evild3ad / MemProcFS-Analyzer

MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
https://lethal-forensics.com
GNU General Public License v3.0
462 stars 53 forks source link

frozen on - [Info] Processing C:\Users\Admin\Downloads\MemProcFS-Analyzer-v0.9\MemProcFS-Analyzer-v0.9\ch2.dmp [approx. 1-10 min] #23

Closed madeonukraine closed 1 year ago

madeonukraine commented 1 year ago

C:\Users\Admin\Downloads\MemProcFS-Analyzer-v0.9\MemProcFS-Analyzer-v0.9\MemProcFS-Analyzer.ps1? [D] Do not run [R] Run once [S] Suspend [?] Help (default is "D"): i write "R" and after

installed the necessary dependencies that are indicated in your branch, I run the script on behalf of the admin, there is a check for the presence of software, after everything is fine, the program writes that the process will take from 1 to 10 minutes but does not even load the PC, waited 15 hours with a training 500mb RAM dump, as well as my own, tried it on different PCs and clean virtual machines, writes that the disk mount but it is not even in the hard disk manager, tell me what am I doing wrong?

evild3ad commented 1 year ago

Hi, please run MemProcFS directly against your memory snapshot and check for any error message. 500 MB sounds old or bogus.

https://github.com/ufrisk/MemProcFS

On Wed 14. Jun 2023 at 16:26, madeonukraine @.***> wrote:

C:\Users\Admin\Downloads\MemProcFS-Analyzer-v0.9\MemProcFS-Analyzer-v0.9\MemProcFS-Analyzer.ps1? [D] Do not run [R] Run once [S] Suspend [?] Help (default is "D"): i write "R" and after

installed the necessary dependencies that are indicated in your branch, I run the script on behalf of the admin, there is a check for the presence of software, after everything is fine, the program writes that the process will take from 1 to 10 minutes but does not even load the PC, waited 15 hours with a training 500mb RAM dump, as well as my own, tried it on different PCs and clean virtual machines, writes that the disk mount but it is not even in the hard disk manager, tell me what am I doing wrong?

— Reply to this email directly, view it on GitHub https://github.com/evild3ad/MemProcFS-Analyzer/issues/23, or unsubscribe https://github.com/notifications/unsubscribe-auth/AB54DQ3IJZ5LH7TYGT5JDL3XLHCX7ANCNFSM6AAAAAAZGOR2GU . You are receiving this because you are subscribed to this thread.Message ID: @.***>