 53 00 | C.E.S.S. |
1128 | 4f 00 52 00 53 00 3d 00 | O.R.S.=. |
1136 | 34 00 00 00 4f 00 53 00 | 4...O.S. |
1144 | 3d 00 57 00 69 00 6e 00 | =.W.i.n. |
1152 | 64 00 6f 00 77 00 73 00 | d.o.w.s. |
1160 | 5f 00 4e 00 54 00 00 00 | _.N.T... |
1168 | 50 00 61 00 74 00 68 00 | P.a.t.h. |
1176 | 3d 00 43 00 3a 00 5c 00 | =.C.:.\. |
1184 | 57 00 49 00 4e 00 44 00 | W.I.N.D. |
1192 | 4f 00 57 00 53 00 5c 00 | O.W.S.\. |
1200 | 73 00 79 00 73 00 74 00 | s.y.s.t. |
1208 | 65 00 6d 00 33 00 32 00 | e.m.3.2. |
1216 | 3b 00 43 00 3a 00 5c 00 | ;.C.:.\. |
1224 | 57 00 49 00 4e 00 44 00 | W.I.N.D. |
1232 | 4f 00 57 00 53 00 3b 00 | O.W.S.;. |
1240 | 43 00 3a 00 5c 00 57 00 | C.:.\.W. |
1248 | 49 00 4e 00 44 00 4f 00 | I.N.D.O. |
1256 | 57 00 53 00 5c 00 53 00 | W.S.\.S. |
1264 | 79 00 73 00 74 00 65 00 | y.s.t.e. |
1272 | 6d 00 33 00 32 00 5c 00 | m.3.2.\. |
1280 | 57 00 62 00 65 00 6d 00 | W.b.e.m. |
1288 | 3b 00 43 00 3a 00 5c 00 | ;.C.:.\. |
1296 | 57 00 49 00 4e 00 44 00 | W.I.N.D. |
1304 | 4f 00 57 00 53 00 5c 00 | O.W.S.\. |
1312 | 53 00 79 00 73 00 74 00 | S.y.s.t. |
1320 | 65 00 6d 00 33 00 32 00 | e.m.3.2. |
1328 | 5c 00 57 00 69 00 6e 00 | \.W.i.n. |
1336 | 64 00 6f 00 77 00 73 00 | d.o.w.s. |
1344 | 50 00 6f 00 77 00 65 00 | P.o.w.e. |
1352 | 72 00 53 00 68 00 65 00 | r.S.h.e. |
1360 | 6c 00 6c 00 5c 00 76 00 | l.l.\.v. |
1368 | 31 00 2e 00 30 00 5c 00 | 1...0.\. |
1376 | 3b 00 43 00 3a 00 5c 00 | ;.C.:.\. |
1384 | 57 00 49 00 4e 00 44 00 | W.I.N.D. |
1392 | 4f 00 57 00 53 00 5c 00 | O.W.S.\. |
1400 | 53 00 79 00 73 00 74 00 | S.y.s.t. |
1408 | 65 00 6d 00 33 00 32 00 | e.m.3.2. |
1416 | 5c 00 4f 00 70 00 65 00 | \.O.p.e. |
1424 | 6e 00 53 00 53 00 48 00 | n.S.S.H. |
1432 | 5c 00 3b 00 43 00 3a 00 | \.;.C.:. |
1440 | 5c 00 57 00 49 00 4e 00 | \.W.I.N. |
1448 | 44 00 4f 00 57 00 53 00 | D.O.W.S. |
1456 | 5c 00 73 00 79 00 73 00 | \.s.y.s. |
1464 | 74 00 65 00 6d 00 33 00 | t.e.m.3. |
1472 | 32 00 5c 00 63 00 6f 00 | 2.\.c.o. |
1480 | 6e 00 66 00 69 00 67 00 | n.f.i.g. |
1488 | 5c 00 73 00 79 00 73 00 | \.s.y.s. |
1496 | 74 00 65 00 6d 00 70 00 | t.e.m.p. |
1504 | 72 00 6f 00 66 00 69 00 | r.o.f.i. |
1512 | 6c 00 65 00 5c 00 41 00 | l.e.\.A. |
