viewer9 documentation

FlushBuffersFile PML Operation

Example from 64-bit PML

Hover over field values like Time, ResultCode, and bytes of evdata in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

FlushBuffersFile opcode=3,29

ev=38646 advop=IRP_MJ_FLUSH_BUFFERS

Time:2022-05-17 16:06:22.7852722
Duration:0.0041173
ResultCode:SUCCESS
Tid:3836
Path:C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat

evdata[0-124] file offset 21895934

000 00 00 00 b6 00 00 00 ........
800 00 06 00 01 00 00 00 ........
1600 00 00 00 00 00 00 00 ........
omit 4 rows of zeros
5600 00 00 00 00 00 00 00 ........
6435 80 cf 02 43 3a 5c 50 5...C:\P
7272 6f 67 72 61 6d 44 61 rogramDa
8074 61 5c 4d 69 63 72 6f ta\Micro
8873 6f 66 74 5c 4e 65 74 soft\Net
9677 6f 72 6b 5c 44 6f 77 work\Dow
1046e 6c 6f 61 64 65 72 5c nloader\
11271 6d 67 72 30 2e 64 61 qmgr0.da
12074 3e 7c c5 77 t>..w

Call Stack stacksize=22

StackAddressmodModNameModPath
0xfffff880011730f7194fltmgr.sys + 0x20f7C:\Windows\system32\drivers\fltmgr.sys
0xfffff88001173fc7194fltmgr.sys + 0x2fc7C:\Windows\system32\drivers\fltmgr.sys
0xfffff880011726c7194fltmgr.sys + 0x16c7C:\Windows\system32\drivers\fltmgr.sys
0xfffff80002b491fa161ntoskrnl.exe + 0x2fb1faC:\Windows\system32\ntoskrnl.exe
0xfffff80002b6900d161ntoskrnl.exe + 0x31b00dC:\Windows\system32\ntoskrnl.exe
0xfffff800028eff53161ntoskrnl.exe + 0xa1f53C:\Windows\system32\ntoskrnl.exe
0x77c89c5a2ntdll.dll + 0x69c5aC:\Windows\SYSTEM32\ntdll.dll
0x7fefd7eaf6843KERNELBASE.dll + 0x1af68C:\Windows\system32\KERNELBASE.dll
0x7fef711e796434qmgr.dll + 0x2e796c:\windows\system32\qmgr.dll
0x7fef7114056434qmgr.dll + 0x24056c:\windows\system32\qmgr.dll
0x7fef71186b4434qmgr.dll + 0x286b4c:\windows\system32\qmgr.dll
0x7fef7110a1e434qmgr.dll + 0x20a1ec:\windows\system32\qmgr.dll
0x77b39ac11USER32.dll + 0x19ac1C:\Windows\system32\USER32.dll
0x77b397de1USER32.dll + 0x197deC:\Windows\system32\USER32.dll
0x7fef7111f6d434qmgr.dll + 0x21f6dc:\windows\system32\qmgr.dll
0x7fef711c987434qmgr.dll + 0x2c987c:\windows\system32\qmgr.dll
0x7fef7100160434qmgr.dll + 0x10160c:\windows\system32\qmgr.dll
0x7fef70ffaa9434qmgr.dll + 0xfaa9c:\windows\system32\qmgr.dll
0xff671344367svchost.exe + 0x1344C:\Windows\system32\svchost.exe
0x7fefdf0a82d50sechost.dll + 0xa82dC:\Windows\SYSTEM32\sechost.dll
0x77a1556d0kernel32.dll + 0x1556dC:\Windows\system32\kernel32.dll
0x77c7372d2ntdll.dll + 0x5372dC:\Windows\SYSTEM32\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.