加载了符号的,官网下载的对应系统的符号包,加载符号后显示
Loading Kernel Symbols
...............................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
....
然后我 u NtOpenProcess之类的函数,成功,u KiFastCallEntry,显示一大堆的类似
ERROR: Module load completed but symbols could not be loaded for \SystemRoot\system32\DRIVERS\iusb3hcs.sys
*** ERROR: Symbol file could not be found. Defaulted to export symbols for \SystemRoot\system32\drivers\vsock.sys -
的消息,最后显示一个,Couldn't resolve error at 'KiFastCallEntry'
,然后我调试一个记事本,输入.process /p fffffa8012220a40之后就出现了一个错误信息,
Implicit process is now fffffa80`12220a40
GetContextState failed, 0x80004001
,之后.reload,出现
Loading Kernel Symbols
...............................................................
................................................................
.........................
Loading User Symbols
...Missing image name, possible paged-out or corrupt data.
.*** WARNING: Unable to verify timestamp for Unknown_Module_00000000`00000000
Unable to add module at 00000000`00000000
.....................
Loading unloaded module list
....
,再次u KiFastCallEntry依然失败。
这个就是整个流程了