| viewer9 documentation | Index Home |
ProcessStart PML Operation
This is the first event of the newly created process and is generally preceeded by a ProcessCreate event in the parent process.
ParentPid indicates the parent process. It should match the ProcParentPid shown in the process fields on the right. Also on the right will be a parentproc value and link, if the parent process was captured.
CmdLine shows the way the process was launched including the pathname used to call it and the arguments passed.
Env lists the environment variables of the process.
Example from 64-bit PML
Hover over field values like Time, ResultCode, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.
ProcessStart opcode=1,7
ev=84547
| Time: | 2022-05-17 19:41:53.7281411 |
| Duration: | 0.0000000 |
| ResultCode: | SUCCESS |
| Tid: | 7868 |
| ParentPid: | 3772 |
| CmdLine: | "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2203.5-0\MpCopyAccelerator.exe" |
| CurDirectory: | C:\WINDOWS\system32\ |
| Env: | ALLUSERSPROFILE=C:\ProgramData APPDATA=C:\WINDOWS\system32\config\systemprofile\AppData\Roaming CommonProgramFiles=C:\Program Files\Common Files CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files CommonProgramW6432=C:\Program Files\Common Files COMPUTERNAME=WIN10X64-VM ComSpec=C:\WINDOWS\system32\cmd.exe DriverData=C:\Windows\System32\Drivers\DriverData LOCALAPPDATA=C:\WINDOWS\system32\config\systemprofile\AppData\Local NUMBER_OF_PROCESSORS=4 OS=Windows_NT Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\WindowsApps PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC PROCESSOR_ARCHITECTURE=AMD64 PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 94 Stepping 3, GenuineIntel PROCESSOR_LEVEL=6 PROCESSOR_REVISION=5e03 ProgramData=C:\ProgramData ProgramFiles=C:\Program Files ProgramFiles(x86)=C:\Program Files (x86) ProgramW6432=C:\Program Files PSModulePath=%ProgramFiles%\WindowsPowerShell\Modules;C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules PUBLIC=C:\Users\Public SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\WINDOWS\TEMP TMP=C:\WINDOWS\TEMP USERDOMAIN=WORKGROUP USERNAME=WIN10X64-VM$ USERPROFILE=C:\WINDOWS\system32\config\systemprofile windir=C:\WINDOWS |
evdata[0-2895] file offset 40982764
| 0 | bc 0e 00 00 58 00 14 00 | ....X... |
| 8 | 36 05 00 00 22 00 43 00 | 6...".C. |
| 16 | 3a 00 5c 00 50 00 72 00 | :.\.P.r. |
| 24 | 6f 00 67 00 72 00 61 00 | o.g.r.a. |
| 32 | 6d 00 44 00 61 00 74 00 | m.D.a.t. |
| 40 | 61 00 5c 00 4d 00 69 00 | a.\.M.i. |
| 48 | 63 00 72 00 6f 00 73 00 | c.r.o.s. |
| 56 | 6f 00 66 00 74 00 5c 00 | o.f.t.\. |
| 64 | 57 00 69 00 6e 00 64 00 | W.i.n.d. |
| 72 | 6f 00 77 00 73 00 20 00 | o.w.s. . |
| 80 | 44 00 65 00 66 00 65 00 | D.e.f.e. |
| 88 | 6e 00 64 00 65 00 72 00 | n.d.e.r. |
| 96 | 5c 00 50 00 6c 00 61 00 | \.P.l.a. |
| 104 | 74 00 66 00 6f 00 72 00 | t.f.o.r. |
| 112 | 6d 00 5c 00 34 00 2e 00 | m.\.4... |
| 120 | 31 00 38 00 2e 00 32 00 | 1.8...2. |
| 128 | 32 00 30 00 33 00 2e 00 | 2.0.3... |
| 136 | 35 00 2d 00 30 00 5c 00 | 5.-.0.\. |
| 144 | 4d 00 70 00 43 00 6f 00 | M.p.C.o. |
| 152 | 70 00 79 00 41 00 63 00 | p.y.A.c. |
| 160 | 63 00 65 00 6c 00 65 00 | c.e.l.e. |
| 168 | 72 00 61 00 74 00 6f 00 | r.a.t.o. |
| 176 | 72 00 2e 00 65 00 78 00 | r...e.x. |
| 184 | 65 00 22 00 43 00 3a 00 | e.".C.:. |
| 192 | 5c 00 57 00 49 00 4e 00 | \.W.I.N. |
| 200 | 44 00 4f 00 57 00 53 00 | D.O.W.S. |
| 208 | 5c 00 73 00 79 00 73 00 | \.s.y.s. |
| 216 | 74 00 65 00 6d 00 33 00 | t.e.m.3. |
| 224 | 32 00 5c 00 41 00 4c 00 | 2.\.A.L. |
| 232 | 4c 00 55 00 53 00 45 00 | L.U.S.E. |
| 240 | 52 00 53 00 50 00 52 00 | R.S.P.R. |
| 248 | 4f 00 46 00 49 00 4c 00 | O.F.I.L. |
| 256 | 45 00 3d 00 43 00 3a 00 | E.=.C.:. |
| 264 | 5c 00 50 00 72 00 6f 00 | \.P.r.o. |
| 272 | 67 00 72 00 61 00 6d 00 | g.r.a.m. |
| 280 | 44 00 61 00 74 00 61 00 | D.a.t.a. |
| 288 | 00 00 41 00 50 00 50 00 | ..A.P.P. |
| 296 | 44 00 41 00 54 00 41 00 | D.A.T.A. |
| 304 | 3d 00 43 00 3a 00 5c 00 | =.C.:.\. |
| 312 | 57 00 49 00 4e 00 44 00 | W.I.N.D. |
| 320 | 4f 00 57 00 53 00 5c 00 | O.W.S.\. |
| 328 | 73 00 79 00 73 00 74 00 | s.y.s.t. |
| 336 | 65 00 6d 00 33 00 32 00 | e.m.3.2. |
| 344 | 5c 00 63 00 6f 00 6e 00 | \.c.o.n. |
| 352 | 66 00 69 00 67 00 5c 00 | f.i.g.\. |
| 360 | 73 00 79 00 73 00 74 00 | s.y.s.t. |
| 368 | 65 00 6d 00 70 00 72 00 | e.m.p.r. |
| 376 | 6f 00 66 00 69 00 6c 00 | o.f.i.l. |
| 384 | 65 00 5c 00 41 00 70 00 | e.\.A.p. |
| 392 | 70 00 44 00 61 00 74 00 | p.D.a.t. |
| 400 | 61 00 5c 00 52 00 6f 00 | a.\.R.o. |
| 408 | 61 00 6d 00 69 00 6e 00 | a.m.i.n. |
| 416 | 67 00 00 00 43 00 6f 00 | g...C.o. |
| 424 | 6d 00 6d 00 6f 00 6e 00 | m.m.o.n. |
| 432 | 50 00 72 00 6f 00 67 00 | P.r.o.g. |
| 440 | 72 00 61 00 6d 00 46 00 | r.a.m.F. |
| 448 | 69 00 6c 00 65 00 73 00 | i.l.e.s. |
| 456 | 3d 00 43 00 3a 00 5c 00 | =.C.:.\. |
| 464 | 50 00 72 00 6f 00 67 00 | P.r.o.g. |
| 472 | 72 00 61 00 6d 00 20 00 | r.a.m. . |
| 480 | 46 00 69 00 6c 00 65 00 | F.i.l.e. |
