<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Attached Processes</title>
	<link>https://www.dumpanalysis.org/blog/index.php/2010/06/11/attached-processes/</link>
	<description>Structural and Behavioral Patterns for Software Diagnostics, Forensics and Prognostics</description>
	<pubDate>Wed, 06 May 2026 20:18:28 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: Dmitry Vostokov</title>
		<link>https://www.dumpanalysis.org/blog/index.php/2010/06/11/attached-processes/#comment-158832</link>
		<dc:creator>Dmitry Vostokov</dc:creator>
		<pubDate>Wed, 16 Jun 2010 21:05:08 +0000</pubDate>
		<guid>https://www.dumpanalysis.org/blog/index.php/2010/06/11/attached-processes/#comment-158832</guid>
		<description>Here is an example when System process is attached (for system thread):

THREAD 8827cdb0  Cid 0f64.2ef8  Teb: 00000000 Win32Thread: 00000000 WAIT: (Unknown) KernelMode Non-Alertable
    89562144  SynchronizationEvent
IRP List:
    897548c0: (0006,0094) Flags: 00000404  Mdl: 00000000
Not impersonating
DeviceMap                 e1003880
Owning Process            89e264e8       Image:         svchost.exe
Attached Process          8a78c7e0       Image:         System
Wait Start TickCount      3705814        Ticks: 3365934 (0:14:36:32.718)
Context Switch Count      424599             
UserTime                  00:00:00.000
KernelTime                00:00:03.578
Start Address termdd!_IcaDriverThread (0xf683a30c)
Stack Init f40e2000 Current f40e1294 Base f40e2000 Limit f40df000 Call 0
Priority 10 BasePriority 10 PriorityDecrement 0
ChildEBP RetAddr  
f40e12ac 8083d26e nt!KiSwapContext+0x26
f40e12d8 8083dc5e nt!KiSwapThread+0x2e5
f40e1320 f5baa873 nt!KeWaitForSingleObject+0x346
f40e136c f5ba1965 tcpip!TCPCleanup+0xcf
f40e13a8 8083fe13 tcpip!TCPDispatch+0x10c
f40e13bc 80930b42 nt!IofCallDriver+0x45
f40e13ec 8092d5e0 nt!IopCloseFile+0x2ae
f40e141c 8092d783 nt!ObpDecrementHandleCount+0xcc
f40e1444 8092d6a7 nt!ObpCloseHandleTableEntry+0x131
f40e1488 8092d6f2 nt!ObpCloseHandle+0x82
f40e1498 8083387f nt!NtClose+0x1b
f40e1498 8083acd4 nt!KiFastCallEntry+0xfc (TrapFrame @ f40e14a4)
f40e1514 f6839c6c nt!ZwClose+0x11
f40e152c f43ce141 termdd!IcaZwClose+0x48
f40e1548 f43cc80a TDTCP!DeviceCancelIo+0xa1
f40e1558 f43cceb5 TDTCP!StackCancelIo+0x24
f40e1d90 f683a359 TDTCP!TdInputThread+0x25b
f40e1dac 8092277b termdd!_IcaDriverThread+0x4d
f40e1ddc 8083fb5f nt!PspSystemThreadStartup+0x2e
00000000 00000000 nt!KiThreadStartup+0x16</description>
		<content:encoded><![CDATA[<p>Here is an example when System process is attached (for system thread):</p>
<p>THREAD 8827cdb0  Cid 0f64.2ef8  Teb: 00000000 Win32Thread: 00000000 WAIT: (Unknown) KernelMode Non-Alertable<br />
    89562144  SynchronizationEvent<br />
IRP List:<br />
    897548c0: (0006,0094) Flags: 00000404  Mdl: 00000000<br />
Not impersonating<br />
DeviceMap                 e1003880<br />
Owning Process            89e264e8       Image:         svchost.exe<br />
Attached Process          8a78c7e0       Image:         System<br />
