-
Notifications
You must be signed in to change notification settings - Fork 91
Unable to process SYSTEM hive for Windows 10 18003 Build 17134.1 #20
Comments
I'm experiencing the a similar error: [+] Reading registry hive: SYSTEM... A commercial tool has read the ShimCache so I know there are entries. |
Update to the latest version. 0x34 is the magic value for Windows 10 after the Creators update. |
@mbevilacqua It looks like you're trying to parse a hive file as a registry file. Try using |
definitely parsing a hive as I have no reg export but I retried just in case and it works. Not sure if there was an update in between or I thumbed it while testing but thanks! |
@mbevilacqua yw. 0x66676572 are the first four bytes of a hive file (ascii 'regf' in little endian). That's why I think it isn't a registry file. The files from C:\Windows\System32\config* are hive files. @adavism this can probably be closed. |
[+] Reading binary file: /SYSTEM...
[-] Got an unrecognized magic value of 0x66676572... bailing
[-] No Shim Cache entries found...
The text was updated successfully, but these errors were encountered: