-
Notifications
You must be signed in to change notification settings - Fork 167
Crash on dumping parameters #38
Copy link
Copy link
Closed
Labels
bugSomething isn't workingSomething isn't working
Description
Test case
Issue
When dumping of the parameters is selected, produced trace is incomplete.
Using the default params.txt:
kernel32;LoadLibraryW;1
kernel32;LoadLibraryA;1
kernel32;GetProcAddress;2
advapi32;RegQueryValueW;3
kernel32;CreateFileW;6
The end of the tracelog:
17710;msvcrt.__iob_func
17610;msvcrt.fflush
15492;kernel32.GetCurrentProcess
d479;kernel32.LoadLibraryA
When LoadLibraryA was removed from params.txt, the tracelog continues. Example:
175f0;msvcrt.fwrite
17710;msvcrt.__iob_func
17610;msvcrt.fflush
15492;kernel32.GetCurrentProcess
d479;kernel32.LoadLibraryA
d480;kernel32.GetProcAddress
13ad8;called: ?? [15440000+5c]
> 15440000+6e;SYSCALL:0x50(NtProtectVirtualMemory)
> 15440000+70;nim.[unnamedImageEntryPoint+125ee]*
13b09;called: ?? [15440000+2e]
[...]
Possible crash on dumping parameters of LoadLibraryA.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't working