| 488 | 73 00 5c 00 43 00 6f 00 | s.\.C.o. |
| 496 | 6d 00 6d 00 6f 00 6e 00 | m.m.o.n. |
| 504 | 20 00 46 00 69 00 6c 00 | .F.i.l. |
| 512 | 65 00 73 00 00 00 43 00 | e.s...C. |
| 520 | 6f 00 6d 00 6d 00 6f 00 | o.m.m.o. |
| 528 | 6e 00 50 00 72 00 6f 00 | n.P.r.o. |
| 536 | 67 00 72 00 61 00 6d 00 | g.r.a.m. |
| 544 | 46 00 69 00 6c 00 65 00 | F.i.l.e. |
| 552 | 73 00 28 00 78 00 38 00 | s.(.x.8. |
| 560 | 36 00 29 00 3d 00 43 00 | 6.).=.C. |
| 568 | 3a 00 5c 00 50 00 72 00 | :.\.P.r. |
| 576 | 6f 00 67 00 72 00 61 00 | o.g.r.a. |
| 584 | 6d 00 20 00 46 00 69 00 | m. .F.i. |
| 592 | 6c 00 65 00 73 00 20 00 | l.e.s. . |
| 600 | 28 00 78 00 38 00 36 00 | (.x.8.6. |
| 608 | 29 00 5c 00 43 00 6f 00 | ).\.C.o. |
| 616 | 6d 00 6d 00 6f 00 6e 00 | m.m.o.n. |
| 624 | 20 00 46 00 69 00 6c 00 | .F.i.l. |
| 632 | 65 00 73 00 00 00 43 00 | e.s...C. |
| 640 | 6f 00 6d 00 6d 00 6f 00 | o.m.m.o. |
| 648 | 6e 00 50 00 72 00 6f 00 | n.P.r.o. |
| 656 | 67 00 72 00 61 00 6d 00 | g.r.a.m. |
| 664 | 57 00 36 00 34 00 33 00 | W.6.4.3. |
| 672 | 32 00 3d 00 43 00 3a 00 | 2.=.C.:. |
| 680 | 5c 00 50 00 72 00 6f 00 | \.P.r.o. |
| 688 | 67 00 72 00 61 00 6d 00 | g.r.a.m. |
| 696 | 20 00 46 00 69 00 6c 00 | .F.i.l. |
| 704 | 65 00 73 00 5c 00 43 00 | e.s.\.C. |
| 712 | 6f 00 6d 00 6d 00 6f 00 | o.m.m.o. |
| 720 | 6e 00 20 00 46 00 69 00 | n. .F.i. |
| 728 | 6c 00 65 00 73 00 00 00 | l.e.s... |
| 736 | 43 00 4f 00 4d 00 50 00 | C.O.M.P. |
| 744 | 55 00 54 00 45 00 52 00 | U.T.E.R. |
| 752 | 4e 00 41 00 4d 00 45 00 | N.A.M.E. |
| 760 | 3d 00 57 00 49 00 4e 00 | =.W.I.N. |
| 768 | 31 00 30 00 58 00 36 00 | 1.0.X.6. |
| 776 | 34 00 2d 00 56 00 4d 00 | 4.-.V.M. |
| 784 | 00 00 43 00 6f 00 6d 00 | ..C.o.m. |
| 792 | 53 00 70 00 65 00 63 00 | S.p.e.c. |
| 800 | 3d 00 43 00 3a 00 5c 00 | =.C.:.\. |
| 808 | 57 00 49 00 4e 00 44 00 | W.I.N.D. |
| 816 | 4f 00 57 00 53 00 5c 00 | O.W.S.\. |
| 824 | 73 00 79 00 73 00 74 00 | s.y.s.t. |
| 832 | 65 00 6d 00 33 00 32 00 | e.m.3.2. |
| 840 | 5c 00 63 00 6d 00 64 00 | \.c.m.d. |
| 848 | 2e 00 65 00 78 00 65 00 | ..e.x.e. |
| 856 | 00 00 44 00 72 00 69 00 | ..D.r.i. |
| 864 | 76 00 65 00 72 00 44 00 | v.e.r.D. |
| 872 | 61 00 74 00 61 00 3d 00 | a.t.a.=. |
| 880 | 43 00 3a 00 5c 00 57 00 | C.:.\.W. |
| 888 | 69 00 6e 00 64 00 6f 00 | i.n.d.o. |
| 896 | 77 00 73 00 5c 00 53 00 | w.s.\.S. |
| 904 | 79 00 73 00 74 00 65 00 | y.s.t.e. |
| 912 | 6d 00 33 00 32 00 5c 00 | m.3.2.\. |
| 920 | 44 00 72 00 69 00 76 00 | D.r.i.v. |
| 928 | 65 00 72 00 73 00 5c 00 | e.r.s.\. |
| 936 | 44 00 72 00 69 00 76 00 | D.r.i.v. |
| 944 | 65 00 72 00 44 00 61 00 | e.r.D.a. |
| 952 | 74 00 61 00 00 00 4c 00 | t.a...L. |
| 960 | 4f 00 43 00 41 00 4c 00 | O.C.A.L. |
| 968 | 41 00 50 00 50 00 44 00 | A.P.P.D. |
| 976 | 41 00 54 00 41 00 3d 00 | A.T.A.=. |
| 984 | 43 00 3a 00 5c 00 57 00 | C.:.\.W. |
| 992 | 49 00 4e 00 44 00 4f 00 | I.N.D.O. |
| 1000 | 57 00 53 00 5c 00 73 00 | W.S.\.s. |
| 1008 | 79 00 73 00 74 00 65 00 | y.s.t.e. |
| 1016 | 6d 00 33 00 32 00 5c 00 | m.3.2.\. |
| 1024 | 63 00 6f 00 6e 00 66 00 | c.o.n.f. |
| 1032 | 69 00 67 00 5c 00 73 00 | i.g.\.s. |
| 1040 | 79 00 73 00 74 00 65 00 | y.s.t.e. |
| 1048 | 6d 00 70 00 72 00 6f 00 | m.p.r.o. |
| 1056 | 66 00 69 00 6c 00 65 00 | f.i.l.e. |
| 1064 | 5c 00 41 00 70 00 70 00 | \.A.p.p. |
| 1072 | 44 00 61 00 74 00 61 00 | D.a.t.a. |
| 1080 | 5c 00 4c 00 6f 00 63 00 | \.L.o.c. |
| 1088 | 61 00 6c 00 00 00 4e 00 | a.l...N. |
| 1096 | 55 00 4d 00 42 00 45 00 | U.M.B.E. |
| 1104 | 52 00 5f 00 4f 00 46 00 | R._.O.F. |
| 1112 | 5f 00 50 00 52 00 4f 00 | _.P.R.O. |
| 1120 | 43 00 45 00 53 00 53 00 | C.E.S.S. |
| 1128 | 4f 00 52 00 53 00 3d 00 | O.R.S.=. |
| 1136 | 34 00 00 00 4f 00 53 00 | 4...O.S. |
| 1144 | 3d 00 57 00 69 00 6e 00 | =.W.i.n. |
| 1152 | 64 00 6f 00 77 00 73 00 | d.o.w.s. |
| 1160 | 5f 00 4e 00 54 00 00 00 | _.N.T... |
| 1168 | 50 00 61 00 74 00 68 00 | P.a.t.h. |
| 1176 | 3d 00 43 00 3a 00 5c 00 | =.C.:.\. |
| 1184 | 57 00 49 00 4e 00 44 00 | W.I.N.D. |
| 1192 | 4f 00 57 00 53 00 5c 00 | O.W.S.\. |
| 1200 | 73 00 79 00 73 00 74 00 | s.y.s.t. |
| 1208 | 65 00 6d 00 33 00 32 00 | e.m.3.2. |
| 1216 | 3b 00 43 00 3a 00 5c 00 | ;.C.:.\. |
| 1224 | 57 00 49 00 4e 00 44 00 | W.I.N.D. |
| 1232 | 4f 00 57 00 53 00 3b 00 | O.W.S.;. |
| 1240 | 43 00 3a 00 5c 00 57 00 | C.:.\.W. |
| 1248 | 49 00 4e 00 44 00 4f 00 | I.N.D.O. |
| 1256 | 57 00 53 00 5c 00 53 00 | W.S.\.S. |
| 1264 | 79 00 73 00 74 00 65 00 | y.s.t.e. |
| 1272 | 6d 00 33 00 32 00 5c 00 | m.3.2.\. |
| 1280 | 57 00 62 00 65 00 6d 00 | W.b.e.m. |
| 1288 | 3b 00 43 00 3a 00 5c 00 | ;.C.:.\. |
| 1296 | 57 00 49 00 4e 00 44 00 | W.I.N.D. |
| 1304 | 4f 00 57 00 53 00 5c 00 | O.W.S.\. |
| 1312 | 53 00 79 00 73 00 74 00 | S.y.s.t. |
| 1320 | 65 00 6d 00 33 00 32 00 | e.m.3.2. |
| 1328 | 5c 00 57 00 69 00 6e 00 | \.W.i.n. |
| 1336 | 64 00 6f 00 77 00 73 00 | d.o.w.s. |
| 1344 | 50 00 6f 00 77 00 65 00 | P.o.w.e. |
| 1352 | 72 00 53 00 68 00 65 00 | r.S.h.e. |
| 1360 | 6c 00 6c 00 5c 00 76 00 | l.l.\.v. |
