viewer9 documentation

CloseFile PML Operation

Example from 64-bit PML

Hover over field values like Time, ResultCode, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

CloseFile opcode=3,38

ev=8867 advop=IRP_MN_QUERY_INFORMATION

Time:2022-05-17 16:06:21.1163640
Duration:0.0000064
ResultCode:SUCCESS
Tid:1676
Path:C:\Windows\System32\spool\drivers\color\sRGB Color Space Profile.icm

evdata[0-137] file offset 5060938

000 07 00 00 3b 7f bb e4 ....;...
804 04 00 00 01 00 00 00 ........
1600 00 00 00 00 00 00 00 ........
omit 4 rows of zeros
5600 00 00 00 00 00 00 00 ........
6444 80 00 00 43 3a 5c 57 D...C:\W
7269 6e 64 6f 77 73 5c 53 indows\S
8079 73 74 65 6d 33 32 5c ystem32\
8873 70 6f 6f 6c 5c 64 72 spool\dr
9669 76 65 72 73 5c 63 6f ivers\co
1046c 6f 72 5c 73 52 47 42 lor\sRGB
11220 43 6f 6c 6f 72 20 53 Color S
12070 61 63 65 20 50 72 6f pace Pro
12866 69 6c 65 2e 69 63 6d file.icm
13675 00 u.

Call Stack stacksize=41

StackAddressmodModNameModPath
0xfffff880011730f7194fltmgr.sys + 0x20f7C:\Windows\system32\drivers\fltmgr.sys
0xfffff88001173fc7194fltmgr.sys + 0x2fc7C:\Windows\system32\drivers\fltmgr.sys
0xfffff880011726c7194fltmgr.sys + 0x16c7C:\Windows\system32\drivers\fltmgr.sys
0xfffff80002b46def161ntoskrnl.exe + 0x2f8defC:\Windows\system32\ntoskrnl.exe
0xfffff80002b479ed161ntoskrnl.exe + 0x2f99edC:\Windows\system32\ntoskrnl.exe
0xfffff80002c7a849161ntoskrnl.exe + 0x42c849C:\Windows\system32\ntoskrnl.exe
0xfffff80002b466d4161ntoskrnl.exe + 0x2f86d4C:\Windows\system32\ntoskrnl.exe
0xfffff800028eff53161ntoskrnl.exe + 0xa1f53C:\Windows\system32\ntoskrnl.exe
0x77c8989a2ntdll.dll + 0x6989aC:\Windows\SYSTEM32\ntdll.dll
0x7fefd7d186343KERNELBASE.dll + 0x1863C:\Windows\system32\KERNELBASE.dll
0x77a214f10kernel32.dll + 0x214f1C:\Windows\system32\kernel32.dll
0x7fef3c742d1691mscms.dll + 0x42d1C:\Windows\system32\mscms.dll
0x7fef3c71c95691mscms.dll + 0x1c95C:\Windows\system32\mscms.dll
0x7feff7ffbe257GDI32.dll + 0x2fbe2C:\Windows\system32\GDI32.dll
0x7feff7ff86657GDI32.dll + 0x2f866C:\Windows\system32\GDI32.dll
0x7feff801df957GDI32.dll + 0x31df9C:\Windows\system32\GDI32.dll
0x7feff7fde3457GDI32.dll + 0x2de34C:\Windows\system32\GDI32.dll
0x7feff7fb31757GDI32.dll + 0x2b317C:\Windows\system32\GDI32.dll
0x7fee6e722dd683chrome.dll + 0x17522ddC:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x77b35ab41USER32.dll + 0x15ab4C:\Windows\system32\USER32.dll
0x77c8b4ef2ntdll.dll + 0x6b4efC:\Windows\SYSTEM32\ntdll.dll
0xfffff80002b29d66161ntoskrnl.exe + 0x2dbd66C:\Windows\system32\ntoskrnl.exe
0xfffff960001a35c5310win32k.sys + 0x1535c5C:\Windows\System32\win32k.sys
0xfffff960000993b7310win32k.sys + 0x493b7C:\Windows\System32\win32k.sys
0xfffff96000139b3c310win32k.sys + 0xe9b3cC:\Windows\System32\win32k.sys
0xfffff800028eff53161ntoskrnl.exe + 0xa1f53C:\Windows\system32\ntoskrnl.exe
0x77b35aea1USER32.dll + 0x15aeaC:\Windows\system32\USER32.dll
0x7fee716d52b683chrome.dll + 0x1a4d52bC:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee5880ec2683chrome.dll + 0x160ec2C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee716dafa683chrome.dll + 0x1a4dafaC:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee65f16c8683chrome.dll + 0xed16c8C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee5c39e14683chrome.dll + 0x519e14C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee950519b683chrome.dll + 0x3de519bC:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee8bd8f60683chrome.dll + 0x34b8f60C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee936f7e5683chrome.dll + 0x3c4f7e5C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee936eb97683chrome.dll + 0x3c4eb97C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee936dce0683chrome.dll + 0x3c4dce0C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee5a7b6b8683chrome.dll + 0x35b6b8C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x7fee60739d1683chrome.dll + 0x9539d1C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x77a1556d0kernel32.dll + 0x1556dC:\Windows\system32\kernel32.dll
0x77c7372d2ntdll.dll + 0x5372dC:\Windows\SYSTEM32\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.