1520 | 70 00 70 00 44 00 61 00 | p.p.D.a. |
1528 | 74 00 61 00 5c 00 4c 00 | t.a.\.L. |
1536 | 6f 00 63 00 61 00 6c 00 | o.c.a.l. |
1544 | 5c 00 4d 00 69 00 63 00 | \.M.i.c. |
1552 | 72 00 6f 00 73 00 6f 00 | r.o.s.o. |
1560 | 66 00 74 00 5c 00 57 00 | f.t.\.W. |
1568 | 69 00 6e 00 64 00 6f 00 | i.n.d.o. |
1576 | 77 00 73 00 41 00 70 00 | w.s.A.p. |
1584 | 70 00 73 00 00 00 50 00 | p.s...P. |
1592 | 41 00 54 00 48 00 45 00 | A.T.H.E. |
1600 | 58 00 54 00 3d 00 2e 00 | X.T.=... |
1608 | 43 00 4f 00 4d 00 3b 00 | C.O.M.;. |
1616 | 2e 00 45 00 58 00 45 00 | ..E.X.E. |
1624 | 3b 00 2e 00 42 00 41 00 | ;...B.A. |
1632 | 54 00 3b 00 2e 00 43 00 | T.;...C. |
1640 | 4d 00 44 00 3b 00 2e 00 | M.D.;... |
1648 | 56 00 42 00 53 00 3b 00 | V.B.S.;. |
1656 | 2e 00 56 00 42 00 45 00 | ..V.B.E. |
1664 | 3b 00 2e 00 4a 00 53 00 | ;...J.S. |
1672 | 3b 00 2e 00 4a 00 53 00 | ;...J.S. |
1680 | 45 00 3b 00 2e 00 57 00 | E.;...W. |
1688 | 53 00 46 00 3b 00 2e 00 | S.F.;... |
1696 | 57 00 53 00 48 00 3b 00 | W.S.H.;. |
1704 | 2e 00 4d 00 53 00 43 00 | ..M.S.C. |
1712 | 00 00 50 00 52 00 4f 00 | ..P.R.O. |
1720 | 43 00 45 00 53 00 53 00 | C.E.S.S. |
1728 | 4f 00 52 00 5f 00 41 00 | O.R._.A. |
1736 | 52 00 43 00 48 00 49 00 | R.C.H.I. |
1744 | 54 00 45 00 43 00 54 00 | T.E.C.T. |
1752 | 55 00 52 00 45 00 3d 00 | U.R.E.=. |
1760 | 41 00 4d 00 44 00 36 00 | A.M.D.6. |
1768 | 34 00 00 00 50 00 52 00 | 4...P.R. |
1776 | 4f 00 43 00 45 00 53 00 | O.C.E.S. |
1784 | 53 00 4f 00 52 00 5f 00 | S.O.R._. |
1792 | 49 00 44 00 45 00 4e 00 | I.D.E.N. |
1800 | 54 00 49 00 46 00 49 00 | T.I.F.I. |
1808 | 45 00 52 00 3d 00 49 00 | E.R.=.I. |
1816 | 6e 00 74 00 65 00 6c 00 | n.t.e.l. |
1824 | 36 00 34 00 20 00 46 00 | 6.4. .F. |
1832 | 61 00 6d 00 69 00 6c 00 | a.m.i.l. |
1840 | 79 00 20 00 36 00 20 00 | y. .6. . |
1848 | 4d 00 6f 00 64 00 65 00 | M.o.d.e. |
1856 | 6c 00 20 00 39 00 34 00 | l. .9.4. |
1864 | 20 00 53 00 74 00 65 00 | .S.t.e. |
1872 | 70 00 70 00 69 00 6e 00 | p.p.i.n. |
1880 | 67 00 20 00 33 00 2c 00 | g. .3.,. |
1888 | 20 00 47 00 65 00 6e 00 | .G.e.n. |
1896 | 75 00 69 00 6e 00 65 00 | u.i.n.e. |
1904 | 49 00 6e 00 74 00 65 00 | I.n.t.e. |