| 1368 | 31 00 2e 00 30 00 5c 00 | 1...0.\. |
| 1376 | 3b 00 43 00 3a 00 5c 00 | ;.C.:.\. |
| 1384 | 57 00 49 00 4e 00 44 00 | W.I.N.D. |
| 1392 | 4f 00 57 00 53 00 5c 00 | O.W.S.\. |
| 1400 | 53 00 79 00 73 00 74 00 | S.y.s.t. |
| 1408 | 65 00 6d 00 33 00 32 00 | e.m.3.2. |
| 1416 | 5c 00 4f 00 70 00 65 00 | \.O.p.e. |
| 1424 | 6e 00 53 00 53 00 48 00 | n.S.S.H. |
| 1432 | 5c 00 3b 00 43 00 3a 00 | \.;.C.:. |
| 1440 | 5c 00 57 00 49 00 4e 00 | \.W.I.N. |
| 1448 | 44 00 4f 00 57 00 53 00 | D.O.W.S. |
| 1456 | 5c 00 73 00 79 00 73 00 | \.s.y.s. |
| 1464 | 74 00 65 00 6d 00 33 00 | t.e.m.3. |
| 1472 | 32 00 5c 00 63 00 6f 00 | 2.\.c.o. |
| 1480 | 6e 00 66 00 69 00 67 00 | n.f.i.g. |
| 1488 | 5c 00 73 00 79 00 73 00 | \.s.y.s. |
| 1496 | 74 00 65 00 6d 00 70 00 | t.e.m.p. |
| 1504 | 72 00 6f 00 66 00 69 00 | r.o.f.i. |
| 1512 | 6c 00 65 00 5c 00 41 00 | l.e.\.A. |
| 1520 | 70 00 70 00 44 00 61 00 | p.p.D.a. |
| 1528 | 74 00 61 00 5c 00 4c 00 | t.a.\.L. |
| 1536 | 6f 00 63 00 61 00 6c 00 | o.c.a.l. |
| 1544 | 5c 00 4d 00 69 00 63 00 | \.M.i.c. |
| 1552 | 72 00 6f 00 73 00 6f 00 | r.o.s.o. |
| 1560 | 66 00 74 00 5c 00 57 00 | f.t.\.W. |
| 1568 | 69 00 6e 00 64 00 6f 00 | i.n.d.o. |
| 1576 | 77 00 73 00 41 00 70 00 | w.s.A.p. |
| 1584 | 70 00 73 00 00 00 50 00 | p.s...P. |
| 1592 | 41 00 54 00 48 00 45 00 | A.T.H.E. |
| 1600 | 58 00 54 00 3d 00 2e 00 | X.T.=... |
| 1608 | 43 00 4f 00 4d 00 3b 00 | C.O.M.;. |
| 1616 | 2e 00 45 00 58 00 45 00 | ..E.X.E. |
| 1624 | 3b 00 2e 00 42 00 41 00 | ;...B.A. |
| 1632 | 54 00 3b 00 2e 00 43 00 | T.;...C. |
| 1640 | 4d 00 44 00 3b 00 2e 00 | M.D.;... |
| 1648 | 56 00 42 00 53 00 3b 00 | V.B.S.;. |
| 1656 | 2e 00 56 00 42 00 45 00 | ..V.B.E. |
| 1664 | 3b 00 2e 00 4a 00 53 00 | ;...J.S. |
| 1672 | 3b 00 2e 00 4a 00 53 00 | ;...J.S. |
| 1680 | 45 00 3b 00 2e 00 57 00 | E.;...W. |
| 1688 | 53 00 46 00 3b 00 2e 00 | S.F.;... |
| 1696 | 57 00 53 00 48 00 3b 00 | W.S.H.;. |
| 1704 | 2e 00 4d 00 53 00 43 00 | ..M.S.C. |
| 1712 | 00 00 50 00 52 00 4f 00 | ..P.R.O. |
| 1720 | 43 00 45 00 53 00 53 00 | C.E.S.S. |
| 1728 | 4f 00 52 00 5f 00 41 00 | O.R._.A. |
| 1736 | 52 00 43 00 48 00 49 00 | R.C.H.I. |
| 1744 | 54 00 45 00 43 00 54 00 | T.E.C.T. |
| 1752 | 55 00 52 00 45 00 3d 00 | U.R.E.=. |
| 1760 | 41 00 4d 00 44 00 36 00 | A.M.D.6. |
| 1768 | 34 00 00 00 50 00 52 00 | 4...P.R. |
| 1776 | 4f 00 43 00 45 00 53 00 | O.C.E.S. |
| 1784 | 53 00 4f 00 52 00 5f 00 | S.O.R._. |
| 1792 | 49 00 44 00 45 00 4e 00 | I.D.E.N. |
