Home Search
 You are here: arrow Home Search

Search Our Site

Select the content to include in your search:

Total: 12 results found.
Search Keyword current. Search for it with
Results 1 - 12 of 12
... expression evaluator Show current evaluator Show available evaluators Set c++ as the default expression evaluator Set masm as the default expression ...
2. Contact & Imprint
... part of the web site from which reference was made to this page. If any parts or individual wordings in this text do not comply with the current legal position or no longer comply with the same or ...
3. !mlocks hung interpretation help needed
(Forum/Crash Dump Analysis )
...  116 CurrentReaderThreadIds: WaitingReaderCount: 576 ReaderEvent: 80400002 WaitingReaderThreadIds: *This lock has 116 orphaned reader locks. 0:007> !rwlock Address  ...
4. Help with crash dump
(Forum/Crash Dump Analysis )
... address which referenced memory Debugging Details: ------------------ OVERLAPPED_MODULE: tmcomm READ_ADDRESS: 00000140 CURRENT_IRQL: 2 FAULTING_IP: nt!PsReturnProcessNonPagedPoolQuota+19 804eb5b9 ...
5. Minidump error
(Forum/Crash Dump Analysis )
...  0x50 PROCESS_NAME: System CURRENT_IRQL: 1 TRAP_FRAME: eeb9dc30 -- (.trap 0xffffffffeeb9dc30) ErrCode = 00000000 eax=00000000 ebx=00000000 ecx=000007a4 edx=eeb9dd88 esi=ffffffe8 edi=00000000 eip=e086c6a1 ...
... 7c90d3aa 7c80174d 00000788 00000000 ntdll!KiFastSystemCallRet 0007fbf8 7c9100b8 00090330 0007fcd0 7c910041 ntdll!ZwFsControlFile+0xc 1: kd> !irp 88666008 Irp is active with 10 stacks 10 is current ...
7. Re: drwtsn32
(Forum/General Questions)
... and will also be transmitted to Microsoft over the Internet. However, if you have manually set the \\HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AeDebug\Auto value to zero, the Don't ...
8. Re: Memory Access errors in the Kernel
(Forum/Kernel-Mode Debugging)
... one. Typically, when you are doing kernel debugging, the only visible user-mode address space is the one that is associated with the current process. The .process command instructs the kernel debugger ...
9. Re: Remote debugging of CrashMe with ntsd -d
(Forum/Article Discussions)
... just that. Just follow the steps described here: How To Create a User-Defined Service. Once you set everything up you should see something like this in the registry of your target machine: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DbgService].. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DbgService\Parameters] "Application"="C:\\dbgsrv\\dbgsrv.exe ...
10. Re: See in Memory Descriptor List whats on
(Forum/Kernel-Mode Debugging)
... information about currently verified drivers" -> Next (3x). Now you will see the pool usage of each driver: [USER POSTED IMAGE] [u]In WinDbg After enabling driver verifier you can get even ...
11. Re: sort lm n t by date/time
(Forum/Crash Dump Analysis )
Welcome Carl. You might try the !dll -l command. It lists all currently loaded dlls sorted by their load order, though enough memory information must be present in the dump for the command to work (.dump ...
12. Windbg for memory analysis using mimikatz ERROR
(Forum/Crash Dump Analysis )
I'm using windbg version 6.12 and using mimilib.dll for debugging memory. All works fine until I get following output on UI 0:000> !mimikatz DPAPI Backup keys ================= Current prefered ...

  up top of page up  

Copyright © 2022 All Rights Reserved.
Page generated in 0.0010 seconds.