therealdreg / dbgchild Goto Github PK
View Code? Open in Web Editor NEWDebug Child Process Tool (auto attach)
Home Page: https://rootkit.es/
License: Other
Debug Child Process Tool (auto attach)
Home Page: https://rootkit.es/
License: Other
Failed to open the debugger debug child process
Don't know how to use it
can provide video?
I don’t understand how to install it. it is written that you have to extract the contents of the archive in the x64dbg folder, but the contents are totally different from what is described in the readme:
It may be:
CreateProcessPatch.exe - Hook ZwCreateUserProcess (two separate exe files for x86 and x64) and loads DbgChildHookDLL.dll
DbgChildHookDLL.dll - (two separate dll files for x86 and x64) - outputs process id's to CPIDS folder
NTDLLEntryPatch.exe - Patches or unpatches LdrInitializeThunk (two separate exe files for x86 and x64)
DbgChild.dp32 - x64dbg plugin x86
DbgChild.dp64 - x64dbg plugin x64
NewProcessWatcher.exe - Watches for new child processes from the CPIDS folder
x64_post.unicode.txt - Support file
x64_pre.unicode.txt - Support file
x86_post.unicode.txt - Support file
x86_pre.unicode.txt - Support file
how can I install it as plugin for x64dbg?
Thanks for any reply.
The parent process is x86, and the child process is x64. When enabled dbgchild plugin in x32dbg and spawn the child, the parent will simply crash and the debugging of both parent and child processes failed
version: Windows11 22H2 22621.1928
When opening processwatcher.exe I get a continous loop of this errors
TID[1500] - ERROR: ReadDirectoryChangesW.
TID[1500] - Watching: Z:\x64dbg\x64\CPIDS
TID[3892] - ERROR: ReadDirectoryChangesW.
TID[3892] - Watching: Z:\x64dbg\x32\CPIDS
TID[1500] - ERROR: ReadDirectoryChangesW.
TID[1500] - Watching: Z:\x64dbg\x64\CPIDS
TID[3892] - ERROR: ReadDirectoryChangesW.
TID[3892] - Watching: Z:\x64dbg\x32\CPIDS
TID[1500] - ERROR: ReadDirectoryChangesW.
TID[1500] - Watching: Z:\x64dbg\x64\CPIDS
TID[3892] - ERROR: ReadDirectoryChangesW.
TID[3892] - Watching: Z:\x64dbg\x32\CPIDS
TID[1500] - ERROR: ReadDirectoryChangesW.
TID[1500] - Watching: Z:\x64dbg\x64\CPIDS
TID[3892] - ERROR: ReadDirectoryChangesW.
TID[3892] - Watching: Z:\x64dbg\x32\CPIDS
TID[1500] - ERROR: ReadDirectoryChangesW.
TID[1500] - Watching: Z:\x64dbg\x64\CPIDS
TID[3892] - ERROR: ReadDirectoryChangesW.
TID[3892] - Watching: Z:\x64dbg\x32\CPIDS
I am using Windows 7 SP1 x86 right out of the box on a VirtualBox VM.
I only download x64dbg and copied the plugin inside the folder.
No logs are created.
I don't know why it shows error in the x64 folder since it is an x86 platform. I even deleted the x64 folder and it is still showing in the error.
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.