| 1800 | 54 00 49 00 46 00 49 00 | T.I.F.I. |
| 1808 | 45 00 52 00 3d 00 49 00 | E.R.=.I. |
| 1816 | 6e 00 74 00 65 00 6c 00 | n.t.e.l. |
| 1824 | 36 00 34 00 20 00 46 00 | 6.4. .F. |
| 1832 | 61 00 6d 00 69 00 6c 00 | a.m.i.l. |
| 1840 | 79 00 20 00 36 00 20 00 | y. .6. . |
| 1848 | 4d 00 6f 00 64 00 65 00 | M.o.d.e. |
| 1856 | 6c 00 20 00 39 00 34 00 | l. .9.4. |
| 1864 | 20 00 53 00 74 00 65 00 | .S.t.e. |
| 1872 | 70 00 70 00 69 00 6e 00 | p.p.i.n. |
| 1880 | 67 00 20 00 33 00 2c 00 | g. .3.,. |
| 1888 | 20 00 47 00 65 00 6e 00 | .G.e.n. |
| 1896 | 75 00 69 00 6e 00 65 00 | u.i.n.e. |
| 1904 | 49 00 6e 00 74 00 65 00 | I.n.t.e. |
| 1912 | 6c 00 00 00 50 00 52 00 | l...P.R. |
| 1920 | 4f 00 43 00 45 00 53 00 | O.C.E.S. |
| 1928 | 53 00 4f 00 52 00 5f 00 | S.O.R._. |
| 1936 | 4c 00 45 00 56 00 45 00 | L.E.V.E. |
| 1944 | 4c 00 3d 00 36 00 00 00 | L.=.6... |
| 1952 | 50 00 52 00 4f 00 43 00 | P.R.O.C. |
| 1960 | 45 00 53 00 53 00 4f 00 | E.S.S.O. |
| 1968 | 52 00 5f 00 52 00 45 00 | R._.R.E. |
| 1976 | 56 00 49 00 53 00 49 00 | V.I.S.I. |
| 1984 | 4f 00 4e 00 3d 00 35 00 | O.N.=.5. |
| 1992 | 65 00 30 00 33 00 00 00 | e.0.3... |
| 2000 | 50 00 72 00 6f 00 67 00 | P.r.o.g. |
| 2008 | 72 00 61 00 6d 00 44 00 | r.a.m.D. |
| 2016 | 61 00 74 00 61 00 3d 00 | a.t.a.=. |
| 2024 | 43 00 3a 00 5c 00 50 00 | C.:.\.P. |
| 2032 | 72 00 6f 00 67 00 72 00 | r.o.g.r. |
| 2040 | 61 00 6d 00 44 00 61 00 | a.m.D.a. |
| 2048 | 74 00 61 00 00 00 50 00 | t.a...P. |
| 2056 | 72 00 6f 00 67 00 72 00 | r.o.g.r. |
| 2064 | 61 00 6d 00 46 00 69 00 | a.m.F.i. |
| 2072 | 6c 00 65 00 73 00 3d 00 | l.e.s.=. |
| 2080 | 43 00 3a 00 5c 00 50 00 | C.:.\.P. |
| 2088 | 72 00 6f 00 67 00 72 00 | r.o.g.r. |
| 2096 | 61 00 6d 00 20 00 46 00 | a.m. .F. |
| 2104 | 69 00 6c 00 65 00 73 00 | i.l.e.s. |
| 2112 | 00 00 50 00 72 00 6f 00 | ..P.r.o. |
| 2120 | 67 00 72 00 61 00 6d 00 | g.r.a.m. |
| 2128 | 46 00 69 00 6c 00 65 00 | F.i.l.e. |
| 2136 | 73 00 28 00 78 00 38 00 | s.(.x.8. |
| 2144 | 36 00 29 00 3d 00 43 00 | 6.).=.C. |
| 2152 | 3a 00 5c 00 50 00 72 00 | :.\.P.r. |
| 2160 | 6f 00 67 00 72 00 61 00 | o.g.r.a. |
| 2168 | 6d 00 20 00 46 00 69 00 | m. .F.i. |
| 2176 | 6c 00 65 00 73 00 20 00 | l.e.s. . |
| 2184 | 28 00 78 00 38 00 36 00 | (.x.8.6. |
| 2192 | 29 00 00 00 50 00 72 00 | )...P.r. |
| 2200 | 6f 00 67 00 72 00 61 00 | o.g.r.a. |
| 2208 | 6d 00 57 00 36 00 34 00 | m.W.6.4. |
| 2216 | 33 00 32 00 3d 00 43 00 | 3.2.=.C. |
| 2224 | 3a 00 5c 00 50 00 72 00 | :.\.P.r. |
