THREAD ffffd10924d0b400 Cid
0004.0154
Teb:
0000000000000000
Win32Thread:
0000000000000000
WAIT: (Executive) KernelMode Non
-
Alertable
ffffe10e11971da8 SynchronizationEvent
Not impersonating
DeviceMap ffff990972809a20
Owning Process ffffd10924cf1040 Image: System
Attached Process N
/
A Image: N
/
A
Wait Start TickCount
15963
Ticks:
10903
(
0
:
00
:
02
:
50.359
)
Context Switch Count
6807
IdealProcessor:
5
UserTime
00
:
00
:
00.000
KernelTime
00
:
00
:
00.140
Win32 Start Address nt!ExpWorkerThread (
0xfffff80666ad7c30
)
Stack Init ffffe10e11972530 Current ffffe10e11971650
Base ffffe10e11973000 Limit ffffe10e1196c000 Call
0000000000000000
Priority
12
BasePriority
12
IoPriority
2
PagePriority
5
Child
-
SP RetAddr Call Site
ffffe10e`
11971690
fffff806`
66a3ba05
nt!KiSwapContext
+
0x76
ffffe10e`
119717d0
fffff806`
66a3dbe7
nt!KiSwapThread
+
0xab5
ffffe10e`
11971920
fffff806`
66a3fb06
nt!KiCommitThreadWait
+
0x137
ffffe10e`
119719d0
fffff806`
66a8fe98
nt!KeWaitForSingleObject
+
0x256
ffffe10e`
11971d70
fffff806`
66ad70b4
nt!ExfWaitForRundownProtectionRelease
+
0xf4
ffffe10e`
11971de0
fffff806`
67c7370e
nt!ExWaitForRundownProtectionRelease
+
0x24
ffffe10e`
11971e10
fffff806`
67cc1850
FLTMGR!FltpWaitForRundownProtectionReleaseInternal
+
0x11a
ffffe10e`
11971f20
fffff806`
67cd8376
FLTMGR!FltUnregisterFilter
+
0xf0
ffffe10e`
11971fe0
fffff80b`
98f364c9
FLTMGR!FltvUnregisterFilter
+
0x16
ffffe10e`
11972010
fffff806`
67cccb99
fsflt!FilterUnload
+
0x89
[D:\
filter
.c @
479
]
ffffe10e`
11972050
fffff806`
67ccce36
FLTMGR!FltpDoUnloadFilter
+
0x19d
ffffe10e`
11972240
fffff806`
670ce773
FLTMGR!FltpMiniFilterDriverUnload
+
0x146
ffffe10e`
11972280
fffff806`
66ad7d85
nt!IopLoadUnloadDriver
+
0x191653
ffffe10e`
119722c0
fffff806`
66b6e8e7
nt!ExpWorkerThread
+
0x155
ffffe10e`
119724b0
fffff806`
66c1e0f4
nt!PspSystemThreadStartup
+
0x57
ffffe10e`
11972500
00000000
`
00000000
nt!KiStartSystemThread
+
0x34