Skip to content

drltrace can't output the trace of child process #15

@whuang328

Description

@whuang328

Thanks for all the contribution and information in drltrace. I have just started the research of binary analysis in Windows. And I am trying to apply drltrace on my research to trace the library calls of Adobe Acrobat DC reader. However, I suffered from an issue that I can't get the Adobe related dll such as 'JP2KLib.dll' by applying -only_to_lib flag on drltrace.

My command is ".\drltrace.exe -logdir D:\Winfuzz_test\drltrace_win_x32\log -only_to_lib "JP2KLib.dll" -- "C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" D:\Winfuzz_test\test\1.pdf"

And the environment is Windows 7 with visual studio 2013.

After I tried it on Acrobat Reader 9.0, I can successfully get the 'JP2LLib.dll' in the trace. Maksim told me that maybe the reason is that Acrobat Reader DC will call 'JP2Klib.dll' in its child process, but drltrace can't get the log of the child process now. Can you help me to examine this issue? Thanks for all the help and information.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions