New
#1
Solution for reading Win7 dumps in Win10(WinDBG)
Guys and gals, i'm here honored to present to you the solution for reading dumps made by Windows 7 on Windows 10 with the latest SDK. After hours and hours of re-search with no success i decided to experiment myself. I got this crazy idea when i was transferring files from my other computer to this computer. The idea was basically, what happens if you transfer the Windows 7 symbols to Windows 10? I decided to try it out, to my surprise it worked and i was able to analyze Windows 7 dumps without any symbol issues at all.
Here is a little tutorial on how to do it.
1. Download my Windows 7 symbol package from here: http://1drv.ms/1VsdqyK
2. Right-click the symcache.zip folder and download it(obviously)
3. When you have downloaded it and opened it you will see that there's a folder inside called "symcache", extract it to your desired place.
4. Go into WinDBG and go to File -> Symbol File Path
5. Click Browse and navigate to where your symbol folder is(in my case it's symcache located in root)
6. Click OK and go to File -> Save Workspace and you are done.
Another way to do is to download and install the symbols from here: Symbols for Service Pack 1(x64) machines, for Service Pack 1(x86),for RTM(x86) and for RTM(x86).
Now you should be able to read Windows 7 dumps without any problems. Please do note that you can't read Windows 10 dumps using this method. If you do want to read Windows 10 dumps you'll need the Windows 10 symbols. Hope this helped you out, this has been driving me nuts since July, i'm sure many of you aswell are tired of seeing this every single time when analyzing a Windows 7 dump.
We can just hope that MS fixes this problem, which they won't do in some time. Anyways that's it.
//Laith
Last edited by derekimo; 01 Oct 2015 at 19:58. Reason: Replaced direct download links. Link to the source instead.