viewer9 documentation

QueryEAFile PML Operation

Example from 64-bit PML

Hover over field values like Time, ResultCode, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

QueryEAFile opcode=3,27

ev=168963 advop=IRP_MJ_QUERY_EA

Time:2022-05-17 20:43:26.7105015
Duration:0.0000059
ResultCode:SUCCESS
Tid:376
Path:C:\Windows\CSC\v2.0.6

evdata[0-92] file offset 55777404

000 00 00 00 05 00 73 00 ......s.
800 00 16 00 01 00 00 00 ........
16f5 01 00 00 00 00 00 00 ........
24d0 70 df 08 80 fa ff ff .p......
323a 00 00 00 00 00 00 00 :.......
4000 00 00 00 00 00 00 00 ........
4800 9e c6 01 a0 f8 ff ff ........
5600 00 00 00 00 00 00 00 ........
6415 80 ff ff 43 3a 5c 57 ....C:\W
7269 6e 64 6f 77 73 5c 43 indows\C
8053 43 5c 76 32 2e 30 2e SC\v2.0.
8836 90 00 00 00 6....

Call Stack stacksize=68

StackAddressmodModNameModPath
0xfffff880011440f782fltmgr.sys + 0x20f7C:\Windows\system32\drivers\fltmgr.sys
0xfffff88001144fc782fltmgr.sys + 0x2fc7C:\Windows\system32\drivers\fltmgr.sys
0xfffff880011436c782fltmgr.sys + 0x16c7C:\Windows\system32\drivers\fltmgr.sys
0xfffff80002afe1fa49ntoskrnl.exe + 0x2fb1faC:\Windows\system32\ntoskrnl.exe
0xfffff80002ccbd7f49ntoskrnl.exe + 0x4c8d7fC:\Windows\system32\ntoskrnl.exe
0xfffff800028a4f5349ntoskrnl.exe + 0xa1f53C:\Windows\system32\ntoskrnl.exe
0xfffff8000289a6c049ntoskrnl.exe + 0x976c0C:\Windows\system32\ntoskrnl.exe
0xfffff880043936ab154csc.sys + 0x1f6abC:\Windows\system32\drivers\csc.sys
0xfffff88004392734154csc.sys + 0x1e734C:\Windows\system32\drivers\csc.sys
0xfffff8800439bb4e154csc.sys + 0x27b4eC:\Windows\system32\drivers\csc.sys
0xfffff88004397ea3154csc.sys + 0x23ea3C:\Windows\system32\drivers\csc.sys
0xfffff88004397fdb154csc.sys + 0x23fdbC:\Windows\system32\drivers\csc.sys
0xfffff88004397d4e154csc.sys + 0x23d4eC:\Windows\system32\drivers\csc.sys
0xfffff880043ceea8154csc.sys + 0x5aea8C:\Windows\system32\drivers\csc.sys
0xfffff88004386831154csc.sys + 0x12831C:\Windows\system32\drivers\csc.sys
0xfffff880043cdaa2154csc.sys + 0x59aa2C:\Windows\system32\drivers\csc.sys
0xfffff88004386e51154csc.sys + 0x12e51C:\Windows\system32\drivers\csc.sys
0xfffff880043b448c154csc.sys + 0x4048cC:\Windows\system32\drivers\csc.sys
0xfffff880043b4dd9154csc.sys + 0x40dd9C:\Windows\system32\drivers\csc.sys
0xfffff88004325213150rdbss.sys + 0x2a213C:\Windows\system32\DRIVERS\rdbss.sys
0xfffff88004324623150rdbss.sys + 0x29623C:\Windows\system32\DRIVERS\rdbss.sys
0xfffff88004323d53150rdbss.sys + 0x28d53C:\Windows\system32\DRIVERS\rdbss.sys
0xfffff880042ff768150rdbss.sys + 0x4768C:\Windows\system32\DRIVERS\rdbss.sys
0xfffff8800431dbb4150rdbss.sys + 0x22bb4C:\Windows\system32\DRIVERS\rdbss.sys
0xfffff880043b1b4a154csc.sys + 0x3db4aC:\Windows\system32\drivers\csc.sys
0xfffff8800437c753154csc.sys + 0x8753C:\Windows\system32\drivers\csc.sys
0xfffff880017e3c40107mup.sys + 0x6c40C:\Windows\System32\Drivers\mup.sys
0xfffff880017e3157107mup.sys + 0x6157C:\Windows\System32\Drivers\mup.sys
