AbstractTableViewEdit columnsAppearanceDialogAppearanceColorsColor#FFFFFFBackground ColorXPropertiesFontGeneral Tables:Disassembly:HexDump:Stack:Registers:HexEdit:&Application Font*Courier New&DefaultsNormalBoldItalicBold + Italic67891011121416182022Log:&Cancel&SaveSelect ColorSettings saved!
TextHeader TextBackgroundSelectionSeparatorsBytesModified BytesRestored BytesRIPEIPBreakpointsHardware BreakpointsBookmarksCommentsAutomatic CommentsMnemonic Brief CommentsLabelsAddressesSelected AddressesConditional Jump Lines (jump)Conditional Jump Lines (no jump)Unconditional Jump LinesTraced lineFunction LinesLoop LinesSideBar:Register LabelsBulletsDisabled BreakpointsUnconditional Jump Lines (jump)Unconditional Jump Lines (no jump)Jump Lines (executing)Code Folding Checkbox ColorModified RegistersRegister NamesArgument Register NamesExtra InformationInstructions:HighlightingCommasPrefixesValuesMnemonicsPush/PopsCallsReturnsConditional JumpsUnconditional JumpsNOPsFARINT3sUnusual InstructionsGeneral RegistersFPU RegistersMMX RegistersXMM RegistersYMM RegistersZMM RegistersMemory SizesMemory SegmentsMemory BracketsMemory Stack BracketsMemory Base RegistersMemory Index RegistersMemory ScalesMemory Operators (+/-/*)Inactive TextRSPESPReturn To CommentSEH Chain CommentUser Stack Frame LineSystem Stack Frame LineWildcardsGraphUnconditional branch lineTrue branch lineFalse branch lineTerminal node shadowOther:Current ThreadWatch (When Watchdog is Triggered)Memory Map BreakpointMemory Map %1Memory Map Section TextSearch Highlight ColorNOT FOUND IN CONFIG!&Default Value&Current SettingAssembleDialog0Keep &Size&Fill with NOP's&XEDParse&Keystone&asmjitOKCancel<font color='orange'><b>Instruction decoding error</b></font>empty instruction<font color='orange'><b>Instruction encoding error: %1</b></font><font color='red'><b>Instruction bigger by %1 %2...</b></font>bytebytes<font color='#00cc00'><b>Instruction smaller by %1 %2...</b></font><font color='#00cc00'><b>Instruction is same size!</b></font><font color='#00cc00'><b>Instruction encoded successfully!</b></font>AttachDialogAttach<a href="http://faq.x64dbg.com">Why is process X not shown?</a>Refresh&Attach&CancelPIDPathCommand Line ArgumentsBreakpointsViewSoftwareAddressNameModule/LabelStateHit countLog textConditionFast resumeCommand on hitCommentHardwareMemoryModuleSoftware breakpointHardware breakpointMemory breakpointDLL breakpointInactiveEnabledDisabled&Edit&RemoveE&nable&Disable&AddEnter the module nameExample: mydll.dllRemove AllReset hit countEnable AllDisable All&CopyBridgeReferencesBrowseDialogDialogPlease input the file path.Path:&Browse...&OK&CancelCPUArgumentWidgetFormUnlocked[Formatting Error]Follow %1 in %2DisassemblerDumpStack&CopyDefault (x64 fastcall)Default (stdcall)Default (stdcall, EBP stack)thiscallDelphi (Borland fastcall)LockedCallsCPUDisassembly&Selected Address&Address: &Constant: &Value: Address: Constant: &Edit&Fill...Fill with &NOPs&Copy&PastePaste (&Ignore Size)&Binary&SelectionSelection (&No Bytes)&Address&RVADisassembly&Restore selectionToggleEditSet Hardware on ExecutionRemove HardwareReplace Slot 0 (Free)Replace Slot 1 (Free)Replace Slot 2 (Free)Replace Slot 3 (Free)BreakpointReplace Slot %1 (0x%2)&Follow in Dump&Follow in DisassemblerOpen Source FileSelectionFunctionDecompileGraphHelp on Symbolic NameHelp on mnemonicShow mnemonic briefHide mnemonic brief&Highlighting modeDisable Branch Destination PreviewEnable Branch Destination PreviewLabel Current AddressLabelDisableBitByteWordTrace recordCommentToggle BookmarkAnalyze moduleAdd functionDelete functionArgumentAdd argumentDelete argumentAnalyze single functionRemove analysis from moduleRemove analysis from selectionTreat selection &head asTreat from &selection asAnalysisAssemblePatches&Yara...Set New Origin HereCreate New Thread HereOriginPreviousNextExpressionFile OffsetStart of PageEnd of PageStart of FunctionEnd of FunctionGo toxrefs...C&ommand&Constant&String references&Intermodular calls&PatternCurrent RegionCurrent ModuleAll Modules&Search for&Selected Address(es)Find &references toCurrent address is not executableSetting software breakpoint here may result in crash. Do you really want to continue?Add label at Error!DbgSetLabelAt failed!Add comment at DbgSetCommentAt failed!DbgSetBookmarkAt failed!Assemble at %1Failed to assemble instruction " %1 " (%2)Not inside a module...Goto File Offset in Enter ConstantFind Pattern...Edit code at %1Fill code at %1Selection not in a module...Failed to assemble instruction "Failed to set trace record.
Argument for the new threadSizeCPUDumpB&inary&Edit&Fill...&CopyPaste (&Ignore Size)Save To a File&Restore selectionFollow in StackFollow in Disassembler&Follow QWORD in Disassembler&Follow DWORD in Disassembler&Follow QWORD in Current Dump&Follow DWORD in Current Dump&Follow QWORD in Dump&Follow DWORD in Dump&Sync with expressionEntrop&y...Set &Label&Modify Value&BreakpointHardware, &Access&Byte&Word&Dword&QwordHardware, &WriteHardware, &ExecuteRemove &HardwareMemory, Access&Singleshoot&Restore on hitMemory, WriteMemory, ExecuteRemove &Memory&Find Pattern...&Yara...Data co&py...Find &References&Go to&ExpressionFile OffsetStart of PageEnd of PagePreviousNext&Hex&Extended ASCII&Codepage...&Text&ASCII&Integer&Float&Address&DisassemblyAdd label at Error!DbgSetLabelAt failed!Modify valueEnter expression to follow in Dump...Not inside a module...Goto File Offset in %1HexASCIIUNICODESigned short (16-bit)&PasteWatch QWORDWatch DWORDAllocate MemorySigned byte (8-bit)Signed long (32-bit)Signed long long (64-bit)Unsigned byte (8-bit)Unsigned short (16-bit)Unsigned long (32-bit)Unsigned long long (64-bit)Hex short (16-bit)Hex long (32-bit)Hex long long (64-bit)&Float (32-bit)&Double (64-bit)&Long double (80-bit)Float (32-bit)Double (64-bit)Long double (80-bit)AddressCommentsNot yet supported!Edit data at %1Fill data at %1Save to fileAll files (*.*)Find Pattern...DumpEntropy (Address: %1, Size: %2)Enter expression to sync with...SizeWarningYou're trying to allocate a zero-sized buffer just now.ErrorThe size of buffer you're trying to allocate exceeds 1GB. Please check your expression to ensure nothing is wrong.Memory allocation failed!CPUInfoBoxAddressRVAFile OffsetJump is takenJump is not taken&Selected Address&Address: &Constant: &Value: &Follow in Dump&CopyCPUMultiDumpDump Watch Change Tab %1 NameTab NameCPUSideBarCannot fold selection.
Breakpoint EnabledBreakpoint DisabledBreakpoint Not SetCPUStackCommentsP&ush DWORD...P&ush QWORD...P&op DWORDP&op QWORDAlign Stack PointerB&inary&Edit&Fill...&Copy&PastePaste (&Ignore Size)Brea&kpointHardware, Access&Byte&Word&Dword&QwordHardware, WriteRemove &HardwareMemory, AccessMemory, Write&Singleshoot&Restore on hitRemove &Memory&Restore selectionModifyFollow R&SPFollow R&BPFollow E&SPFollow E&BPFreeze the stack&Find Pattern...Go to &ExpressionGo to PreviousGo to NextGo to Base of Stack FrameFollow DWORD in DumpFollow QWORD in Dump&Watch DWORD&Watch QWORDPush DWORDPush QWORDGo to Next Stack FrameGo to Previous Stack Frame&Follow in DisassemblerFollow DWORD in &DumpFollow QWORD in &DumpDump %1Follow DWORD in &StackFollow QWORD in &StackUnfreeze the stackEnter expression to follow in Stack...Edit data at %1Fill data at %1Find Pattern...CPUWidgetFormGotoCtrl+GCalculatorDialogCalculator&Follow in DisassemblerXXXXExpression:Octal:Unsigned:Hexadecimal:ASCII:0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000 0001 0010Binary:XXXUnicode:Signed:&CloseFollow in &DumpCallStackViewAddressToFromCommentFollow &AddressFollow &ToFollow &From&CopyCloseDialogClosing Debugger...CodepageSelectionDialogSelect Codepage...&OK&CancelColumnReorderDialogDialogDisplayed<- &Add&Hide ->&Up&Down<< A&dd allAvailable&Ok&CancelErrorThere isn't anything to display yet!CommandHelpViewFormModuleCommandInitialize debugging a file.
Example:
InitDebug "C:\test.exe", commandline, "C:\homeDir"Stop debugging (terminate the target).
Example:
StopDebugResume debugging.
Example:
runConfigurationFile -> OpenFile -> AttachFile -> DetachFile -> ExitView -> CPUView -> LogView -> BreakpointsView -> Memory MapView -> Call StackView -> NotesView -> SEHView -> ScriptView -> Symbol InfoView -> SourceView -> ReferencesView -> ThreadsView -> PatchesView -> CommentsView -> LabelsView -> BookmarksView -> FunctionsView -> SnowmanView -> HandlesView -> GraphDebug -> RunDebug -> Run until selectionDebug -> Run until expressionDebug -> PauseDebug -> RestartDebug -> CloseDebug -> Step intoDebug -> Step into (source)Debug -> Step overDebug -> Step over (source)Debug -> Execute till returnDebug -> Run (pass exceptions)Debug -> Run (swallow exception)Debug -> Step into (pass execptions)Debug -> Step into (swallow exception)Debug -> Step over (pass execptions)Debug -> Step over (swallow exception)Debug -> Execute till return (pass exceptions)Debug -> Run to user codeDebug -> Skip next instructionDebug -> CommandDebug -> Trace Into ConditionalDebug -> Trace Over ConditionalDebug -> Trace Record -> BitDebug -> Trace Record -> NoneDebug -> Undo instructionDebug -> Animate intoDebug -> Animate overDebug -> Animate commandPlugins -> ScyllaFavourites -> Manage Favourite ToolsOptions -> PreferencesOptions -> AppearanceOptions -> ShortcutsOptions -> TopmostOptions -> Reload style.cssHelp -> AboutHelp -> DonateHelp -> Check for UpdatesHelp -> CalculatorHelp -> Report BugHelp -> ManualHelp -> Generate Crash DumpActions -> Find StringsActions -> Find Intermodular CallsActions -> Toggle BreakpointActions -> Toggle BookmarkActions -> Delete BreakpointActions -> Enable/Disable BreakpointActions -> Binary EditActions -> Binary FillActions -> Binary Fill NOPsActions -> Binary CopyActions -> Binary PasteActions -> Binary Paste (Ignore Size)Actions -> Undo SelectionActions -> Set LabelActions -> Set CommentActions -> Toggle FunctionActions -> Toggle ArgumentActions -> AssembleActions -> YaraActions -> Set New Origin HereActions -> Goto OriginActions -> Goto PreviousActions -> Goto NextActions -> Goto ExpressionActions -> Goto Start of PageActions -> Goto End of PageActions -> Goto Start of FunctionActions -> Goto End of FunctionActions -> Goto File OffsetActions -> Find References to Selected AddressActions -> Find PatternActions -> Find ReferencesActions -> xrefs...Actions -> Analyze Single FunctionActions -> Analyze ModuleActions -> Help on MnemonicActions -> Toggle Mnemonic BriefActions -> Highlighting ModeActions -> Enable/Disable Branch Destination PreviewActions -> FindActions -> Decompile FunctionActions -> Decompile SelectionActions -> Edit breakpointActions -> Enable/Disable LoggingActions -> Allocate MemoryActions -> Free MemoryActions -> Sync With ExpressionActions -> EntropyActions -> Copy All RegistersActions -> Mark As User ModuleActions -> Mark As System ModuleActions -> Mark As PartyActions -> Set Hardware Breakpoint (Execute)Actions -> Remove Hardware BreakpointActions -> Remove Analysis From ModuleActions -> Remove Analysis From SelectionActions -> Treat Selection As CodeActions -> Treat Selection As ByteActions -> Treat Selection As WordActions -> Treat Selection As DwordActions -> Treat Selection As FwordActions -> Treat Selection As QwordActions -> Treat Selection As TbyteActions -> Treat Selection As OwordActions -> Treat Selection As FloatActions -> Treat Selection As DoubleActions -> Treat Selection As LongDoubleActions -> Treat Selection As ASCIIActions -> Treat Selection As UNICODEActions -> Treat Selection As MMWordActions -> Treat Selection As XMMWordActions -> Treat Selection As YMMWordActions -> Increase RegisterActions -> Decrease RegisterActions -> Increase Register byActions -> Decrease Register byActions -> Zero RegisterActions -> Set Register to OneActions -> Toggle Register ValueActions -> CopyActions -> Copy AddressActions -> Copy SymbolActions -> Load ScriptActions -> Reload ScriptActions -> Unload ScriptActions -> Run ScriptActions -> Toggle Script BreakpointActions -> Run Script to CursorActions -> Step ScriptActions -> Abort ScriptActions -> Execute Script CommandActions -> RefreshActions -> GraphActions -> Graph -> Toggle overviewActions -> Increment x87 StackActions -> Decrement x87 StackActions -> PushActions -> PopActions -> Redirect LogActions -> Browse in ExplorerActions -> Download Symbols for This ModuleActions -> Download Symbols for All ModulesActions -> Create New Thread HereNOT FOUND IN CONFIG!DBG%u functions
Indirect pointer: 0x%p 0x%p
%u functions discovered!
