The free OSR Learning Library has more than 50 articles on a wide variety of topics about writing and debugging device drivers and Minifilters. From introductory level to advanced. All the articles have been recently reviewed and updated, and are written using the clear and definitive style you've come to expect from OSR over the years.
Check out The OSR Learning Library at: https://www.osr.com/osr-learning-library/
I received a dump file that is dumped from the system with the latest update.
The dump file reports:
FAILURE_EXCEPTION_CODE: 5E2FC6A7 EXCEPTION_STR: WRONG_SYMBOLS IMAGE_NAME: ntoskrnl.wrong.symbols.exe MODULE_NAME: nt_wrong_symbols SYMBOL_NAME: nt_wrong_symbols!5E2FC6A777D000
Here is my symbol file path
3: kd> vertarget Windows 8.1 Kernel Version 9600 MP (16 procs) Free x64 Product: Server, suite: TerminalServer SingleUserTS Built by: 9600.19629.amd64fre.winblue_ltsb_escrow.200127-1700 Machine Name: Kernel base = 0xfffff802`6c688000 PsLoadedModuleList = 0xfffff802`6c94d5f0 Debug session time: Wed Apr 29 20:09:43.380 2020 (UTC + 8:00) System Uptime: 2 days 14:48:43.591
3: kd> lmvm nt Browse full module list start end module name fffff802`6c688000 fffff802`6ce05000 nt (export symbols) ntkrnlmp.exe Loaded symbol image file: ntkrnlmp.exe Image path: ntkrnlmp.exe Image name: ntkrnlmp.exe Browse all global symbols functions data Timestamp: Tue Jan 28 13:29:11 2020 (5E2FC6A7) CheckSum: 0070705C ImageSize: 0077D000 Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
I could not find the symbol of ntkrnlmp.exe with that timestamp from my symbol file path.
Could anyone let me know how to get the symbol file for the dump?
|Upcoming OSR Seminars|
|OSR has suspended in-person seminars due to the Covid-19 outbreak. But, don't miss your training! Attend via the internet instead!|
|Kernel Debugging||13-17 May 2024||Live, Online|
|Developing Minifilters||1-5 Apr 2024||Live, Online|
|Internals & Software Drivers||11-15 Mar 2024||Live, Online|
|Writing WDF Drivers||26 Feb - 1 Mar 2024||Live, Online|