what further info can be deduced from the information
the below process seems to run
but windbg says no active threads ?
so on whose back this is piggybacking ( i mean how to find the pig
that is backing this ? )
no handles ? no object table ?
i also can see two explorer instance one 2 days old and not having
active thread ??
another 1 day old and having threads ?
what mean no active threads ? ( i mean can passive threads if any can
be put to use to run something ? )
this is a vm that doesnt have /debug so i cant attach kd
what further info (maximum that is possible that could be learnt
passively using lkd or whatever !! before resorting to third degree
from the paste below
lkd> .process /p /r 85dba020
Implicit process is now 85dba020
Loading User Symbols
PEB is paged out (Peb.Ldr = 7ffde00c). Type “.hh dbgerr001” for details
lkd> !process 85dba020 17
PROCESS 85dba020 SessionId: 0 Cid: 09d8 Peb: 7ffde000 ParentCid: 08e8
DirBase: 10700320 ObjectTable: 00000000 HandleCount: 0.
Image: wq3qef54.exe
VadRoot 00000000 Vads 0 Clone 0 Private 0. Modified 49. Locked 0.
DeviceMap e3059d10
Token e5146030
ElapsedTime 01:46:41.250
UserTime 00:00:00.046
KernelTime 00:00:00.171
QuotaPoolUsage[PagedPool] 0
QuotaPoolUsage[NonPagedPool] 0
Working Set Sizes (now,min,max) (8, 50, 345) (32KB, 200KB, 1380KB)
PeakWorkingSetSize 685
VirtualSize 26 Mb
PeakVirtualSize 29 Mb
PageFaultCount 694
MemoryPriority BACKGROUND
BasePriority 8
CommitCharge 0
No active threads
lkd> !process 0 0 explorer.exe
PROCESS 863fc320 SessionId: 0 Cid: 017c Peb: 7ffdf000 ParentCid: 07f4
DirBase: 107002e0 ObjectTable: 00000000 HandleCount: 0.
Image: explorer.exe
PROCESS 860009c8 SessionId: 0 Cid: 0424 Peb: 7ffda000 ParentCid: 0cc4
DirBase: 10700440 ObjectTable: e1c92a20 HandleCount: 826.
Image: explorer.exe
lkd> .process /p /r 863fc320
Implicit process is now 863fc320
Loading User Symbols
PEB is paged out (Peb.Ldr = 7ffdf00c). Type “.hh dbgerr001” for details
lkd> !process 863fc320 17
PROCESS 863fc320 SessionId: 0 Cid: 017c Peb: 7ffdf000 ParentCid: 07f4
DirBase: 107002e0 ObjectTable: 00000000 HandleCount: 0.
Image: explorer.exe
VadRoot 00000000 Vads 0 Clone 0 Private 0. Modified 929127. Locked 0.
DeviceMap e3059d10
Token e36d1438
ElapsedTime 2 Days 11:26:33.468
UserTime 00:04:15.703
KernelTime 00:02:14.125
QuotaPoolUsage[PagedPool] 0
QuotaPoolUsage[NonPagedPool] 0
Working Set Sizes (now,min,max) (14, 50, 345) (56KB, 200KB, 1380KB)
PeakWorkingSetSize 15789
VirtualSize 157 Mb
PeakVirtualSize 500 Mb
PageFaultCount 1042096
MemoryPriority BACKGROUND
BasePriority 8
CommitCharge 0
No active threads
lkd> !process 860009c8 17
PROCESS 860009c8 SessionId: 0 Cid: 0424 Peb: 7ffda000 ParentCid: 0cc4
DirBase: 10700440 ObjectTable: e1c92a20 HandleCount: 826.
Image: explorer.exe
VadRoot 8601f920 Vads 539 Clone 0 Private 14425. Modified 397280. Locked 0.
DeviceMap e3059d10
Token e4606030
ElapsedTime 1 Day 07:38:39.984
UserTime 00:04:30.890
KernelTime 00:01:56.984
QuotaPoolUsage[PagedPool] 269404
QuotaPoolUsage[NonPagedPool] 24200
Working Set Sizes (now,min,max) (6962, 50, 345) (27848KB, 200KB, 1380KB)
PeakWorkingSetSize 15329
VirtualSize 210 Mb
PeakVirtualSize 234 Mb
PageFaultCount 524892
MemoryPriority BACKGROUND
BasePriority 8
CommitCharge 17170
THREAD 85ccfc78 Cid 0424.0f60 Teb: 7ffdf000 Win32Thread: e2b2cb50 WAIT
: (WrUserRequest) UserMode Non-Alertable
86596970 SynchronizationEvent
Not impersonating
DeviceMap e3059d10
Owning Process 0 Image:
Attached Process 860009c8 Image: explorer.exe
Wait Start TickCount 13693288 Ticks: 10206 (0:00:02:39.468)
Context Switch Count 45600 LargeStack
UserTime 00:00:07.546
KernelTime 00:00:14.109
*** ERROR: Module load completed but symbols could not be loaded for C:\WINDOWS<br>explorer.exe
Win32 Start Address explorer (0x0101a55f)
Start Address KERNEL32!BaseProcessStartThunk (0x7c810705)
Stack Init a862f000 Current a862ecb0 Base a862f000 Limit a862b000 Call 0
Priority 10 BasePriority 8 PriorityDecrement 0 DecrementCount 16
Kernel stack not resident.
THREAD 86568c88 Cid 0424.0c4c Teb: 7ffdd000 Win32Thread: e3865690 WAIT
: (Unknown) UserMode Non-Alertable
85ff1fc0 Semaphore Limit 0x7fffffff
lkd>