Closed UltraForensic closed 4 months ago
There must be some deadlock issue. Those can be a bit tricky to find, but it's good that you're able to share the memory dump.
Can you please zip and upload the memory dump, pagefile and swapfile and share the link with me and I'll take a look ASAP.
Send it to me in a DM on Twitter or Discord
@ufrisk Thank you for quick reply! Sent you a DM on Twitter. Please check it out.
The issue should now be resolved in 5.11.2 which was just published.
It was a parsing issue resulting the parser to get stuck in a forever loop in some very specific cases.
Thank you for reporting this issue and sharing the problematic memory dump.
Hello, I ran into an issue that forensics mode (
-forensic 1
) stucks since itsforensic/progress_percent.txt
reaches90
in specific memory image.Confirmed that this issue is still present on latest release version of MemProcFS (5.11.1) for Windows.
Let me know if any additional information is needed for investigation (I can share the memory image causing this issue). Thanks for developing a great tool!
Some notes:
winpmem_mini_x64_rc2.exe physmem.raw