Wait Start TickCount      3705814        Ticks: 3365934 (0:14:36:32.718)<br />
Context Switch Count      424599<br />
UserTime                  00:00:00.000<br />
KernelTime                00:00:03.578<br />
Start Address termdd!_IcaDriverThread (0xf683a30c)<br />
Stack Init f40e2000 Current f40e1294 Base f40e2000 Limit f40df000 Call 0<br />
Priority 10 BasePriority 10 PriorityDecrement 0<br />
ChildEBP RetAddr<br />
f40e12ac 8083d26e nt!KiSwapContext+0&#215;26<br />
f40e12d8 8083dc5e nt!KiSwapThread+0&#215;2e5<br />
f40e1320 f5baa873 nt!KeWaitForSingleObject+0&#215;346<br />
f40e136c f5ba1965 tcpip!TCPCleanup+0xcf<br />
f40e13a8 8083fe13 tcpip!TCPDispatch+0&#215;10c<br />
f40e13bc 80930b42 nt!IofCallDriver+0&#215;45<br />
f40e13ec 8092d5e0 nt!IopCloseFile+0&#215;2ae<br />
f40e141c 8092d783 nt!ObpDecrementHandleCount+0xcc<br />
f40e1444 8092d6a7 nt!ObpCloseHandleTableEntry+0&#215;131<br />
f40e1488 8092d6f2 nt!ObpCloseHandle+0&#215;82<br />
f40e1498 8083387f nt!NtClose+0&#215;1b<br />
f40e1498 8083acd4 nt!KiFastCallEntry+0xfc (TrapFrame @ f40e14a4)<br />
f40e1514 f6839c6c nt!ZwClose+0&#215;11<br />
f40e152c f43ce141 termdd!IcaZwClose+0&#215;48<br />
f40e1548 f43cc80a TDTCP!DeviceCancelIo+0xa1<br />
f40e1558 f43cceb5 TDTCP!StackCancelIo+0&#215;24<br />
f40e1d90 f683a359 TDTCP!TdInputThread+0&#215;25b<br />
f40e1dac 8092277b termdd!_IcaDriverThread+0&#215;4d<br />
f40e1ddc 8083fb5f nt!PspSystemThreadStartup+0&#215;2e<br />
00000000 00000000 nt!KiThreadStartup+0&#215;16</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dmitry Vostokov</title>
		<link>https://www.dumpanalysis.org/blog/index.php/2010/06/11/attached-processes/#comment-157587</link>
		<dc:creator>Dmitry Vostokov</dc:creator>
		<pubDate>Fri, 11 Jun 2010 15:29:45 +0000</pubDate>
		<guid>https://www.dumpanalysis.org/blog/index.php/2010/06/11/attached-processes/#comment-157587</guid>
		<description>Great! I missed that post from your blog. Reading now
Thanks,
Dmitry</description>
		<content:encoded><![CDATA[<p>Great! I missed that post from your blog. Reading now<br />
Thanks,<br />
Dmitry</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott</title>
		<link>https://www.dumpanalysis.org/blog/index.php/2010/06/11/attached-processes/#comment-157575</link>
		<dc:creator>Scott</dc:creator>
		<pubDate>Fri, 11 Jun 2010 14:27:21 +0000</pubDate>
		<guid>https://www.dumpanalysis.org/blog/index.php/2010/06/11/attached-processes/#comment-157575</guid>
		<description>I covered a bit more detail on why these two fields exist and the differences in the debugger output depending on the target O/S version here:

http://analyze-v.com/?p=234

-scott</description>
		<content:encoded><![CDATA[<p>I covered a bit more detail on why these two fields exist and the differences in the debugger output depending on the target O/S version here:</p>
<p><a href="http://analyze-v.com/?p=234" rel="nofollow">http://analyze-v.com/?p=234</a></p>
<p>-scott</p>
]]></content:encoded>
	</item>
</channel>
</rss>