1912 | 6c 00 00 00 50 00 52 00 | l...P.R. |
1920 | 4f 00 43 00 45 00 53 00 | O.C.E.S. |
1928 | 53 00 4f 00 52 00 5f 00 | S.O.R._. |
1936 | 4c 00 45 00 56 00 45 00 | L.E.V.E. |
1944 | 4c 00 3d 00 36 00 00 00 | L.=.6... |
1952 | 50 00 52 00 4f 00 43 00 | P.R.O.C. |
1960 | 45 00 53 00 53 00 4f 00 | E.S.S.O. |
1968 | 52 00 5f 00 52 00 45 00 | R._.R.E. |
1976 | 56 00 49 00 53 00 49 00 | V.I.S.I. |
1984 | 4f 00 4e 00 3d 00 35 00 | O.N.=.5. |
1992 | 65 00 30 00 33 00 00 00 | e.0.3... |
2000 | 50 00 72 00 6f 00 67 00 | P.r.o.g. |
2008 | 72 00 61 00 6d 00 44 00 | r.a.m.D. |
2016 | 61 00 74 00 61 00 3d 00 | a.t.a.=. |
2024 | 43 00 3a 00 5c 00 50 00 | C.:.\.P. |
2032 | 72 00 6f 00 67 00 72 00 | r.o.g.r. |
2040 | 61 00 6d 00 44 00 61 00 | a.m.D.a. |
2048 | 74 00 61 00 00 00 50 00 | t.a...P. |
2056 | 72 00 6f 00 67 00 72 00 | r.o.g.r. |
2064 | 61 00 6d 00 46 00 69 00 | a.m.F.i. |
2072 | 6c 00 65 00 73 00 3d 00 | l.e.s.=. |
2080 | 43 00 3a 00 5c 00 50 00 | C.:.\.P. |
2088 | 72 00 6f 00 67 00 72 00 | r.o.g.r. |
2096 | 61 00 6d 00 20 00 46 00 | a.m. .F. |
2104 | 69 00 6c 00 65 00 73 00 | i.l.e.s. |
2112 | 00 00 50 00 72 00 6f 00 | ..P.r.o. |
2120 | 67 00 72 00 61 00 6d 00 | g.r.a.m. |
2128 | 46 00 69 00 6c 00 65 00 | F.i.l.e. |
2136 | 73 00 28 00 78 00 38 00 | s.(.x.8. |
2144 | 36 00 29 00 3d 00 43 00 | 6.).=.C. |
2152 | 3a 00 5c 00 50 00 72 00 | :.\.P.r. |
2160 | 6f 00 67 00 72 00 61 00 | o.g.r.a. |
2168 | 6d 00 20 00 46 00 69 00 | m. .F.i. |
2176 | 6c 00 65 00 73 00 20 00 | l.e.s. . |
2184 | 28 00 78 00 38 00 36 00 | (.x.8.6. |
2192 | 29 00 00 00 50 00 72 00 | )...P.r. |
2200 | 6f 00 67 00 72 00 61 00 | o.g.r.a. |
2208 | 6d 00 57 00 36 00 34 00 | m.W.6.4. |
2216 | 33 00 32 00 3d 00 43 00 | 3.2.=.C. |
2224 | 3a 00 5c 00 50 00 72 00 | :.\.P.r. |
2232 | 6f 00 67 00 72 00 61 00 | o.g.r.a. |
2240 | 6d 00 20 00 46 00 69 00 | m. .F.i. |
2248 | 6c 00 65 00 73 00 00 00 | l.e.s... |
2256 | 50 00 53 00 4d 00 6f 00 | P.S.M.o. |
2264 | 64 00 75 00 6c 00 65 00 | d.u.l.e. |
2272 | 50 00 61 00 74 00 68 00 | P.a.t.h. |
2280 | 3d 00 25 00 50 00 72 00 | =.%.P.r. |
2288 | 6f 00 67 00 72 00 61 00 | o.g.r.a. |
2296 | 6d 00 46 00 69 00 6c 00 | m.F.i.l. |
2304 | 65 00 73 00 25 00 5c 00 | e.s.%.\. |