| 2232 | 6f 00 67 00 72 00 61 00 | o.g.r.a. |
| 2240 | 6d 00 20 00 46 00 69 00 | m. .F.i. |
| 2248 | 6c 00 65 00 73 00 00 00 | l.e.s... |
| 2256 | 50 00 53 00 4d 00 6f 00 | P.S.M.o. |
| 2264 | 64 00 75 00 6c 00 65 00 | d.u.l.e. |
| 2272 | 50 00 61 00 74 00 68 00 | P.a.t.h. |
| 2280 | 3d 00 25 00 50 00 72 00 | =.%.P.r. |
| 2288 | 6f 00 67 00 72 00 61 00 | o.g.r.a. |
| 2296 | 6d 00 46 00 69 00 6c 00 | m.F.i.l. |
| 2304 | 65 00 73 00 25 00 5c 00 | e.s.%.\. |
| 2312 | 57 00 69 00 6e 00 64 00 | W.i.n.d. |
| 2320 | 6f 00 77 00 73 00 50 00 | o.w.s.P. |
| 2328 | 6f 00 77 00 65 00 72 00 | o.w.e.r. |
| 2336 | 53 00 68 00 65 00 6c 00 | S.h.e.l. |
| 2344 | 6c 00 5c 00 4d 00 6f 00 | l.\.M.o. |
| 2352 | 64 00 75 00 6c 00 65 00 | d.u.l.e. |
| 2360 | 73 00 3b 00 43 00 3a 00 | s.;.C.:. |
| 2368 | 5c 00 57 00 49 00 4e 00 | \.W.I.N. |
| 2376 | 44 00 4f 00 57 00 53 00 | D.O.W.S. |
| 2384 | 5c 00 73 00 79 00 73 00 | \.s.y.s. |
| 2392 | 74 00 65 00 6d 00 33 00 | t.e.m.3. |
| 2400 | 32 00 5c 00 57 00 69 00 | 2.\.W.i. |
| 2408 | 6e 00 64 00 6f 00 77 00 | n.d.o.w. |
| 2416 | 73 00 50 00 6f 00 77 00 | s.P.o.w. |
| 2424 | 65 00 72 00 53 00 68 00 | e.r.S.h. |
| 2432 | 65 00 6c 00 6c 00 5c 00 | e.l.l.\. |
| 2440 | 76 00 31 00 2e 00 30 00 | v.1...0. |
| 2448 | 5c 00 4d 00 6f 00 64 00 | \.M.o.d. |
| 2456 | 75 00 6c 00 65 00 73 00 | u.l.e.s. |
| 2464 | 00 00 50 00 55 00 42 00 | ..P.U.B. |
| 2472 | 4c 00 49 00 43 00 3d 00 | L.I.C.=. |
| 2480 | 43 00 3a 00 5c 00 55 00 | C.:.\.U. |
| 2488 | 73 00 65 00 72 00 73 00 | s.e.r.s. |
| 2496 | 5c 00 50 00 75 00 62 00 | \.P.u.b. |
| 2504 | 6c 00 69 00 63 00 00 00 | l.i.c... |
| 2512 | 53 00 79 00 73 00 74 00 | S.y.s.t. |
| 2520 | 65 00 6d 00 44 00 72 00 | e.m.D.r. |
| 2528 | 69 00 76 00 65 00 3d 00 | i.v.e.=. |
| 2536 | 43 00 3a 00 00 00 53 00 | C.:...S. |
| 2544 | 79 00 73 00 74 00 65 00 | y.s.t.e. |
| 2552 | 6d 00 52 00 6f 00 6f 00 | m.R.o.o. |
| 2560 | 74 00 3d 00 43 00 3a 00 | t.=.C.:. |
| 2568 | 5c 00 57 00 49 00 4e 00 | \.W.I.N. |
| 2576 | 44 00 4f 00 57 00 53 00 | D.O.W.S. |
| 2584 | 00 00 54 00 45 00 4d 00 | ..T.E.M. |
| 2592 | 50 00 3d 00 43 00 3a 00 | P.=.C.:. |
| 2600 | 5c 00 57 00 49 00 4e 00 | \.W.I.N. |
| 2608 | 44 00 4f 00 57 00 53 00 | D.O.W.S. |
| 2616 | 5c 00 54 00 45 00 4d 00 | \.T.E.M. |
| 2624 | 50 00 00 00 54 00 4d 00 | P...T.M. |
| 2632 | 50 00 3d 00 43 00 3a 00 | P.=.C.:. |
| 2640 | 5c 00 57 00 49 00 4e 00 | \.W.I.N. |
| 2648 | 44 00 4f 00 57 00 53 00 | D.O.W.S. |
| 2656 | 5c 00 54 00 45 00 4d 00 | \.T.E.M. |