This kind of analysis doesn't work on x32 executables...
this command is debug-onlySaving database...
Failed to write database file!Loading commandline...Loading database...
Invalid database file!
Failed to read database file!
Invalid database file (JSON)!Warning: Failed to create database folder '%s'. Path may be read only.
Database file: %s
missing operandfailed to convert operandoperand value too biginvalid operand (FromHex failed)invalid size (expected %llu, got %llu)invalid size (expected %u, got %u)80bit extended float is not supportedinvalid string literalstring too longdest buffer too smallThread switched from %X to %X !
Module: %s - (switched from %s)File: %s - PID: %X - %sThread: %s%s%s breakpoint "%s" at %s (%p)!
%s breakpoint at %s (%p)!
%s breakpoint "%s" at %p!
%s breakpoint at %p!
executeread/writewriteHardware breakpoint (%s%s) "%s" at %s (%p)!
Hardware breakpoint (%s%s) at %s (%p)!
Hardware breakpoint (%s%s) "%s" at %p!
Hardware breakpoint (%s%s) at %p!
(read) (write) (execute) (read/write/execute)Memory breakpoint%s "%s" at %s (%p, %p)!
Memory breakpoint%s at %s (%p, %p)!
Memory breakpoint%s "%s" at %p (%p)!
Memory breakpoint%s at %p (%p)!
DLL LoadDLL UnloadDLL Load and unloadBreakpoint reached not in list!User code reached at %s (%p)!Breakpoint %p has been disabled because the bytes don't match! Expected: %02X %02X, Found: %02X %02X
Could not set breakpoint %p! (SetBPX)
MemRead failed on breakpoint address%p!
Could not set memory breakpoint %p! (SetMemoryBPXEx)
You can only set 4 hardware breakpointsDLL Breakpoint %s(%s):Module %s
DLL Breakpoint(%s):Module %s
Could not set hardware breakpoint %p! (SetHardwareBreakPoint)
Set hardware breakpoint on %p!
Could not delete breakpoint %p! (DeleteBPX)
Could not delete memory breakpoint %p! (RemoveMemoryBPX)
Could not delete hardware breakpoint %p! (DeleteHardwareBreakPoint)
Trace finished after %llu steps!
Trace finished after %u steps!
Bad tracing state.
??? (GetFileNameFromHandle failed)Process Started: %p %s
TLS Callbacks: %d
Failed to get TLS callback addresses!TLS Callback %d%d invalid TLS callback addresses...
entry breakpointProcess stopped with exit code 0x%X
ThreadThread %X created, Entry: %p
No threads left to switch to (bug?)Thread %X exit
Attach breakpoint reached!System breakpoint reached!Error: Cannot load global initialization script.Error: Cannot load debuggee initialization script.TLS CallbackDLL Loaded: %p %s
DLL Unloaded: %p %s
DebugString: "%s"
DetachDebuggerEx failed...Detached!paused!SetThreadName(%X, "%s")
First chance exception on %p (%.8X, %s)!
First chance exception on %p (%.8X)!
Last chance exception on %p (%.8X, %s)!
Last chance exception on %p (%.8X)!
Delete breakpoint failed (BpDelete): %p
Delete breakpoint failed (DeleteBPX): %p
Could not enable breakpoint %p (SetBPX)
Could not enable breakpoint %p (BpEnable)
Could not disable breakpoint %p (BpEnable)
Could not disable breakpoint %p (DeleteBPX)
Did not enable hardware breakpoint %p (all slots full)
Could not enable hardware breakpoint %p (BpEnable)
Could not enable hardware breakpoint %p (SetHardwareBreakPoint)
Could not disable hardware breakpoint %p (BpEnable)
Could not disable hardware breakpoint %p (DeleteHardwareBreakPoint)
Could not enable memory breakpoint %p (BpEnable)
Could not enable memory breakpoint %p (SetMemoryBPXEx)
Could not disable memory breakpoint %p (BpEnable)
Could not disable memory breakpoint %p (RemoveMemoryBPX)
Could not enable DLL breakpoint %s (BpEnable)
Could not enable DLL breakpoint %s (LibrarianSetBreakPoint)
Could not disable DLL breakpoint %s (BpEnable)
Could not disable DLL breakpoint %s (LibrarianRemoveBreakPoint)
Could not delete DLL breakpoint %s (BpDelete)
Could not delete DLL breakpoint %s (LibrarianRemoveBreakPoint)
Delete memory breakpoint failed (BpDelete): %p
Delete memory breakpoint failed (RemoveMemoryBPX): %p
Delete hardware breakpoint failed (BpDelete): %p
Delete hardware breakpoint failed (DeleteHardwareBreakPoint): %p
Error starting process (CreateProcess, %s)!
