BlackINT3 / OpenArk

The Next Generation of Anti-Rookit(ARK) tool for Windows.

Home Page:https://openark.blackint3.com

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

开发者你好,我遇到了这个问题:无法进入内核

tao1256 opened this issue · comments

OpenArk Console
Copyright (C) 2019 BlackINT3 https://github.com/BlackINT3/OpenArk
[Kernel::InitKernelEntryView::::operator ()] [INFO] 操作系统 : Windows 11
[Kernel::InitKernelEntryView::::operator ()] [INFO] 主版本号 : 10
[Kernel::InitKernelEntryView::::operator ()] [INFO] 副版本号 : 0
[Kernel::InitKernelEntryView::::operator ()] [INFO] 发行编号 : 23H2
[Kernel::InitKernelEntryView::::operator ()] [INFO] 编译号 : 22631
[Kernel::InitKernelEntryView::::operator ()] [INFO] 主服务包 : 0
[Kernel::InitKernelEntryView::::operator ()] [INFO] 副服务包 : 0
[Kernel::InitKernelEntryView::::operator ()] [INFO] R3地址空间 : 0x10000 - 0x7FFFFFFEFFFF
[Kernel::InitKernelEntryView::::operator ()] [INFO] R0地址空间 : 0xFFFF080000000000 - 0xFFFFFFFFFFFFFFFF
[Kernel::InitKernelEntryView::::operator ()] [INFO] 页面大小 : 4 KB
[Kernel::InitKernelEntryView::::operator ()] [INFO] 物理内存 : 32 GB
[Kernel::InitKernelEntryView::::operator ()] [INFO] CPU核数 : 16
[Kernel::InitKernelEntryView::::operator ()] [INFO] 系统根目录 : C:\WINDOWS
[Kernel::InitKernelEntryView::::operator ()] [INFO] 启动时间 : 2023-12-05 09:54:33 (0Day/10Hour/15Min)
[Kernel::InitKernelEntryView::::operator ()] [INFO] BootInfo : UEFI & SecureBoot
[Kernel::InitKernelEntryView::::operator ()] [INFO] HVM : VT Enabled
[OpenArk::onActionCheckUpdate] [INFO] requset server:http://file.blackint3.com:88/openark/version.txt
[OpenArk::onActionCheckUpdate::::operator ()] [INFO] local appver:1.3.2, build:202311111651
[OpenArk::onActionCheckUpdate::::operator ()] [INFO] server responsed:{
"err": 0,
"appver": "1.3.2",
"appbd": "202311111651",
"appcl": "6L+b56iL5aKe5by677ya5aKe5YqgUFBM44CB5YaF5a2Y5omr5o+P44CB57q/56iL566h55CG44CB5qih5Z2X5Y246L2944CB5Y+l5p+E5o+Q5p2D562J5ZCE56eN5Yqf6IO9CuWGheaguOWinuW8uu+8muWinuWKoOemgeeUqC/lkK/nlKjlm57osIPvvIxEdW1w6amx5Yqo44CB5raI5oGv6ZKp5a2Q44CB5by65Yig5paH5Lu244CB5paH5Lu2L+azqOWGjOihqOeuoeeQhuOAgeWQr+WKqOmhueOAgeiuoeWIkuS7u+WKoeOAgeacjeWKoeeuoeeQhuetieWQhOenjeWKn+iDvQrnlYzpnaLlop7lvLrvvJrkvJjljJZVSe+8jOWkp+W5heaPkOWNh+a1geeVheaApwrmlK/mjIHmnIDmlrBXaW4xMQpCVUfkv67lpI3vvIzov5jmnInlhbblroPlvojlpJrmnKrmj5Dlj4rnmoTlip/og70KS2VlcCBTaW1wbGUsIEtlZXAgRXZvbHV0aW9uYXJ5IQotLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0KSW1wb3ZlZCBwcm9jZXNzIG1hbmFnZXI6IEFkZGVkIFBQTCxNZW1vcnlTY2FuLFRocmVhZCx1bmxvYWQgbW9kdWxl44CBY2hhbmdlIGhhbmRsZSBhY2Nlc3MgZXRjLgpJbXBvdmVkIGtlcm5lbCBtYW5hZ2VyOiBBZGRlZCBrZXJuZWwgZmVhdHVyZXMsIGVuYWJsZS9kaXNhYmxlIGNhbGxiYWNrLCBEdW1wIGRyaXZlcixNZXNzYWdlSG9vayxGb3JjZURlbGV0ZSxGaWxlL1JlZy9Cb290IG1hbmFnZXIgZXRjLgpJbXByb3ZlZCBVSSBzdWJzdGFudGlhbGx5LgpTdXBwb3J0IHdpbjExIGxhdGVzdCByZWxlYXNlLgpCdWdmaXhlZCBhbmQgbWFueSBvdGhlciB1bm1lbnRpb25lZCBmZWF0dXJlcy4K",
"appurl": "https://github.com/BlackINT3/OpenArk/releases"
}

