viewer9 documentation

ThreadExit PML Operation

Example from 64-bit PML

Hover over field values like Time, ResultCode, CreatedTime, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

ThreadExit opcode=1,4

ev=6214

Time:2020-08-20 21:25:12.2189388
Duration:0.0000000
ResultCode:SUCCESS
Tid:12164
UserTime:0.0000000
KernelTime:0.0000000

evdata[0-19] file offset 2756932

003 01 00 00 00 00 00 00 ........
800 00 00 00 00 00 00 00 ........
1600 00 00 00 ....

Call Stack stacksize=5

StackAddressmodModNameModPath
0xfffff8010c5d20b9383ntoskrnl.exe + 0x5d20b9C:\WINDOWS\system32\ntoskrnl.exe
0xfffff8010c6261a8383ntoskrnl.exe + 0x6261a8C:\WINDOWS\system32\ntoskrnl.exe
0xfffff8010c624493383ntoskrnl.exe + 0x624493C:\WINDOWS\system32\ntoskrnl.exe
0xfffff8010c62441a383ntoskrnl.exe + 0x62441aC:\WINDOWS\system32\ntoskrnl.exe
0xfffff8010c1d3c15383ntoskrnl.exe + 0x1d3c15C:\WINDOWS\system32\ntoskrnl.exe

ThreadExit is "Thread Exit" with a space in Procmon, And likewise, these corresponding detail field names have spaces in Procmon: User Time, Kernel Time.

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.