3
If execute the !process command in the windwos debugger you get output in this format:
PROCESS fffffa8006bff940
SessionId: 0 Cid: 03ec Peb: 7f79ae1f000 ParentCid: 02e4
DirBase: 084ed000 ObjectTable: fffff8a002c3fd80 HandleCount: <Data Not Accessible>
Image: svchost.exe
It's well documented that Cid is the ProcessId (pid) in hex. However, I don't see what the C stands for.
2That's not the "c" he's talking about. – ckhan – 2013-01-03T07:39:28.500
lol, I reread his output a few times, thinking it was an odd question. Misinterpretation on my part. – Solemnity – 2013-01-04T00:32:00.390