BlackINT3 / OpenArk

The Next Generation of Anti-Rookit(ARK) tool for Windows.

Home Page:https://openark.blackint3.com

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

v1.3.0进入内核模式失败

godtang opened this issue · comments

commented

[Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\tmj\AppData\Roaming\OpenArk\symbols\fltMgr.pdb\BDB830D5AD37A0994727A90DE1D97BA41\fltMgr.pdb
[Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\tmj\AppData\Roaming\OpenArk\symbols\netio.pdb\AB48DD1F891D44F37D4883A131CE8E5F1\netio.pdb
[Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\tmj\AppData\Roaming\OpenArk\symbols\ntkrnlmp.pdb\79BE8C368BEC7DD9677EA9B355ACE7841\ntkrnlmp.pdb
[Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\tmj\AppData\Roaming\OpenArk\symbols\win32kfull.pdb\E4F8E6FD1C189A77A7282D02D158A7971\win32kfull.pdb
[UNONE::ObLoadDriverW] [ERR] NtLoadDriver service:\Registry\Machine\System\CurrentControlSet\Services\OpenArkDrv64 err:c0000603
[Kernel::onClickKernelMode] [ERR] InstallDriver C:\Users\tmj\AppData\Roaming\OpenArk\kernel\OpenArkDrv64.sys err
image

commented

i meet the same question

commented

i meet the same question

设置-更新和安全-恢复-高级启动
选择 禁用驱动程序签名强制执行 看看能不能进入内核模式

image
遇到了类似的问题,系统:Win11 22H2 22621.2428

进QQ群 706663529, 获取最新Beta版
注:后面Beta版都在QQ群发布,也可以在github等待发布稳定版。

Join QQ group 706663529 to get the latest Beta version.
Note: Beta versions will be released in the QQ group, and you can also wait for the stable version to be released on GitHub.

进QQ群 706663529, 获取最新Beta版 注:后面Beta版都在QQ群发布,也可以在github等待发布稳定版。

Join QQ group 706663529 to get the latest Beta version. Note: Beta versions will be released in the QQ group, and you can also wait for the stable version to be released on GitHub.

这个群搜不到啊,老哥你试试看

进QQ群 706663529, 获取最新Beta版 注:后面Beta版都在QQ群发布,也可以在github等待发布稳定版。

Join QQ group 706663529 to get the latest Beta version. Note: Beta versions will be released in the QQ group, and you can also wait for the stable version to be released on GitHub.

QQ上搜不到这个群

commented

@DyingWallet @thunder-sword 用电脑搜,我用手机也搜不到
image

commented

加群后已经能进入内核模式,各位可以等待或加群获取最新版本。

设置-更新和安全-恢复-高级启动 选择 禁用驱动程序签名强制执行 看看能不能进入内核模式

使用这个方法成功进入内核模式,感谢