ntdll module not loading correctly in windbg, but why?

前端 未结 2 923
情深已故
情深已故 2020-12-10 07:44

I\'ve used windbg for user mode debugging before, but I suspect I did something to my system because I don\'t recall having a problem using for example the extension command

2条回答
  •  夕颜
    夕颜 (楼主)
    2020-12-10 08:10

    It seems that with the Windows Updates distributed on 20151013 , the heap information is available again.

    0:018> !chksym ntdll
    
    C:\Windows\SysWOW64\ntdll.dll
    Timestamp: 56099FFA
    SizeOfImage: 180000
          pdb: wntdll.pdb
      pdb sig: C2B37FDB-B631-4EA7-8A6D-7F51123F151E
          age: 2
    
    Loaded pdb is microsoft\wntdll.pdb   \C2B37FDBB6314EA78A6D7F51123F151E2\wntdll.pdb
    
    wntdll.pdb
      pdb sig: C2B37FDB-B631-4EA7-8A6D-7F51123F151E
          age: 2
    
    MATCH: wntdll.pdb and C:\Windows\SysWOW64\ntdll.dll
    

    and

    0:018> lm v m *ntdll*
    start    end        module name
    77530000 776b0000   ntdll      (pdb symbols)        microsoft\wntdll.pdb\C2B37FDBB6314EA78A6D7F51123F151E2\wntdll.pdb
    Loaded symbol image file: C:\Windows\SysWOW64\ntdll.dll
    Image path: C:\Windows\SysWOW64\ntdll.dll
    Image name: ntdll.dll
    Timestamp:        Mon Sep 28 22:15:54 2015 (56099FFA)
    CheckSum:         001412F8
    ImageSize:        00180000
    File version:     6.1.7601.23223
    Product version:  6.1.7601.23223
    File flags:       0 (Mask 3F)
    File OS:          40004 NT Win32
    File type:        2.0 Dll
    File date:        00000000.00000000
    Translations:     0409.04b0
    CompanyName:      Microsoft Corporation
    ProductName:      Microsoft® Windows® Operating System
    InternalName:     ntdll.dll
    OriginalFilename: ntdll.dll
    ProductVersion:   6.1.7601.23223
    FileVersion:      6.1.7601.23223 (win7sp1_ldr.150928-0600)
    FileDescription:  NT Layer DLL
    LegalCopyright:   © Microsoft Corporation. All rights reserved.
    

    Can you install the updates, rebuild your application and try again?

提交回复
热议问题