INVALID_PROCESS_ATTACH_ATTEMPT
Code: 0x5 (5)
As HRESULT:- S: 0 (Success)
- C: 0 (Microsoft-defined)
- N: 0 (Not an NTSTATUS value)
- Facility: 0x000 (FACILITY_NULL: Default)
- Code: 0x0005 (5)
- Sev: 0 (STATUS_SEVERITY_SUCCESS)
- C: 0 (Microsoft-defined)
- Facility: 0x000 (Default)
- Code: 0x0005 (5)
Parameters
| Parameter | Description |
|---|---|
| 1 | The pointer to the dispatcher object for the target process, or if the thread is already attached, the pointer to the object for the original process. |
| 2 | The pointer to the dispatcher object of the process that the current thread is currently attached to. |
| 3 | The value of the thread's APC state index. |
| 4 | A non-zero value indicates that a DPC is running on the current processor. |
Description
The INVALID_PROCESS_ATTACH_ATTEMPT bug check has a value of 0x00000005. This generally indicates that the thread was attached to a process in a situation where that is not allowed. For example, this bug check could occur if KeAttachProcess was called when the thread was already attached to a process (which is illegal), or if the thread returned from certain function calls in an attached state (which is invalid),
This bug check appears very infrequently.
Important
This article is for programmers. If you're a customer who has received a blue screen error code while using your computer, see Troubleshoot blue screen errors.
Remarks
The !analyze debug extension displays information about the bug check and can be helpful in determining the root cause.
This bug check can occur if the driver calls the KeAttachProcess function and the thread is already attached to another process. It is better to use the KeStackAttachProcess function. If the current thread was already attached to another process, the KeStackAttachProcess function saves the current APC state before it attaches the current thread to the new process. Calling KeStackAttachProcess incorrectly can also cause this bug check, for example if a DPC is running on the current processor.
For general information about this area, see working with Windows Kernel-Mode Process and Thread Manager and Introduction to Kernel Dispatcher Objects.
Article text from the Windows driver documentation (opens in a new tab), by Microsoft, under the CC BY 4.0 (opens in a new tab) licence.
Associated Modules
| Module | Code | Found in | Description |
|---|---|---|---|
| DevDispItemProvider.dll | 0x5 | 8.11011 | %1 - Front |
| ESENT.dll | 0x5 | 8.11011 | Table/Column/Index Definition |
| EhStorTcgDrv.sys | 0x5 | 1011 | Unexpected size. Object: %1 Expected Size: %2 Actual Size: %3 |
| EventCreate.exe | 0x5 | 78.11011 | %1 |
| KernelBase.dll | 0x5 | 78.1 | Access is denied. |
| NetTCPIP.dll | 0x5 | 1011 | Not all required properties are specified: %1 and either %2 %3 %4 %5 or %6 %7 |
| SMCCx.dll | 0x5 | 1011 | Unexpected size. Object: %1 Expected Size: %2 Actual Size: %3 |
| ServiceModelEvents.dll | 0x5 | 78.11011 | WebHost |
| UsbccidDriver.dll | 0x5 | 1011 | Unexpected size. Object: %1 Expected Size: %2 Actual Size: %3 |
| VSSVC.exe | 0x5 | 1011 | Volume Shadow Copy Service initialization error: could not retrieve backup/restore privilege [%1]. %2 |
| WUDFUsbccidDriver.dll | 0x5 | 1011 | Unexpected size. Object: %1 Expected Size: %2 Actual Size: %3 |
| WinSAT.exe | 0x5 | 1011 | The assessment or other operation did not complete successfully. This is due to an error being reported from the operating system, driver, or other component. |
| WudfSMCClassExt.dll | 0x5 | 1011 | Unexpected size. Object: %1 Expected Size: %2 Actual Size: %3 |
| bootstr.dll | 0x5 | 1011 | Windows PreInstallation Environment |
| cmimcext.sys | 0x5 | 1011 | Value blocked: %4 under the key, %2, was NOT set after failing validation. |
| connect.dll | 0x5 | 78.11011 | Failed to connect to %1!s! |