2312 | 57 00 69 00 6e 00 64 00 | W.i.n.d. |
2320 | 6f 00 77 00 73 00 50 00 | o.w.s.P. |
2328 | 6f 00 77 00 65 00 72 00 | o.w.e.r. |
2336 | 53 00 68 00 65 00 6c 00 | S.h.e.l. |
2344 | 6c 00 5c 00 4d 00 6f 00 | l.\.M.o. |
2352 | 64 00 75 00 6c 00 65 00 | d.u.l.e. |
2360 | 73 00 3b 00 43 00 3a 00 | s.;.C.:. |
2368 | 5c 00 57 00 49 00 4e 00 | \.W.I.N. |
2376 | 44 00 4f 00 57 00 53 00 | D.O.W.S. |
2384 | 5c 00 73 00 79 00 73 00 | \.s.y.s. |
2392 | 74 00 65 00 6d 00 33 00 | t.e.m.3. |
2400 | 32 00 5c 00 57 00 69 00 | 2.\.W.i. |
2408 | 6e 00 64 00 6f 00 77 00 | n.d.o.w. |
2416 | 73 00 50 00 6f 00 77 00 | s.P.o.w. |
2424 | 65 00 72 00 53 00 68 00 | e.r.S.h. |
2432 | 65 00 6c 00 6c 00 5c 00 | e.l.l.\. |
2440 | 76 00 31 00 2e 00 30 00 | v.1...0. |
2448 | 5c 00 4d 00 6f 00 64 00 | \.M.o.d. |
2456 | 75 00 6c 00 65 00 73 00 | u.l.e.s. |
2464 | 00 00 50 00 55 00 42 00 | ..P.U.B. |
2472 | 4c 00 49 00 43 00 3d 00 | L.I.C.=. |
2480 | 43 00 3a 00 5c 00 55 00 | C.:.\.U. |
2488 | 73 00 65 00 72 00 73 00 | s.e.r.s. |
2496 | 5c 00 50 00 75 00 62 00 | \.P.u.b. |
2504 | 6c 00 69 00 63 00 00 00 | l.i.c... |
2512 | 53 00 79 00 73 00 74 00 | S.y.s.t. |
2520 | 65 00 6d 00 44 00 72 00 | e.m.D.r. |
2528 | 69 00 76 00 65 00 3d 00 | i.v.e.=. |
2536 | 43 00 3a 00 00 00 53 00 | C.:...S. |
2544 | 79 00 73 00 74 00 65 00 | y.s.t.e. |
2552 | 6d 00 52 00 6f 00 6f 00 | m.R.o.o. |
2560 | 74 00 3d 00 43 00 3a 00 | t.=.C.:. |
2568 | 5c 00 57 00 49 00 4e 00 | \.W.I.N. |
2576 | 44 00 4f 00 57 00 53 00 | D.O.W.S. |
2584 | 00 00 54 00 45 00 4d 00 | ..T.E.M. |
2592 | 50 00 3d 00 43 00 3a 00 | P.=.C.:. |
2600 | 5c 00 57 00 49 00 4e 00 | \.W.I.N. |
2608 | 44 00 4f 00 57 00 53 00 | D.O.W.S. |
2616 | 5c 00 54 00 45 00 4d 00 | \.T.E.M. |
2624 | 50 00 00 00 54 00 4d 00 | P...T.M. |
2632 | 50 00 3d 00 43 00 3a 00 | P.=.C.:. |
2640 | 5c 00 57 00 49 00 4e 00 | \.W.I.N. |
2648 | 44 00 4f 00 57 00 53 00 | D.O.W.S. |
2656 | 5c 00 54 00 45 00 4d 00 | \.T.E.M. |
2664 | 50 00 00 00 55 00 53 00 | P...U.S. |
2672 | 45 00 52 00 44 00 4f 00 | E.R.D.O. |
2680 | 4d 00 41 00 49 00 4e 00 | M.A.I.N. |
2688 | 3d 00 57 00 4f 00 52 00 | =.W.O.R. |
2696 | 4b 00 47 00 52 00 4f 00 | K.G.R.O. |
