viewer9 documentation | Index Home |
Device PNP PML Operations
These operations belong to opcode=3,47. evdata[0] corresponds to the PnP IRP minor function code (see PML Binary Data and Results Offsets).
DeviceUsageNotification
Corresponds to IRP_MN_DEVICE_USAGE_NOTIFICATION 0x16.
QueryDeviceRelations
Corresponds to IRP_MN_QUERY_DEVICE_RELATIONS 0x07.
Example of QueryDeviceRelations from 32-bit PML
Hover over field values like Time, ResultCode, and bytes of evdata (like evdata[0] mentioned above) in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.
QueryDeviceRelations opcode=3,47
ev=6330 advop=IRP_MJ_PNP
Time: | 2022-05-19 23:22:14.6848668 |
Duration: | 0.0000202 |
ResultCode: | SUCCESS |
Tid: | 36 |
Path: | C:\$Mft |
evdata[0-58] file offset 1452717
0 | 07 ff ff ff ff ff ff ff | ........ |
8 | 00 00 00 00 01 00 00 00 | ........ |
16 | 04 00 00 00 00 00 00 00 | ........ |
24 | 00 00 00 00 00 00 00 00 | ........ |
32 | 00 00 00 00 00 00 00 00 | ........ |
40 | 00 00 00 00 07 80 ff ff | ........ |
48 | 43 3a 5c 24 4d 66 74 ff | C:\$Mft. |
56 | ff ff ff | ... |
Call Stack stacksize=13
StackAddress | mod | ModName | ModPath |
---|---|---|---|
0x8ac86df7 | 159 | fltmgr.sys + 0x2df7 | C:\Windows\system32\drivers\fltmgr.sys |
0x8ac89d38 | 159 | fltmgr.sys + 0x5d38 | C:\Windows\system32\drivers\fltmgr.sys |
0x8ac8a251 | 159 | fltmgr.sys + 0x6251 | C:\Windows\system32\drivers\fltmgr.sys |
0x8ac8a710 | 159 | fltmgr.sys + 0x6710 | C:\Windows\system32\drivers\fltmgr.sys |
0x82886f87 | 128 | ntkrnlpa.exe + 0x39f87 | C:\Windows\system32\ntkrnlpa.exe |
0x82a325b8 | 128 | ntkrnlpa.exe + 0x1e55b8 | C:\Windows\system32\ntkrnlpa.exe |
0x8286a2b2 | 128 | ntkrnlpa.exe + 0x1d2b2 | C:\Windows\system32\ntkrnlpa.exe |
0x829f387a | 128 | ntkrnlpa.exe + 0x1a687a | C:\Windows\system32\ntkrnlpa.exe |
0x829f375d | 128 | ntkrnlpa.exe + 0x1a675d | C:\Windows\system32\ntkrnlpa.exe |
0x8aeacc75 | 166 | Ntfs.sys + 0xa2c75 | C:\Windows\System32\Drivers\Ntfs.sys |
0x8ae223dc | 166 | Ntfs.sys + 0x183dc | C:\Windows\System32\Drivers\Ntfs.sys |
0x828b7b4b | 128 | ntkrnlpa.exe + 0x6ab4b | C:\Windows\system32\ntkrnlpa.exe |
0x82a62b38 | 128 | ntkrnlpa.exe + 0x215b38 | C:\Windows\system32\ntkrnlpa.exe |
See also
Posted 4 Jul 2022 last updated 15 Nov 2022 As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.
Copyright 2022, bryantlite, Inc.