-


2


"" "" .   ,   ( ) . , , , win32 API- CreateProcess:

 

xor eax,eax ; eax := 0

push offset pi ; lpProcessInformation

push offset sis ; lpStartupInfo

push eax ; lpCurrentDirectory

push eax ; lpEnvironment

push eax ; dwCreationFlags

push eax ; bInheritHandles

push eax ; lpThreadAttributes

push eax ; lpProcessAttributes

push offset file_name ;

push eax ; lpApplicationName

call ds:[CreateProcess];

API-

IAT