IsWow64Process failed!Use x32dbg to debug this process!Use x64dbg to debug this process!Debugging stopped!not enough arguments!Resolved shortcut "%s"->"%s"
File does not exist!Could not open file!Invalid PE file!Use x32dbg to debug this file!Use x64dbg to debug this file!The debuggee does not stop after 10 seconds. The debugger state may be corrupted.Not enough arguments!Invalid type specified!Default breakpoint type set to: %s
Invalid addr: "%s"
Breakpoint already set!Error setting breakpoint at %p! (IsBPXEnabled)
Error setting breakpoint at %p! (memread)
Error setting breakpoint at %p! (bpnew)
Error setting breakpoint at %p! (SetBPX)
Breakpoint at %p set!
No breakpoints to delete!All breakpoints deleted!Delete breakpoint failed (bpdel): %p
No such breakpoint "%s"
Breakpoint deleted!No breakpoints to enable!All breakpoints enabled!Breakpoint already enabled!Breakpoint enabled!No breakpoints to disable!All breakpoints disabled!Breakpoint already disabled!Breakpoint disabled!not enough arguments!
Can't set %s on breakpoint "%s"
breakpoint namebreak conditionlogging textlogging conditioncommand on hitcommand conditionCan't set hit count on breakpoint "%s"
Can't set fast resume on breakpoint "%1"
Can't set singleshoot on breakpoint "%1"
Can't set silent on breakpoint "%1"
argument count mismatch!
Invalid type, assuming 'x'Invalid size, using 1Address not aligned to %d
Hardware breakpoint already set!Error setting hardware breakpoint (bpnew)!Error setting hardware breakpoint (TitanEngine)!Hardware breakpoint at %p set!
No hardware breakpoints to delete!All hardware breakpoints deleted!Delete hardware breakpoint failed: %p (BpDelete)
Delete hardware breakpoint failed: %p (DeleteHardwareBreakPoint)
No such hardware breakpoint "%s"
Hardware breakpoint deleted!No hardware breakpoints to enable!All hardware breakpoints enabled!Hardware breakpoint already enabled!Could not enable hardware breakpoint %p (SetHardwareBreakpoint)
Hardware breakpoint enabled!No hardware breakpoints to disable!All hardware breakpoints disabled!Hardware breakpoint already disabled!Could not disable hardware breakpoint %p (DeleteHardwareBreakpoint)
Hardware breakpoint disabled!Invalid type (argument ignored)Memory breakpoint already set!Error setting memory breakpoint! (BpNew)Error setting memory breakpoint! (SetMemoryBPXEx)Memory breakpoint at %p set!
no memory breakpoints to delete!All memory breakpoints deleted!Delete memory breakpoint failed: %p (BpDelete)
Delete memory breakpoint failed: %p (RemoveMemoryBPX)
No such memory breakpoint "%s"
Memory breakpoint deleted!No memory breakpoints to enable!All memory breakpoints enabled!Memory memory already enabled!Memory breakpoint enabled!No memory breakpoints to disable!All memory breakpoints disabled!Memory breakpoint already disabled!Memory breakpoint disabled!Something went wrong...Error creating Dll breakpoint! (BpNewDll)Error creating Dll breakpoint! (LibrarianSetBreakPoint)No DLL breakpoints to disable!All DLL breakpoints disabled!No such DLL breakpoint "%s"
DLL breakpoint already disabled!Could not disable DLL breakpoint %s (LibrarianSetBreakPoint)
DLL breakpoint disabled!No DLL breakpoints to enable!All DLL breakpoints enabled!DLL breakpoint already enabled!DLL breakpoint enable!Skipped INT3!Debugger hiddenSomething went wrongRun to party is busy.
Not enough argumentsTrace already activeInvalid expression "%s"
VirtualAllocEx failed$lastalloc is zero, provide a page addressVirtualFreeEx failedInvalid address specifiedMemset failedMemory %p (size: %.8X) set to %.2X
%ums
Program is not runningError suspending threadError resuming threadError loading Scylla.dll!Could not find export 'ScyllaStartGui' inside Scylla.dllScylla is already loadedCould not open process %X!
Could not get module filename %X!
Invalid address "%s"!
Invalid stack address!Exception will be swallowedException will be thrown in the programDll breakpoint set on "%s"!
No DLL breakpoints to delete!All DLL breakpoints deleted!Failed to remove DLL breakpoint...DLL breakpoint removed!Not debugging!Invalid thread %X
Thread switched!Thread suspendedThread resumed!Thread terminatedError terminating thread!Create thread failed!Thread %X created at %s %p(Argument=%llX)
Thread %X created at %s %p(Argument=%X)
%d/%d thread(s) suspended
%d/%d thread(s) resumed
Unknown priority value, read the help!Error setting thread priorityThread priority changed!Failed to change the name for thread %X
Thread name set to "%s"!
Thread name changed from "%s" to "%s"!
This may take very long, depending on your network connection and data in the debug directory...Done! See symbol log for more informationInvalid module "%s"!
GetModuleFileNameExA failed!SymGetSearchPath failed!SymSetSearchPath (1) failed!SymUnloadModule64 failed!SymLoadModuleEx failed!SymSetSearchPathW (2) failed!Error getting JIT auto %s
Unknown JIT auto entry type. Use x64 or x32 as parameter.Error using x64 arg the debugger is not a WOW64 process
Unknown JIT auto entry type. Use x64 or x32 as parameterJIT auto %s: %s
Error run the debugger as Admin to setjitauto
Error setting JIT Auto. Use ON:1 or OFF:0 arg or x64/x32, ON:1 or OFF:0.
