volatility3 icon indicating copy to clipboard operation
volatility3 copied to clipboard

pdbconv cant create proper profile for win7 kernel(8199e3319bc8404581e451b565d048b81)

Open kaganisildak opened this issue 8 months ago • 12 comments

After installing KB5039289 and KB5039339 into Win7 machine, pdbconv cant create proper profile for it.

    Version: 64-bit Windows 7
    PE GUID: 66483bb65de000
    PDB GUID: 8199e3319bc8404581e451b565d048b81

I tried to debug but I couldn't go into much detail. From what I understand it cannot read TPI. The maximum address and offset are equal to each other and it gets blocked here. https://github.com/volatilityfoundation/volatility3/blob/351db0e5730f1d1017141d57ee937d3f3d1fbc94/volatility3/framework/symbols/windows/pdbconv.py#L277

kaganisildak avatar Jun 22 '24 18:06 kaganisildak