Thanks for the reply!
can you try a psscan, and see what that give you as output.On Wed, Aug 22, 2012 at 7:58 AM, Jon Nelson <dotcop@gmail.com> wrote:
_______________________________________________I am using the 2.1 Windows standalone exe.I have a dd image of memory from the subject operating system and when I try to use pslist with the Win2008SP1x86 profile I get the following errors:Traceback (most recent call last):File "<string>", line 185, in <module>File "<string>", line 176, in mainFile "C:\volatility\build\pyi.win32\pyinstaller\vol.pkz\volatility.commands", line 111, in executeFile "C:\volatility\volatility\plugins\taskmods.py", line 138, in render_textFile "C:\volatility\build\pyi.win32\pyinstaller\vol.pkz\volatility.win32.tasks", line 72, in pslistFile "C:\volatility\volatility\plugins\overlays\windows\kdbg_vtypes.py", line 40, in processesAttributeError: Could not list tasks, please verify your --profile with kdbgscan
When I try to verify my profile with kdbgscan I get the following for all profiles:**************************************************Instantiating KDBG using: Kernel AS Win2008SP1x86 (6.0.6001 32bit)Offset (V) : 0x8193ec90Offset (P) : 0x193ec90KDBG owner tag check : TrueProfile suggestion (KDBGHeader): Win2008SP1x86Version64 : 0x8193ec68 (Major: 15, Minor: 6001)Service Pack (CmNtCSDVersion) : 1Build string (NtBuildLab) : 6001.18000.x86fre.longhorn_rtm.0PsActiveProcessHead : 0x81954990 (0 processes)PsLoadedModuleList : 0x8195ec70 (0 modules)KernelBase : 0x81847000 (Matches MZ: True)Major (OptionalHeader) : 6Minor (OptionalHeader) : 0KPCR : 0x8193f800 (CPU 0)KPCR : 0x803d1000 (CPU 1)Any help would be greatly appreciated.Jon
Vol-users mailing list
Vol-users@volatilityfoundation.org
http://lists.volatilityfoundation.org/mailman/listinfo/vol-users