Error unknown parameters. Use ON:1 or OFF:0Error setting JIT auto x64Error setting JIT auto x32Error unknown parameters. Use x86 or x64 and ON:1 or OFF:0
Error getting JIT auto x64Error getting JIT auto x32Error unknown parameters use x86 or x64, ON/1 or OFF/0
New JIT auto %s: %s
Error run the debugger as Admin to setjit
Error setting JIT %s
Error there is no old JIT entry stored.New OLD JIT stored: %s
Unknown JIT entry type. Use OLD, x64 or x32 as parameter.Error using x64 arg. The debugger is not a WOW64 process
Error unknown parameters. Use old, oldsave, restore, x86 or x64 as parameter.New JIT %s: %s
Error getting JIT %s
Error: there is not an OLD JIT entry stored yet.OLD JIT entry stored: %s
JIT %s: %s
Error: using an address as arg1
Error getting rights of page: %s
Page: %p, Rights: %s
Error: Using an address as arg1 and as arg2: Execute, ExecuteRead, ExecuteReadWrite, ExecuteWriteCopy, NoAccess, ReadOnly, ReadWrite, WriteCopy. You can add a G at first for add PAGE GUARD, example: GReadOnly
Error: Set rights of %p with Rights: %s
New rights of %p: %s
Error: you must specify the name of the DLL to load
Error: couldn't allocate memory in debuggeeError: couldn't write process memoryError: couldn't get kernel32:LoadLibraryAError allocating memory for cmdlineError converting UNICODE cmdlineError reading PEB base addresError reading PEB -> ProcessParameters -> CommandLine UNICODE_STRINGError reading PEB -> ProcessParameters pointer addressError Getting remote PEB addressError Getting command line base addressError checking the pattern of the commandline storedError writing the new command line storedError getting getcommandlineError allocating the page with UNICODE and ANSI command linesError writing the ANSI command line in the pageError writing the UNICODE command line in the pageError writing command line UNICODE in PEBError getting cmdline (Address: %p)Command line: %s
Error: write the arg1 with the new command line of the process debuggedNew command line: %s
Stack is now freezed
Stack is now unfreezed
Invalid line: "%s"
Failed to convert number "%s"
invalid dest "%s"
Cannot restore last instruction.History record is emptyunknown command/expression: "%s"
Not enough arguments! At least %d arguments must be specified.
invalid variable name "%s"
invalid value "%s"
error creating variable "%s"
could not delete variable "%s"
deleted variable "%s"
invalid hex string "%s" (contains invalid characters)
invalid destination "%s"
invalid hex byte "%s"
failed to write to %p
invalid src "%s"
no variables!error listing variables!directory doesn't existcurrent directory changed!error setting commenterror deleting commenterror setting labelerror deleting labelfailed to set bookmark!bookmark set!failed to delete bookmark!bookmark deleted!invalid expression: "%s"!
invalid address: %p!
failed to assemble "%s" (%s)
failed to add functionfunction added!failed to delete functionfunction deleted!all functions deleted!failed to add argumentargument added!failed to delete argumentargument deleted!all arguments deleted!invalid variable "%s"
invalid argument "%s"!
Variable size not supported.invalid hex string "%s" (length not divisible by 2)
ScriptAddressDataDisassemblyConstant: %pRange: %p-%p%u reference(s) in %ums
StringStrings%u string(s) in %ums
no such variable "%s"!
failed to set variable "%s"!
variable "%s" is not a string!
failed to get variable size "%s"!
failed to get variable data "%s"!
invalid address "%s"!
memwrite failed!string written!invalid memory address %p!
failed to read memory!Pattern: %s&Data&failed to transform pattern![Error disassembling]%d occurrences found in %ums
MemFindInMap failed!DestinationCalls%u call(s) in %ums
CommentsCommentno comments%d comment(s) listed in Reference View
LabelsLabelno labels%d label(s) listed in Reference View
BookmarksNo bookmarks found%d bookmark(s) listed
FunctionsStartEndDisassembly (Start)Label/CommentNo functions%d function(s) listed
ArgumentsNo arguments%d argument(s) listed
Loopsno loops%d loop(s) listed
failed to assemble "%s" (%s)!
Command: "%s"%u result(s) in %ums
[YARA ERROR] [YARA WARNING] File: "%s", Line: %d, Message: "%s"
[YARA] Global rule "%s' matched!
[YARA] Rule "%s" matched:
[YARA] String "%s" : %s on %p
[YARA] Rule "%s" did not match!
[YARA] Scan finished![YARA] Imported module "%s"!
invalid value "%s"!
failed to get module path for %p!
failed to read file "%s"!
failed to read memory page %p[%X]!
Failed to read the rules file "%s"
Rule[YARA] Scan started...%u scan results in %ums...
too many matches!error while scanning memory!error while getting the rules!errors in the rules file!yr_compiler_create failed!invalid module "%s"!
invalid address "%s"
could not read memory at %p
failed to disassemble!
size: %d, id: %d, opcount: %d
operand "%s" %d, register: %s
immediate: 0x%p
memory segment: %s, base: %s, index: %s, scale: %d, displacement: 0x%p
Invalid parameter [base]!Invalid memory address!Invalid parameter [size]Failed to load module (ModLoad)...Virtual module "%s" loaded on %p[%p]!
invalid arguments!usage: meminfo a/r, addrinvalid argumentReadProcessMemory failed!data: %02X
memory map updated!Invalid expression: "%s"Failed to read memory...Failed to write file...%p[% llX] written to "%s" !
%p[% X] written to "%s" !
no description or empty descriptionEncodeMapSetType failed...Could not find the specified privilege: %s
DuplicateHandle failed: %s
Handle %llX closed!
Handle %X closed!
Failed to get SEH (disabled?)Failed to get VEH (loaded symbols for ntdll.dll?)Failed to get VCH (loaded symbols for ntdll.dll?)Failed to get UnhandledExceptionFilter (loaded symbols for kernelbase.dll?)Invalid memory address %p!
No graph generated...Invalid argument 1 : %s
Invalid argument 2 : %s
Image information for %s
Characteristics (0x%X):
None
IMAGE_FILE_RELOCS_STRIPPED: Relocation info stripped from file.IMAGE_FILE_EXECUTABLE_IMAGE: File is executable (i.e. no unresolved externel references).IMAGE_FILE_LINE_NUMS_STRIPPED: Line nunbers stripped from file.IMAGE_FILE_LOCAL_SYMS_STRIPPED: Local symbols stripped from file.IMAGE_FILE_AGGRESIVE_WS_TRIM: Agressively trim working setIMAGE_FILE_LARGE_ADDRESS_AWARE: App can handle >2gb addressesIMAGE_FILE_BYTES_REVERSED_LO: Bytes of machine word are reversed.IMAGE_FILE_32BIT_MACHINE: 32 bit word machine.IMAGE_FILE_DEBUG_STRIPPED: Debugging info stripped from file in .DBG fileIMAGE_FILE_REMOVABLE_RUN_FROM_SWAP: If Image is on removable media, copy and run from the swap file.IMAGE_FILE_NET_RUN_FROM_SWAP: If Image is on Net, copy and run from the swap file.IMAGE_FILE_SYSTEM: System File.IMAGE_FILE_DLL: File is a DLL.IMAGE_FILE_UP_SYSTEM_ONLY: File should only be run on a UP machineIMAGE_FILE_BYTES_REVERSED_HI: Bytes of machine word are reversed.DLL Characteristics (0x%X):
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE: DLL can move.IMAGE_DLLCHARACTERISTICS_FORCE_INTEGRITY: Code Integrity ImageIMAGE_DLLCHARACTERISTICS_NX_COMPAT: Image is NX compatibleIMAGE_DLLCHARACTERISTICS_NO_ISOLATION: Image understands isolation and doesn't want itIMAGE_DLLCHARACTERISTICS_NO_SEH: Image does not use SEH. No SE handler may reside in this imageIMAGE_DLLCHARACTERISTICS_NO_BIND: Do not bind this image.IMAGE_DLLCHARACTERISTICS_WDM_DRIVER: Driver uses WDM model.IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE: Remote Desktop Services aware.Reserved (%p)ReservedThread %X TEBThread %X WoW64 TEBThread %X StackInvalid mnemonic!Too many redirections...invalid instructionNo patches to applyNot all patches are in module %sFailed to get base of module %sFailed to get module path of module %sFailed to make a copy of the original file (patch target is in use?)Unable to obtain attributes for copied fileStaticFileLoad failedStaticFileUnload failedInvalid memory page 0x%p
%s (Region %s)%s (Region %p)Region SearchCouldn't locate module for 0x%p
Module SearchCouldn't get module listAll Modules (%s)Error reading memory in reference search
FileHelper::ReadAllText failed...Empty label detected on line %d!Duplicate label "%s" detected on lines %d and %d!Invalid branch label "%s" detected on line %d!Script finished!Error executing command!The script is too busy. Would you like to terminate it now?Script is terminated by user.Debugger must be paused to run a script!Pointer to SEH_Record[%d]End of SEH Chainreturn to %s from %sreturn to %s from ???[Formatting Error]SymEnumSymbols failed!SymEnumerateModules64 failed!SymGetSearchPathW failed!SymSetSearchPathW (1) failed!Downloading symbols for %s...
GetModuleFileNameExW(%p) failed!
SymUnloadModule64(%p) failed!
SymLoadModuleEx(%p) failed!
Main Threadcould not get filename of module %p
unable to load library %s
not debuggingnoexpr failed on %s
failed to read memorynot debugging!invalid value: "%s"!
failed to write memoryWatchdog %s (expression "%s") is triggered at %p ! Original value: %p, New value: %p
Watch %uNo enough arguments for addwatch
No enough arguments for delwatch
Error expression in argument 1.
No enough arguments for SetWatchNameNo enough arguments for SetWatchExpressionUnknown watchdog mode.
command cut at ~%d characters
[Script DLL] Calling export "AsyncStart"...
[Script DLL] "AsyncStart" returned!
[Script DLL] Calling FreeLibrary...success!
failure (%08X)...
[Script DLL] Loading Script DLL "%s"...
[Script DLL] DLL loaded on 0x%p!
[Script DLL] Creating thread to call the export "AsyncStart"...
[Script DLL] Calling export "Start"...
[Script DLL] "Start" returned!
[Script DLL] Failed to find the exports "AsyncStart" or "Start" (%08X)!
[Script DLL] LoadLibary failed (%08X)!
Initializing wait objects...Initializing debugger...Initializing debugger functions...Setting JSON memory management functions...Initializing capstone...Initializing Yara...Getting directory information...Mnemonic help database loaded!Failed to load mnemonic help database...Failed to read mnemonic help database...Error codes database loaded!Failed to load error codes...Exception codes database loaded!Failed to load exception codes...NTSTATUS codes database loaded!Failed to load NTSTATUS codes...It is strongly discouraged to use symbol servers in your path directly (use the store option instead).
Do you want me to fix this?Symbol Path: %s
Allocating message stack...Initializing global script variables...Registering debugger commands...Registering GUI command handler...Registering expression functions...DefaultRegistering Script DLL command handler...Script DLLStarting command loop...Loading plugins...Handling command line...Reading notes file...Initialization successful!Stopping running debuggee...The debuggee does not close after 10 seconds. Probably the debugger state has been corrupted.Aborting scripts...Waiting for the debuggee to be stopped...Unloading plugins...Stopping command thread...Cleaning up allocated data...Checking for mem leaks...%d memory leak(s) found!
Cleaning up wait objects...Cleaning up debugger threads...Saving notes...Exit signal processed successfully!Failed on ks_open()...ks_asm() failed: count = %lu, error = %uNon-executable memory regionAssembled branch does not point to an executable memory region!Error while writing process memory[PLUGIN] Failed to load plugin: %s
[PLUGIN] Export "pluginit" not found in plugin: %s
[PLUGIN] pluginit failed for plugin: %s
[PLUGIN] %s is incompatible with this SDK version
[PLUGIN] %s v%d Loaded!
[PLUGIN] GuiMenuAdd(GUI_PLUGIN_MENU) failed for plugin: %s
[PLUGIN] GuiMenuAdd(GUI_DISASM_MENU) failed for plugin: %s
[PLUGIN] GuiMenuAdd(GUI_DUMP_MENU) failed for plugin: %s
[PLUGIN] GuiMenuAdd(GUI_STACK_MENU) failed for plugin: %s
[PLUGIN] command "%s" registered!
[PLUGIN] command "%s" unregistered!
[PLUGIN] expression function "%s" registered!
[PLUGIN] expression function "%s" unregistered!
DataCopyDialogData CopyCopyC-Style BYTE (Hex)C-Style WORD (Hex)C-Style DWORD (Hex)C-Style QWORD (Hex)C-Style StringC-Style Unicode StringC-Style Shellcode StringPascal BYTE (Hex)Pascal WORD (Hex)Pascal DWORD (Hex)Pascal QWORD (Hex)GUIDDisassemblerGraphViewUse Graph command or menu action to draw control flow graph here...Follow in &DisassemblerToggle &OverviewEditBreakpointDialogEdit breakpoint&Log Text:&Break Condition:Lo&g Condition:&Name:&Command Text:&Hit Count:C&ommand Condition:Singlesho&ot&Silent&Fast Resume&SaveC&ancelEdit Breakpoint %1EditFloatRegisterDialogDouble:Short:Float:Byte:Int64:Long:High:0-12-34-56-78-9A-BC-DE-FLow:&Hexadecimal&Signed&UnsignedUnified hex value follows memory byte order.&OK&CancelError, register size %1 is not supported.
EntropyDialogEntropyExceptionRangeDialogRangeStart:End:OKCancelFavouriteToolsFavouritesTools&Add...&Edit&RemoveDe&scription...&Up&DownScriptCommandShortcutClear&OK&CancelPathDescriptionEnter the descriptionThis string will appear in the menu.Select scriptScript files (*.txt *.scr);;All files (*.*)Enter the command you want to favouriteExample: bphws cspEnter a new commandExample: bphws ESPGotoDialogEnter expression to follow...&OK&Cancel<font color='red'><b>Not debugging...</b></font><font color='red'><b>Invalid expression...</b></font><font color='red'><b>Empty expression...</b></font><font color='#00DD00'><b>Correct expression! -> </b></font><font color='red'><b>Invalid file offset...</b></font><font color='red'><b>Invalid memory address...</b></font><font color='red'><b>Memory out of range...</b></font>HandlesViewTypeType numberHandleAccessNameRemote addressLocal addressPrivilegeStateHandlesTCP ConnectionsPrivileges&RefreshClose handleDisable Privilege: Enable Privilege: Disable all privilegesEnable all privilegesTCP Connection enumeration is only available on Windows Vista or greater.&CopyUnknownEnabledDisabledHexDump&Selection&AddressError!Selection not in a module...AddressHexEditDialogHexEdit&ASCII:&UNICODE:&Hex:&Keep Size&OK&Entire Block&Cancel&Codepage...Enter text to convert...LineEditDialogDialogCheckBox&OK&Cancel<font color='red'>CT: %1%2</font>LogViewClea&r&CopySelect &All&SaveDisable &Logging&Redirect Log...Enable &LoggingStop &Redirectionfwrite() failed (GetLastError()= %1 ). Log redirection stopped.
Redirect log to fileEnter the file to which you want to redirect log messages.Log files(*.txt);;All files(*.*)_wfopen() failed. Log will not be redirected to %1.
Log will be redirected to %1.
Logging will be enabled.
Logging will be disabled.
Error, log have not been saved.
Log have been saved as %1
MHTabBar&Detach&DeleteMainWindowx64dbg&File&Recent Files&View&DebugTrace record&Help&Plugins&OptionsFavour&itestoolBar&OpenE&xit&Run&PauseRe&start&CloseStep &intoStep &overCo&mmandE&xecute till return&Memory Map&Log Window&AboutScylla&BreakpointsStep into (pass exceptions)Step over (pass exceptions)Run (pass exceptions)Execute till return (pass exceptions)&ScriptScriptRun &until selectionRun until selection&CPUCPUSymbol &InfoSymbol Info&ReferencesReferences&ThreadsThreads&PreferencesSettings&Find StringsFind Strings&AppearanceFind Intermodular CallsPatchesCommentsLabelsBookmarksFunctionsCheck for &UpdatesCall StackShortcuts&DonateDonateCalculatorAttachDetachChange Command &LineSkip next instructionTopmostTopmost Window&Report BugReport Bug&SourceSource&Manual&FAQFAQSEH ChainHide debugger (PEB)Reload style.cssNotesSnowmanHandlesTrace over until conditionTrace into until conditionBitByteWordTrace into beyond trace recordTrace over beyond trace recordTrace into into trace recordTrace over into trace recordNoneRun to &user codeRun until e&xpressionUndo last instructionGenerate crash dump&Manage Favourite Tools...Step over (source)Step into (source)&GraphStep into (swallow exception)Step over (swallow exception)Run (swallow exception)BlogAnimate intoAnimate overAnimate command...Set Initialization ScriptImport settings...LogSymbolsBreakpointsMemory MapSEHGraphCommand: ReadyLanguagesEnter trace into finishing condition.Example: eax == 0 && ebx == 0Enter trace over finishing condition.About x64dbgAbout x32dbgOpen fileExecutables (*.exe *.dll);;All files (*.*)Enter expression to run to...Error!Patches cannot be shown when not debugging...All the money will go to x64dbg development.You will visit x64dbg's official blog.You will be taken to a website where you can report a bug.
Make sure to fill in as much information as possible.This action will crash the debugger and generate a crash dump. You will LOSE ALL YOUR DATA. Do you really want to continue?Have fun debugging the debugger!Debugger detected!Change Command LineCannot get remote command line, use the 'getcmdline' command for more information.Could not set command line!New command line: ErrorManual cannot be opened. Please check if x64dbg.chm exists and ensure there is no other problems with your system.The translation is nearly empty. Do you still want to use this language?New language setting will take effect upon restart.Animate commandExample: StepIntoSet Initialzation Script for DebuggeeScript files (*.txt *.scr);;All files (*.*)Set Global Initialzation ScriptSettings (*.ini);;All files (*.*)MemoryMapViewAddressSizeInfoPage InformationTypeAllocation TypeProtectionCurrent ProtectionInitialAllocation Protection&Follow in DumpFollow in &DisassemblerSet Page Memory Rights&Switch ViewMemory &BreakpointAccess&Singleshoot&RestoreWriteExecute&Remove&Allocate memory&Free memoryFind address &pageEntropy...&Find Pattern...&Dump Memory to FileAdd virtual module&CopyEntropy (Address: %1, Size: %2)ErrorWarningYou're trying to allocate a zero-sized buffer just now.The size of buffer you're trying to allocate exceeds 1GB. Please check your expression to ensure nothing is wrong.Memory allocation failed!Find Pattern...All files (*.*)Save Memory RegionAddress %0 not found in memory map...Enter the address to find...NotesManagerGlobalDebuggeePageMemoryRightsSet Page Memory RightsRightsNO ACCESSREAD ONLYREAD WRITEEXECUTEEXECUTE READFULL ACCESSWRITE COPYEXECUTE WRITE COPYSet RightsSelect ALLDeselect ALLPress CTRL or SHIFT key to select multiple pagesPAGE GUARDAddressPages Rights Changed to: Error setting rights, read the MSDN to learn the valid rights of: PatchDialogPatches&Patches&Modules&Select All&Deselect All&Restore SelectedPick &Groups&Patch File&Import&ExportInformationNothing to patch!Error!Failed to get module filename...Save fileAll files (*.*)Failed to save patched file (%1)%1/%2 patch(es) applied!Open patchPatch files (*.1337)The patch file is empty...Patch file format is incorrect...No patches to apply in the current process.QuestionSome patches are already applied.
