Unable to load image ntoskrnl.exe的问题
来源:互联网 发布:淘宝上买的轮毂可靠吗 编辑:程序博客网 时间:2024/06/05 14:27
最近在分析一个蓝屏dump时发现,nt模块加载不了符号表,其他系统驱动的符号表都能加载成功
3: kd> .reload /f ntUnable to load image ntoskrnl.exe, Win32 error 0n2*** WARNING: Unable to verify timestamp for ntoskrnl.exe*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
激活详细符号加载信息
3: kd> !sym noisynoisy mode - symbol prompts on3: kd> .reload /f ntSYMSRV: d:\mysymbol\ntoskrnl.exe\56BCC7865ec000\ntoskrnl.exe not foundSYMSRV: http://msdl.microsoft.com/download/symbols/ntoskrnl.exe/56BCC7865ec000/ntoskrnl.exe not foundSYMSRV: d:\mysymbol\ntkrnlup.exe\56BCC7865ec000\ntkrnlup.exe not foundSYMSRV: http://msdl.microsoft.com/download/symbols/ntkrnlup.exe/56BCC7865ec000/ntkrnlup.exe not foundSYMSRV: d:\mysymbol\ntkrnlpa.exe\56BCC7865ec000\ntkrnlpa.exe not foundSYMSRV: http://msdl.microsoft.com/download/symbols/ntkrnlpa.exe/56BCC7865ec000/ntkrnlpa.exe not foundSYMSRV: d:\mysymbol\ntkrnlmp.exe\56BCC7865ec000\ntkrnlmp.exe not foundSYMSRV: http://msdl.microsoft.com/download/symbols/ntkrnlmp.exe/56BCC7865ec000/ntkrnlmp.exe not foundSYMSRV: d:\mysymbol\ntkrpamp.exe\56BCC7865ec000\ntkrpamp.exe not foundSYMSRV: http://msdl.microsoft.com/download/symbols/ntkrpamp.exe/56BCC7865ec000/ntkrpamp.exe not foundDBGHELP: C:\Program Files (x86)\Debugging Tools for Windows (x86)\ntoskrnl.exe - file not foundDBGHELP: C:\Program Files (x86)\Debugging Tools for Windows (x86)\ntkrnlup.exe - file not foundDBGHELP: C:\Program Files (x86)\Debugging Tools for Windows (x86)\ntkrnlpa.exe - file not foundDBGHELP: C:\Program Files (x86)\Debugging Tools for Windows (x86)\ntkrnlmp.exe - file not foundDBGHELP: C:\Program Files (x86)\Debugging Tools for Windows (x86)\ntkrpamp.exe - file not foundSYMSRV: D:\mysymbol\ntoskrnl.exe\56BCC7865ec000\ntoskrnl.exe not foundSYMSRV: http://msdl.microsoft.com/download/symbols/ntoskrnl.exe/56BCC7865ec000/ntoskrnl.exe not foundSYMSRV: D:\mysymbol\ntkrnlup.exe\56BCC7865ec000\ntkrnlup.exe not foundSYMSRV: http://msdl.microsoft.com/download/symbols/ntkrnlup.exe/56BCC7865ec000/ntkrnlup.exe not foundSYMSRV: D:\mysymbol\ntkrnlpa.exe\56BCC7865ec000\ntkrnlpa.exe not foundSYMSRV: http://msdl.microsoft.com/download/symbols/ntkrnlpa.exe/56BCC7865ec000/ntkrnlpa.exe not foundSYMSRV: D:\mysymbol\ntkrnlmp.exe\56BCC7865ec000\ntkrnlmp.exe not foundSYMSRV: http://msdl.microsoft.com/download/symbols/ntkrnlmp.exe/56BCC7865ec000/ntkrnlmp.exe not foundSYMSRV: D:\mysymbol\ntkrpamp.exe\56BCC7865ec000\ntkrpamp.exe not foundSYMSRV: http://msdl.microsoft.com/download/symbols/ntkrpamp.exe/56BCC7865ec000/ntkrpamp.exe not foundDBGENG: ntoskrnl.exe - Image mapping disallowed by non-local path.Unable to load image ntoskrnl.exe, Win32 error 0n2DBGENG: ntoskrnl.exe - Partial symbol image load missing image infoDBGHELP: No header for ntoskrnl.exe. Searching for dbg fileDBGHELP: .\ntoskrnl.dbg - file not foundDBGHELP: .\exe\ntoskrnl.dbg - path not foundDBGHELP: .\symbols\exe\ntoskrnl.dbg - path not foundDBGHELP: ntoskrnl.exe missing debug info. Searching for pdb anywayDBGHELP: Can't use symbol server for ntoskrnl.pdb - no header information availableDBGHELP: ntoskrnl.pdb - file not found*** WARNING: Unable to verify timestamp for ntoskrnl.exe*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exeDBGHELP: nt - no symbols loaded
但是提取对方电脑上的ntoskrnl.exe用IDA分析,发现可以正确加载到符号表,于是我将提取到的ntoskrnl.exe放到windbg要找到的路径上去例如:
SYMSRV: d:\mysymbol\ntoskrnl.exe\56BCC7865ec000\ntoskrnl.exe not found
结果这次终于正常加载上了
3: kd> .reload /f ntDBGHELP: d:\mysymbol\ntoskrnl.exe\56BCC7865ec000\ntoskrnl.exe - OKDBGENG: d:\mysymbol\ntoskrnl.exe\56BCC7865ec000\ntoskrnl.exe - Mapped image memoryDBGHELP: nt - public symbols d:\mysymbol\ntkrnlmp.pdb\D7EA2B6682984A0E8697620F5571B7BF2\ntkrnlmp.pdb
阅读全文
0 0
- Unable to load image ntoskrnl.exe的问题
- 修改ntoskrnl.exe的方法
- struts2-Unable to load configuration配置遇到的问题
- hibernate启动遇到的问题(Unable to load bean)
- Unable to load DLL 'SQLite.Interop.dll' 问题的解决方案
- unable to load project ......dproj问题
- 解决unable to load native-library问题
- hadoop 无法load Native库的问题( Unable to load native-hadoop library )
- ntoskrnl.exe损坏或丢失的解决方案
- Unable to load dll的解决方法
- Unable to load dll的解决方法
- Unable to load dll的解决方法
- Unable to load configuration的解决方法
- unable to load dll 的解决方法
- win7 win8 系统ntoskrnl.exe丢失引起蓝屏的问题解决以及ntoskrnl.exe下载位置
- unable to load Intercepter
- Unable to load SELinux
- Unable to load configuration
- LeetCode.143 Reorder List
- Elimination Game问题及解法
- 【实战】2-4Linux上JDK,Tomcat,Maven安装配置(centOS,阿里云)
- python解方程
- html5学习笔记2 html简介
- Unable to load image ntoskrnl.exe的问题
- 类比C++ 学习Python的class
- WEB_01_HTML概述
- Monkeyrunner--自动化测试工具
- macos下java版本动态切换
- Android视频直播的实现
- SSH与SSM学习之hibernate24——关联级别加载策略之属性关联加载策略
- varnish缓存配置详解
- maven新建 webapp项目后JSP文件报错怎样chul