0xfffff880017e464b107mup.sys + 0x764bC:\Windows\System32\Drivers\mup.sys
0xfffff8800114483f82fltmgr.sys + 0x283fC:\Windows\system32\drivers\fltmgr.sys
0xfffff880011622b982fltmgr.sys + 0x202b9C:\Windows\system32\drivers\fltmgr.sys
0xfffff80002cebb1249ntoskrnl.exe + 0x4e8b12C:\Windows\system32\ntoskrnl.exe
0xfffff80002c0fc6449ntoskrnl.exe + 0x40cc64C:\Windows\system32\ntoskrnl.exe
0xfffff80002afd77649ntoskrnl.exe + 0x2fa776C:\Windows\system32\ntoskrnl.exe
0xfffff80002cb932849ntoskrnl.exe + 0x4b6328C:\Windows\system32\ntoskrnl.exe
0xfffff80002ac277b49ntoskrnl.exe + 0x2bf77bC:\Windows\system32\ntoskrnl.exe
0xfffff88001176ed582fltmgr.sys + 0x34ed5C:\Windows\system32\drivers\fltmgr.sys
0xfffff8800117870e82fltmgr.sys + 0x3670eC:\Windows\system32\drivers\fltmgr.sys
0xfffff880011650e482fltmgr.sys + 0x230e4C:\Windows\system32\drivers\fltmgr.sys
0xfffff880011697ba82fltmgr.sys + 0x277baC:\Windows\system32\drivers\fltmgr.sys
0xfffff88001164da082fltmgr.sys + 0x22da0C:\Windows\system32\drivers\fltmgr.sys
0xfffff8800115233d82fltmgr.sys + 0x1033dC:\Windows\system32\drivers\fltmgr.sys
0xfffff8800114840d82fltmgr.sys + 0x640dC:\Windows\system32\drivers\fltmgr.sys
0xfffff8800115335782fltmgr.sys + 0x11357C:\Windows\system32\drivers\fltmgr.sys
0xfffff880011a2c7484PROCMON24.SYS + 0x2c74C:\Windows\System32\Drivers\PROCMON24.SYS
0xfffff880011440f782fltmgr.sys + 0x20f7C:\Windows\system32\drivers\fltmgr.sys
0xfffff88001146a0a82fltmgr.sys + 0x4a0aC:\Windows\system32\drivers\fltmgr.sys
0xfffff880011622a382fltmgr.sys + 0x202a3C:\Windows\system32\drivers\fltmgr.sys
0xfffff80002cebb1249ntoskrnl.exe + 0x4e8b12C:\Windows\system32\ntoskrnl.exe
0xfffff80002c0fc6449ntoskrnl.exe + 0x40cc64C:\Windows\system32\ntoskrnl.exe
0xfffff80002afd77649ntoskrnl.exe + 0x2fa776C:\Windows\system32\ntoskrnl.exe
0xfffff80002cb932849ntoskrnl.exe + 0x4b6328C:\Windows\system32\ntoskrnl.exe
0xfffff80002b4bee449ntoskrnl.exe + 0x348ee4C:\Windows\system32\ntoskrnl.exe
0xfffff800028a4f5349ntoskrnl.exe + 0xa1f53C:\Windows\system32\ntoskrnl.exe
0x77089cfa4ntdll.dll + 0x69cfaC:\Windows\System32\ntdll.dll
0x7fefa7d1c63364cscsvc.dll + 0x1c63C:\Windows\System32\cscsvc.dll
0x7fefa7d21c0364cscsvc.dll + 0x21c0C:\Windows\System32\cscsvc.dll
0x7fefa7e2d35364cscsvc.dll + 0x12d35C:\Windows\System32\cscsvc.dll
0x7fefa7d89b1364cscsvc.dll + 0x89b1C:\Windows\System32\cscsvc.dll
0x7fefa7d8bf7364cscsvc.dll + 0x8bf7C:\Windows\System32\cscsvc.dll
0x7fefa7e2049364cscsvc.dll + 0x12049C:\Windows\System32\cscsvc.dll
0x7fefa7e30db364cscsvc.dll + 0x130dbC:\Windows\System32\cscsvc.dll
0x7fefa7e02d1364cscsvc.dll + 0x102d1C:\Windows\System32\cscsvc.dll
0x7fefa7dfeb5364cscsvc.dll + 0xfeb5C:\Windows\System32\cscsvc.dll
0xffce1344322svchost.exe + 0x1344C:\Windows\System32\svchost.exe
0x7fefeeea82d43sechost.dll + 0xa82dC:\Windows\System32\sechost.dll
0x76e1556d2kernel32.dll + 0x1556dC:\Windows\System32\kernel32.dll
0x7707372d4ntdll.dll + 0x5372dC:\Windows\System32\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.