[OpenArk::onActionCheckUpdate::::operator ()] [INFO] OpenArk is latest.
[Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\12561\AppData\Roaming\OpenArk\symbols\ci.pdb\E817A0A88D7625E8E6826850FFEB3BED1\ci.pdb
[Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\12561\AppData\Roaming\OpenArk\symbols\fltMgr.pdb\87A9DA8C3521C233B137CECD2A4CED621\fltMgr.pdb
[Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\12561\AppData\Roaming\OpenArk\symbols\netio.pdb\4BBE9BBA056BB62AC113353D9FAF4CEB1\netio.pdb
[Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\12561\AppData\Roaming\OpenArk\symbols\ntkrnlmp.pdb\34898958E6070CE1E0B4F363528E1F291\ntkrnlmp.pdb
[Kernel::ParseKernelSymbol] [INFO] Download: http://msdl.blackint3.com:88/download/symbols/ntkrnlmp.pdb/34898958E6070CE1E0B4F363528E1F291/ntkrnlmp.pdb
[UNONE::ObLoadDriverW] [ERR] NtLoadDriver service:\Registry\Machine\System\CurrentControlSet\Services\OpenArkDrv64 err:c0000603
[UNONE::ObLoadDriverW] [ERR] NtLoadDriver service:\Registry\Machine\System\CurrentControlSet\Services\OpenArkDrv64 err:c0000428
[HttpDownload::::operator ()] [INFO] Download failed, err:203, msg:Error transferring http://msdl.blackint3.com:88/download/symbols/ntkrnlmp.pdb/34898958E6070CE1E0B4F363528E1F291/ntkrnlmp.pdb - server replied: Not Found
[Kernel::ParseKernelSymbol] [ERR] LoadSymbol: C:\Users\12561\AppData\Roaming\OpenArk\symbols\ntkrnlmp.pdb\34898958E6070CE1E0B4F363528E1F291\ntkrnlmp.pdb err
[Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\12561\AppData\Roaming\OpenArk\symbols\win32k.pdb\7BAD1A903050A647A0C3B6CE172545001\win32k.pdb
[Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\12561\AppData\Roaming\OpenArk\symbols\win32kbase.pdb\43F01AA539B8EF7FFA9E53F4938107211\win32kbase.pdb
[Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\12561\AppData\Roaming\OpenArk\symbols\win32kfull.pdb\8C27D227ABC18B48FC1D42984DA96BB31\win32kfull.pdb
[Kernel::onEnterKernelMode] [INFO] InstallDriver with new workaround.
[Kernel::onEnterKernelMode] [ERR] InstallDriver C:\Users\12561\AppData\Roaming\OpenArk\kernel\OpenArkDrv64.sys err

@tao1256
Try v1.3.4, join QQ group to contact me if still failed.

If you encounter this situation, please ensure that your system has the latest patches.