| cscui.dll | 0x5 | 1011 | A portion of the Offline Files cache has become corrupted. Restart the computer to clean up the cache. |
| deviceaccess.dll | 0x5 | 8.1 | Task %1 request was denied. %2 cannot service device %4 because: %7. |
| deviceregistration.dll | 0x5 | 1011 | Workplace Join discovery failed. Server returned http status %1. Service URI: %2 |
| dskquota.dll | 0x5 | 78.11011 | Error %1 instantiating IClassFactory in dskquota.dll. %2. |
| dskquoui.dll | 0x5 | 78.11011 | Error %1 instantiating IClassFactory in dskquota.dll. %2. |
| dsreg.dll | 0x5 | 1011 | The discovery request send operation failed with exit code: %1. Inputs: Domain: %2 |
| dssec.dll | 0x5 | 78.11011 | Receive as |
| ehepgres.dll | 0x5 | 7 | %1 |
| ehrecvr.exe | 0x5 | 7 | Media Center Receiver Service could not determine temporary storage location. (0x%1) |
| ehsched.exe | 0x5 | 7 | %1 |
| findstr.exe | 0x5 | 78.11011 | %1: Write error |
| finger.exe | 0x5 | 78.1 | t_look returned %1!d! |
| fltmgr.sys | 0x5 | 1011 | File System Filter '%5' (Version %2.%3, %6) failed to register with Filter Manager. The final status for this operation was %1. |
| fontview.exe | 0x5 | 78.11011 | Font name: %1 |
| ftp.exe | 0x5 | 78.1 | t_look returned %1!d! |
| hostname.exe | 0x5 | 78.1 | t_look returned %1!d! |
| hvloader.dll | 0x5 | 11 | Hypervisor launch has been disabled through the hypervisorlaunchtype bcdedit setting. |
| hvservice.sys | 0x5 | 10 | Hypervisor launch has been disabled through the hypervisorlaunchtype bcdedit setting. |
| kernel32.dll | 0x5 | 78.11011 | Access is denied. |
| microsoft-windows-kernel-processor-power-events.dll | 0x5 | 1011 | Some processor idle power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware. |
| mispace.dll | 0x5 | 8.11011 | %1: An error was encountered while enumerating objects from subsystem "%2" on host "%3". Error encountered was %4 = "%6" (%5!u!). |
| mountvol.exe | 0x5 | 78.11011 | Possible values for VolumeName along with current mount points are: |
| msaudite.dll | 0x5 | 78.11011 | Detailed Tracking |
| msprivs.dll | 0x5 | 78.11011 | Adjust memory quotas for a process |
| netcfg.exe | 0x5 | 1011 | *** You need to reboot your computer for this change to take effect *** |
| netdacim.dll | 0x5 | 8.11011 | Latency must be less than 1000ms. |
| netnccim.dll | 0x5 | 8.11011 | Latency must be less than 1000ms. |
| netttcim.dll | 0x5 | 8.11011 | Latency must be less than 1000ms. |
| nslookup.exe | 0x5 | 78.11011 | Aliased to "%1" |
| powershell.exe | 0x5 | 78.11011 | Starting the CLR failed with HRESULT %1!lx!. |
| pwrshmsg.dll | 0x5 | 78.11011 | Command Lifecycle |
| reagentc.exe | 0x5 | 78.11011 | %1: Operation successful |
| sc.exe | 0x5 | 78.11011 | DESCRIPTION:
Changes the actions upon failure
USAGE:
sc |
| sstpsvc.dll | 0x5 | 1011 | CoId=%1:The Secure Socket Tunneling Protocol (SSTP) negotiation has failed. The failure code is stored in the Data section of this message. Correct the problem and try again. |
| storagewmi.dll | 0x5 | 8.11011 | The requested name could not be applied to the newly created object. |
| w32time.dll | 0x5 | 1011 | The time provider '%1' returned the following error during shutdown: %2 |
| webservices.dll | 0x5 | 78.11011 | The WS_TYPE '%1' may not be used as an optional field. |
| wecutil.exe | 0x5 | 78.11011 | Failed to read from config file. |
| wevtapi.dll | 0x5 | 78.11011 | Shell |
| wevtutil.exe | 0x5 | 78.11011 | Failed to set %1!s! property. |
| wfascim.dll | 0x5 | 1011 | This edition of Windows does not support the requested functionality. |
| win32k.sys | 0x5 | 78.1 | SwapMouseButtons |
| win32kbase.sys | 0x5 | 1011 | SwapMouseButtons |
| winbio.dll | 0x5 | 8.11011 | Move your finger more slowly on the fingerprint reader. |
| winsrv.dll | 0x5 | 78.11011 | Success |
| winsrvext.dll | 0x5 | 11 | Success |
| 62 entries | |||