Do you want to remove these patches?Some bytes do not match the original in the patch file.
Do you want to apply these patches anyway?Save patchNo patches to export.%1 patch(es) exported!PatchDialogGroupSelectorGroup Selector0000000000000000&Toggle&Previous&NextQObjectDbgInit Error!ReferenceManagerClose All TabsReferenceView&Follow in DisassemblerFollow in &DumpFollow &API AddressToggle BreakpointToggle BookmarkSet breakpoint on all commandsRemove breakpoint on all commandsSet breakpoint on all api callsRemove breakpoint on all api callsTotal Progress %1%Set breakpoint on all calls to %1Remove breakpoint on all calls to %1Error!DbgSetBookmarkAt failed!RegistersViewIncrementDecrementZeroSet to 1Modify valueToggleCopy value to clipboardCopy Symbol Value to ClipboardCopy all registersFollow in DisassemblerFollow in DumpFollow in StackIncrement x87 StackDecrement x87 StackChange viewIncrease 4Increase 8Decrease 4Decrease 8PushPopHighlightFollow in &DumpDump %1Hide FPUShow FPUEdit YMM registerEdit XMM registerEdit FPU registerERROR CONVERTING TO HEXEditSet Hardware Breakpoint on %1SEHChainViewAddressHandlerModule/LabelCommentFollow &AddressFollow Handler&CopyScriptViewLineTextInfo&Open...Load ScriptRe&load Script&Unload ScriptToggle &BPRu&n until selection&Step&Run&Abort&Continue here...&Execute Command...Error on lineScript Error!Select scriptScript files (*.txt *.scr);;All files (*.*)Error setting script breakpoint!Execute Script Command...Error executing command!MessageQuestionSearchListViewType here to filter results...RegexLockSearch: Search...&CopySelectFieldsDialogSettingsDialogSettingsEventsSystem Breakpoint*Break on:DLL LoadAttach BreakpointDLL EntryEntry Breakpoint*DLL UnloadTLS Callbacks*Thread EndThread EntryDebug StringsThread StartEngineCalculation Type&Signed&UnsignedDefault Breakpoint TypeINT3Long INT3UD2Undecorate Symbol NamesEnable Debug &PrivilegeEnable Source DebuggingDisable Database CompressionSave Database in Program DirectoryEnable Trace Record Recording during a TraceSkip INT3 steppingNo Script Timeout Warning&Ignore inconsistent breakpointsExceptionsIgnored Exceptions:Add &Range&Delete RangeAdd &LastDisasmArgument SpacesTab between mnemonic and argumentsMemory SpacesUppercaseAutocomments only on CIPGUIShow FPU registers as little endianSave column order and widthDon't show close dialogShow PID in HEXShow Watch Labels in Side BarMiscSymbol Store:Symbol Path:Set x64dbg as Just In Time DebuggerJIT:Confirm before attaching<font color="red">DIE SCUM!</font>Enable Load/Save Tab OrderSearch Engine URLSaveCancel<font color="red"><b>Warning</b></font>: Run the debugger as Admin to enable JIT.Settings saved!ERROR NOT FOUND OLD JITNOT FOUND OLD JIT ENTRY STORED, USE SETJIT COMMANDQuestionAre you sure you want to add %.8X?ShortcutsDialogShortcutsShortcutClear&Save&CancelInstructionSettings saved!SourceViewAddressLineCodeSourceViewerManagerClose All TabsStatusLabel<font color='#00DD00'>Initialized</font><font color='#ff0000'>Paused</font>Running<font color='#ff0000'>Terminated</font>StdTable&LineCropped &Table&Full Table&CopySymbolViewFormBaseModulePartyAddressTypeSymbolSymbol (undecorated)&Follow in DisassemblerFollow in &DumpToggle BreakpointToggle BookmarkFollow &Entry Point in Disassembler&Download Symbols for This ModuleDownload Symbols for &All ModulesCopy File &PathBrowse in Explorer&Yara Memory...&Yara File...Entropy...Mark as &user moduleMark as &system moduleMark as &party...ImportExportUserSystemParty: %1&CopyError!DbgSetBookmarkAt failed!Entropy (%1)Mark the party of the module asErrorThe party number can only be an integerThreadView&CopyNormalAboveNormalTimeCriticalIdleBelowNormalHighestLowestSwitch ThreadSuspend ThreadResume ThreadKill ThreadSet PriorityAbove NormalSuspend All ThreadsResume All ThreadsSet NameBelow NormalTime CriticalGo to Thread EntryNumberIDEntryTEBRIPEIPSuspend CountPriorityWait ReasonLast ErrorUser TimeKernel TimeCreation TimeCPU CyclesNameMainUnknownTimeWastedCounter%1 events/sTime Wasted Debugging:UpdateCheckerNetwork Error!Error!File on server could not be parsed...New build %1 available!<br>Download <a href="%2">here</a><br><br>You are now on build %2You have a development build (%1) of x64dbg!You have the latest build (%1) of x64dbg!InformationVirtualModDialogVirtual Module&Name:&Base:&Size:&OK&CancelWatchViewNameExpressionValueTypeWatchdog ModeID%1 is not readable.DisabledChangedIs trueIs falseNot changed&Add...&DeleteRename&Edit...Watchdog&CopyEnter the expression to watchExample: [EAX]Enter the name of the watch variableWordEditDialogEditSigned:Unsigned:Bytes:Expression:XrefBrowseDialogDialogxrefs at %1YaraRuleSelectionDialogYaraDirectory...&File...&Select&CancelSelect Yara Rules Directory...Select Yara Rule...