2704 | 55 00 50 00 00 00 55 00 | U.P...U. |
2712 | 53 00 45 00 52 00 4e 00 | S.E.R.N. |
2720 | 41 00 4d 00 45 00 3d 00 | A.M.E.=. |
2728 | 57 00 49 00 4e 00 31 00 | W.I.N.1. |
2736 | 30 00 58 00 36 00 34 00 | 0.X.6.4. |
2744 | 2d 00 56 00 4d 00 24 00 | -.V.M.$. |
2752 | 00 00 55 00 53 00 45 00 | ..U.S.E. |
2760 | 52 00 50 00 52 00 4f 00 | R.P.R.O. |
2768 | 46 00 49 00 4c 00 45 00 | F.I.L.E. |
2776 | 3d 00 43 00 3a 00 5c 00 | =.C.:.\. |
2784 | 57 00 49 00 4e 00 44 00 | W.I.N.D. |
2792 | 4f 00 57 00 53 00 5c 00 | O.W.S.\. |
2800 | 73 00 79 00 73 00 74 00 | s.y.s.t. |
2808 | 65 00 6d 00 33 00 32 00 | e.m.3.2. |
2816 | 5c 00 63 00 6f 00 6e 00 | \.c.o.n. |
2824 | 66 00 69 00 67 00 5c 00 | f.i.g.\. |
2832 | 73 00 79 00 73 00 74 00 | s.y.s.t. |
2840 | 65 00 6d 00 70 00 72 00 | e.m.p.r. |
2848 | 6f 00 66 00 69 00 6c 00 | o.f.i.l. |
2856 | 65 00 00 00 77 00 69 00 | e...w.i. |
2864 | 6e 00 64 00 69 00 72 00 | n.d.i.r. |
2872 | 3d 00 43 00 3a 00 5c 00 | =.C.:.\. |
2880 | 57 00 49 00 4e 00 44 00 | W.I.N.D. |
2888 | 4f 00 57 00 53 00 00 00 | O.W.S... |
Call Stack stacksize=19
StackAddress | mod | ModName | ModPath |
---|---|---|---|
0xfffff80438037e56 | 174 | ntoskrnl.exe + 0x637e56 | C:\WINDOWS\system32\ntoskrnl.exe |
0xfffff804380f3856 | 174 | ntoskrnl.exe + 0x6f3856 | C:\WINDOWS\system32\ntoskrnl.exe |
0xfffff8043806cd29 | 174 | ntoskrnl.exe + 0x66cd29 | C:\WINDOWS\system32\ntoskrnl.exe |
0xfffff80437e077b5 | 174 | ntoskrnl.exe + 0x4077b5 | C:\WINDOWS\system32\ntoskrnl.exe |
0x7ffc927ee614 | |||
0x7ffc904e8dcc | |||
0x7ffc904e7106 | |||
0x7ffc91c1cbb4 | |||
0x7ffc7df37a6e | |||
0x7ffc754176c4 | |||
0x7ffc7541d64b | |||
0x7ffc7539631c | |||
0x7ffc75394c41 | |||
0x7ffc7535579b | |||
0x7ffc7df461d3 | |||
0x7ffc927b2150 | |||
0x7ffc927a315a | |||
0x7ffc91c17034 | |||
0x7ffc927a2651 |
ProcessStart is "Process Start" with a space in Procmon. And likewise, the corresponding detail field names are different in Procmon: ParentPid is Parent PID, CmdLine is Command line, CurDirectory is Current directory, Env is Environment.
See also
Posted 4 Jul 2022 last updated 15 Nov 2022 As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.
Copyright 2022, bryantlite, Inc.