Laith
Otaku Pride
Guys and gals, i'm here honored to present to you the solution for reading dumps made by Windows 7 on Windows 10 with the latest SDK. After hours and hours of re-search with no success i decided to experiment myself. I got this crazy idea when i was transferring files from my other computer to this computer. The idea was basically, what happens if you transfer the Windows 7 symbols to Windows 10? I decided to try it out, to my surprise it worked and i was able to analyze Windows 7 dumps without any symbol issues at all.
Here is a little tutorial on how to do it.
1. Download my Windows 7 symbol package from here: http://1drv.ms/1VsdqyK
2. Right-click the symcache.zip folder and download it(obviously)
3. When you have downloaded it and opened it you will see that there's a folder inside called "symcache", extract it to your desired place.
4. Go into WinDBG and go to File -> Symbol File Path
5. Click Browse and navigate to where your symbol folder is(in my case it's symcache located in root)
6. Click OK and go to File -> Save Workspace and you are done.
Another way to do is to download and install the symbols from here: Symbols for Service Pack 1(x64) machines, for Service Pack 1(x86),for RTM(x86) and for RTM(x86).
Now you should be able to read Windows 7 dumps without any problems. Please do note that you can't read Windows 10 dumps using this method. If you do want to read Windows 10 dumps you'll need the Windows 10 symbols. Hope this helped you out, this has been driving me nuts since July, i'm sure many of you aswell are tired of seeing this every single time when analyzing a Windows 7 dump.
We can just hope that MS fixes this problem, which they won't do in some time. Anyways that's it.
//Laith
Here is a little tutorial on how to do it.
1. Download my Windows 7 symbol package from here: http://1drv.ms/1VsdqyK
2. Right-click the symcache.zip folder and download it(obviously)
3. When you have downloaded it and opened it you will see that there's a folder inside called "symcache", extract it to your desired place.
4. Go into WinDBG and go to File -> Symbol File Path
5. Click Browse and navigate to where your symbol folder is(in my case it's symcache located in root)
6. Click OK and go to File -> Save Workspace and you are done.
Another way to do is to download and install the symbols from here: Symbols for Service Pack 1(x64) machines, for Service Pack 1(x86),for RTM(x86) and for RTM(x86).
Now you should be able to read Windows 7 dumps without any problems. Please do note that you can't read Windows 10 dumps using this method. If you do want to read Windows 10 dumps you'll need the Windows 10 symbols. Hope this helped you out, this has been driving me nuts since July, i'm sure many of you aswell are tired of seeing this every single time when analyzing a Windows 7 dump.
We can just hope that MS fixes this problem, which they won't do in some time. Anyways that's it.
//Laith
Last edited by a moderator:
My Computer
- Computer type
- PC/Desktop
- Computer Manufacturer/Model Number
- me!
- OS
- Windows 10 Pro x64
- CPU
- AMD Ryzen 5 1600 @ [email protected]
- Motherboard
- ASUS B350 PRIME-PLUS
- Memory
- G.Skill Flare X 16GB (2x8GB) DDR4-2400 @ 2666MHz
- Graphics Card(s)
- Sapphire Radeon Vega 56 NITRO+
- Sound Card
- None
- Monitor(s) Displays
- ASUS VG248QZ
- Screen Resolution
- 1920x1080
- Hard Drives
- Samsung 850 EVO 250GB*, 1TB Seagate Constellation ES, 2x Samsung 840 250GB in RAID0*
*Thanks ICIT2LOL for supplying me with all of these drives!
- PSU
- Corsair VS550
- Case
- Corsair Crystal 460X
- Cooling
- AMD Wraith Spire
- Keyboard
- Ducky Shine 6 w/ MX Browns and PBT keycaps
- Mouse
- Xtrfy M1-Ice
- Internet Speed
- 100MBit/s down, 20MBit/s up
- Antivirus
- Bitdefender
- Browser
- Google Chrome