| 2664 | 50 00 00 00 55 00 53 00 | P...U.S. |
| 2672 | 45 00 52 00 44 00 4f 00 | E.R.D.O. |
| 2680 | 4d 00 41 00 49 00 4e 00 | M.A.I.N. |
| 2688 | 3d 00 57 00 4f 00 52 00 | =.W.O.R. |
| 2696 | 4b 00 47 00 52 00 4f 00 | K.G.R.O. |
| 2704 | 55 00 50 00 00 00 55 00 | U.P...U. |
| 2712 | 53 00 45 00 52 00 4e 00 | S.E.R.N. |
| 2720 | 41 00 4d 00 45 00 3d 00 | A.M.E.=. |
| 2728 | 57 00 49 00 4e 00 31 00 | W.I.N.1. |
| 2736 | 30 00 58 00 36 00 34 00 | 0.X.6.4. |
| 2744 | 2d 00 56 00 4d 00 24 00 | -.V.M.$. |
| 2752 | 00 00 55 00 53 00 45 00 | ..U.S.E. |
| 2760 | 52 00 50 00 52 00 4f 00 | R.P.R.O. |
| 2768 | 46 00 49 00 4c 00 45 00 | F.I.L.E. |
| 2776 | 3d 00 43 00 3a 00 5c 00 | =.C.:.\. |
| 2784 | 57 00 49 00 4e 00 44 00 | W.I.N.D. |
| 2792 | 4f 00 57 00 53 00 5c 00 | O.W.S.\. |
| 2800 | 73 00 79 00 73 00 74 00 | s.y.s.t. |
| 2808 | 65 00 6d 00 33 00 32 00 | e.m.3.2. |
| 2816 | 5c 00 63 00 6f 00 6e 00 | \.c.o.n. |
| 2824 | 66 00 69 00 67 00 5c 00 | f.i.g.\. |
| 2832 | 73 00 79 00 73 00 74 00 | s.y.s.t. |
| 2840 | 65 00 6d 00 70 00 72 00 | e.m.p.r. |
| 2848 | 6f 00 66 00 69 00 6c 00 | o.f.i.l. |
| 2856 | 65 00 00 00 77 00 69 00 | e...w.i. |
| 2864 | 6e 00 64 00 69 00 72 00 | n.d.i.r. |
| 2872 | 3d 00 43 00 3a 00 5c 00 | =.C.:.\. |
| 2880 | 57 00 49 00 4e 00 44 00 | W.I.N.D. |
| 2888 | 4f 00 57 00 53 00 00 00 | O.W.S... |
Call Stack stacksize=19
| StackAddress | mod | ModName | ModPath |
|---|---|---|---|
| 0xfffff80438037e56 | 174 | ntoskrnl.exe + 0x637e56 | C:\WINDOWS\system32\ntoskrnl.exe |
| 0xfffff804380f3856 | 174 | ntoskrnl.exe + 0x6f3856 | C:\WINDOWS\system32\ntoskrnl.exe |
| 0xfffff8043806cd29 | 174 | ntoskrnl.exe + 0x66cd29 | C:\WINDOWS\system32\ntoskrnl.exe |
| 0xfffff80437e077b5 | 174 | ntoskrnl.exe + 0x4077b5 | C:\WINDOWS\system32\ntoskrnl.exe |
| 0x7ffc927ee614 | |||
| 0x7ffc904e8dcc | |||
| 0x7ffc904e7106 | |||
| 0x7ffc91c1cbb4 | |||
| 0x7ffc7df37a6e | |||
| 0x7ffc754176c4 | |||
| 0x7ffc7541d64b | |||
| 0x7ffc7539631c | |||
| 0x7ffc75394c41 | |||
| 0x7ffc7535579b | |||
| 0x7ffc7df461d3 | |||
| 0x7ffc927b2150 | |||
| 0x7ffc927a315a | |||
| 0x7ffc91c17034 | |||
| 0x7ffc927a2651 |
ProcessStart is "Process Start" with a space in Procmon. And likewise, the corresponding detail field names are different in Procmon: ParentPid is Parent PID, CmdLine is Command line, CurDirectory is Current directory, Env is Environment.
See also
Posted 4 Jul 2022 last updated 15 Nov 2022 As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.
Copyright 2022, bryantlite, Inc.