- Livekd Could Not Resolve Symbols For Ntoskrnl.exe 2
- Livekd Could Not Resolve Symbols For Ntoskrnl.exe X
Analysis Date | 2013-11-23 18:43:31 |
---|---|
MD5 | d031e1ada8f76c447fab00c0e12ad35c |
SHA1 | f0038c59cb07862bd2228677d0b192f99c61091e |
Static Details:
File type | PE32 executable for MS Windows (console) Intel 80386 32-bit | |
---|---|---|
Section | .text md5: e4862f10194a5d9b860d9b43192d4ca5 sha1: 7767a574291d7774019522f3111bb934014cf782 size: 138240 | |
Section | .rdata md5: 329836d3ec5311d3a0bad4f72635ddd7 sha1: 1bac5968c8cf1a9c31db6c7c0df36c008f82ce26 size: 33280 | |
Section | .data md5: 10f3565f5bf969e9e32d9ae57f45485e sha1: 4a31776b21374bdd708ed30709519a9bec1892fa size: 6656 | |
Section | .rsrc md5: 4f7b1dee92a1b71dca7e11e795c8d20a sha1: 25739d96ff02a0fc02f2319524e0e81e0ee5fa5c size: 423424 | |
Timestamp | 2012-10-14 19:55:20 | |
Pdb path | c:srclivekdExeReleaselivekd.pdb | |
Version | LegalCopyright: Copyright © 2000-2012 Mark Russinovich and Ken Johnson InternalName: livekd FileVersion: 5.3 CompanyName: Sysinternals - www.sysinternals.com ProductName: Sysinternals LiveKd ProductVersion: 5.3 FileDescription: livekd OriginalFilename: livekd.exe | |
PEhash | 68c336935bf05f5c1193f2cd561e833c26b64ecc | |
AV | avg | Win32/Sality |
AV | avira | W32/Sality.AT |
AV | mcafee | W32/Sality.gen.z |
AV | msse | Virus:Win32/Sality.AT |
Runtime Details:
Screenshot |
---|
Process
↳ C:malware.exe
Registry | HKEY_CURRENT_USERSoftwareAasppapmmxkvsA1_0 ➝ 2768543866 |
---|---|
Registry | HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionpoliciessystemEnableLUA ➝ NULL |
Registry | HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterSvcAntiVirusOverride ➝ 1 |
Registry | HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionExplorerAdvancedHidden ➝ 2 |
Registry | HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileEnableFirewall ➝ NULL |
Registry | HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsListC:malware.exe ➝ C:malware.exe:*:Enabled:ipsec |
Registry | HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterAntiVirusOverride ➝ 1 |
Registry | HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet SettingsGlobalUserOffline ➝ NULL |
Registry | HKEY_CURRENT_USERSoftwareAasppapmmxkvs-9936270071768776769 ➝ 178 |
Creates File | C:TEMPFILESmonitor.exe |
Creates File | C:Documents and SettingsAdministratorLocal SettingsTemphxevpi.exe |
Creates File | C:WINDOWSSYSTEM.INI |
Creates File | PIPESfcApi |
Creates File | C:Program FilesAdobeAcrobat 7.0ReaderAcroRd32.exe |
Creates File | C:TEMPFILESAcroRd32.exe |
Creates File | PIPElsarpc |
Creates File | C:TEMPmonitor.exe |
Creates File | DeviceAfdEndpoint |
Creates File | C:TEMPFILEShxevpi.exe |
Deletes File | C:Documents and SettingsAdministratorLocal SettingsTemphxevpi.exe |
Creates Mutex | uxJLpe1m |
Creates Mutex | services.exeM_616_ |
Creates Mutex | reader_sl.exeM_976_ |
Creates Mutex | alg.exeM_1844_ |
Creates Mutex | svchost.exeM_848_ |
Creates Mutex | svchost.exeM_800_ |
Creates Mutex | lsass.exeM_628_ |
Creates Mutex | svchost.exeM_1172_ |
Creates Mutex | malware.exeM_1508_ |
Creates Mutex | spoolsv.exeM_1292_ |
Creates Mutex | svchost.exeM_1016_ |
Creates Mutex | monitor.exeM_1184_ |
Creates Mutex | csrss.exeM_548_ |
Creates Mutex | userinit.exeM_256_ |
Creates Mutex | smss.exeM_500_ |
Creates Mutex | winlogon.exeM_572_ |
Creates Mutex | explorer.exeM_340_ |
Creates Mutex | svchost.exeM_1108_ |
Creates Mutex | svchost.exeM_1204_ |
The ntoskrnl.exe (GDR branch) from Windows6.1-KB2882822-x64 update does not have public symbols. Where I can report this? Symchk /v /if ntoskrnl.exe /s SRV.E: SymbolsStore.
Process
↳ C:WINDOWSExplorer.EXE
Creates Mutex | explorer.exeM_340_ |
---|---|
Creates Mutex | uxJLpe1m |
Process
↳ C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe
- If your symbol path is wrong, fix it. If you are using the kernel debugger make sure your local%WINDIR% is not on your symbol path. Then reload symbols using the.reload (Reload Module) command: 0:000.reload ModuleName If your symbol path is correct, you should activate noisy mode so you can see which symbol files dbghelp is loading.
- Oct 24, 2005 Re: LiveKD reports 'Could not resolve symbols for ntoskrnl.exe' by Uday K Verma » Fri, 28 Oct 2005 03:54:21 GMT Well, seems like my symbols for ntoskrnl.exe somehow got corrupted or went invalid.
Creates Mutex | uxJLpe1m |
---|---|
Creates Mutex | reader_sl.exeM_976_ |
Network Details:
Raw Pcap