Not login
0

[244]  wntdll 符号问题

asked 2021-04-28 14:15:08 +0800

liuxiaoliang gravatar image

加载符号发现对应的 ntdll.dll--->加载的是 wntdll.pdb 符号,然后使用windbg !address 或者!peb相关命令就提示下面这种错误 1.为什么ntdll会加载wntdll.pdb不加载ntdll.pdb 2.已经翻墙挂着代理 3.符号文件夹路径也都是英文的。 4.网上说把符号路径换到c:\symbols即可,但是我不想换这个地方,想知道原因。

0:092> !address No symbols for ntdll. Cannot continue.

0:092> !peb PEB at 00cf5000 error 3 InitTypeRead( nt!_PEB at 00cf5000)...

edit retag flag offensive close merge delete

2 Answers

Sort by » oldest newest most voted
0

answered 2021-05-03 11:09:57 +0800

liuxiaoliang gravatar image

加载都没有问题,我使用!sym noisy,符号都没有问题正常加载,加载完后我.reload还是不能是用!address相关指令。

edit flag offensive delete link more
0

answered 2021-04-28 22:19:14 +0800

gdman gravatar image

你调试的应该是wow的情况,也就是64位内核上的32位程序,这时进程里有两个ntdll,微软便把32位的取名为wntdll
!sym noisy打开符号的调试模式 然后再.reload,看看到底哪里加载失败

edit flag offensive delete link more
Login/Signup to Answer

Question Tools

1 follower

Stats

Asked: 2021-04-28 14:15:08 +0800

Seen: 11 times

Last updated: May 03 '21

关闭