-
Notifications
You must be signed in to change notification settings - Fork 1.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Windows 8.1 x86 AttributeError: Struct __MMVAD has no member Start #268
Comments
Thanks for reporting...definitely not a user error kind of thing. Let me look into it and I'll post back. |
Alright, can you try reverting the changes made to lines 445 and 449 in 7ff07bd (not the whole patch, just those lines). In other words, go back to using just StartingVpn and EndingVpn, not the combination of StartingVpnHigh and EndingVpnHigh. It appears those "High" members were added at some point and we apparently haven't figured out exactly when. Also, if you happen to have access to the ntoskrnl.exe file on disk for that sample, can you lookup the build number? It should be 6.3.9600.X and if X is greater than 17031 then you have Update 1 installed. Let me know the value of X for your system if possible - that will help narrow down exactly when this change occurred. |
After reverting those changes, malfind produced results that looked good! vadinfo also gives results that seem reasonable. ntoskrnl.exe has version 6.3.9600.17415. |
Hi there, I want to confirm: the problem still persists, the patch proposed by iMHLv2 works for me. My ntoskrnl.exe has version 6.3.9600.17415 as well. Please consider reverting 7ff07bd or shifting it to another profile. |
This should all be good now...the StartingVpnHigh and EndingVpnHigh members were introduced starting in Windows 8 but only for 64-bit versions of the OS. 32-bit versions of Win8 and Win10 do not have StartingVpnHigh and EndingVpnHigh. Thanks! |
I'm trying to use some of the scanning plugins against a Windows 8.1 x86 memory image; however, the source distribution of 2.5 and git master at 9ad8329 raise the following error:
The pslist plugin shows the processes I'd expect to see in the image.
Here is the imageinfo:
I've tried the other suggested profiles, but none of them give any better results (though, Win8SP0x86 doesn't raise an exception, but also doesn't print any results).
Is this a user error, or is this a bug in Volatility?
The text was updated successfully, but these errors were encountered: