From bc1f4ce4648bba7262fff4af7f57e5483660d8e6 Mon Sep 17 00:00:00 2001 From: "SND\\kernelnet_cp" Date: Thu, 22 Nov 2012 09:19:16 +0000 Subject: [PATCH] [0.2.x] fixed : UM samples git-svn-id: https://pykd.svn.codeplex.com/svn@81320 9b283d60-5439-405e-af05-b73fd8c4d996 --- samples/um/ldr.py | 17 +++++++++++------ 1 file changed, 11 insertions(+), 6 deletions(-) diff --git a/samples/um/ldr.py b/samples/um/ldr.py index ffa4f2b..7985b55 100644 --- a/samples/um/ldr.py +++ b/samples/um/ldr.py @@ -15,15 +15,20 @@ def listModuleFromLdr64(): name = typedVar( "ntdll!_UNICODE_STRING", mod.BaseDllName ) dprintln(loadWChars(name.Buffer, name.Length/2)) - dprintln( "\n32 bit modules:", True) + try: + + peb32 = typedVar( "ntdll32!_PEB", getCurrentProcess() - pageSize() ) - peb32 = typedVar( "ntdll32!_PEB", getCurrentProcess() - pageSize() ) + dprintln( "\n32 bit modules:", True) - moduleLst = typedVarList( peb32.Ldr.deref().InLoadOrderModuleList, "ntdll32!_LDR_DATA_TABLE_ENTRY", "InMemoryOrderLinks" ) + moduleLst = typedVarList( peb32.Ldr.deref().InLoadOrderModuleList, "ntdll32!_LDR_DATA_TABLE_ENTRY", "InMemoryOrderLinks" ) - for mod in moduleLst: - name = typedVar( "ntdll32!_UNICODE_STRING", mod.BaseDllName ) - dprintln(loadWChars(name.Buffer, name.Length/2)) + for mod in moduleLst: + name = typedVar( "ntdll32!_UNICODE_STRING", mod.BaseDllName ) + dprintln(loadWChars(name.Buffer, name.Length/2)) + + except BaseException: + pass def listModuleFromLdr():