Skip to content

Instantly share code, notes, and snippets.

@morimolymoly
Last active November 19, 2021 05:10
Show Gist options
  • Select an option

  • Save morimolymoly/ecd723e7e2661f3ad8a43db750de23b5 to your computer and use it in GitHub Desktop.

Select an option

Save morimolymoly/ecd723e7e2661f3ad8a43db750de23b5 to your computer and use it in GitHub Desktop.
Please provide the full image name, including the extension (i.e. kernel32.dll)
for more reliable results.Base address and size overrides can be given as
.reload <image.ext>=<base>,<size>.
*** WARNING: Unable to verify timestamp for ModuleName
*** ERROR: Module load completed but symbols could not be loaded for ModuleName
Unable to add module at 00000000`00000000
0: kd> !sym noisy
noisy mode - symbol prompts on
0: kd> .reload nt
SYMSRV: BYINDEX: 0xD
c:\Program Files (x86)\Windows Kits\10\Debuggers\x64\sym
ntkrnlmp.pdb
1F9BB45B28B806E4D18925C06E924B8C1
SYMSRV: PATH: c:\Program Files (x86)\Windows Kits\10\Debuggers\x64\sym\ntkrnlmp.pdb\1F9BB45B28B806E4D18925C06E924B8C1\ntkrnlmp.pdb
SYMSRV: RESULT: 0x00000000
DBGHELP: nt - public symbols
c:\Program Files (x86)\Windows Kits\10\Debuggers\x64\sym\ntkrnlmp.pdb\1F9BB45B28B806E4D18925C06E924B8C1\ntkrnlmp.pdb
0: kd> vertarget
Windows 10 Kernel Version 19041 MP (5 procs) Free x64
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Machine Name:
Kernel base = 0xfffff803`53000000 PsLoadedModuleList = 0xfffff803`53c2a2d0
Debug session time: Fri Nov 19 09:10:00.400 2021 (UTC + 9:00)
System Uptime: 0 days 0:00:09.815
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment