BlackINT3 / OpenArk

The Next Generation of Anti-Rookit(ARK) tool for Windows.
https://openark.blackint3.com
GNU Lesser General Public License v2.1
8.29k stars 835 forks source link

进入内核模式失败 #144

Closed welfareHu closed 8 months ago

welfareHu commented 10 months ago

image [OpenArk::onActionCheckUpdate::::operator ()] [INFO] OpenArk is latest. [Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\welfareHu\AppData\Roaming\OpenArk\symbols\fltMgr.pdb\969A6F3F7B6B03139ED9D16D82046A491\fltMgr.pdb [Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\welfareHu\AppData\Roaming\OpenArk\symbols\netio.pdb\9EE7BD721D3DEF087E3DBC8DD61C95411\netio.pdb [Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\welfareHu\AppData\Roaming\OpenArk\symbols\ntkrnlmp.pdb\6DE4B1C1DC23B687940A233637EF56DC1\ntkrnlmp.pdb [Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\welfareHu\AppData\Roaming\OpenArk\symbols\win32kfull.pdb\4383C79AF165716D8125D4968D91E4551\win32kfull.pdb [UNONE::ObLoadDriverW] [ERR] NtLoadDriver service:\Registry\Machine\System\CurrentControlSet\Services\OpenArkDrv64 err:c0000603 [Kernel::onClickKernelMode] [ERR] InstallDriver C:\Users\welfareHu\AppData\Roaming\OpenArk\kernel\OpenArkDrv64.sys err

ZHANG15210037977 commented 10 months ago

遇到同样问题

[Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\zgj\AppData\Roaming\OpenArk\symbols\fltMgr.pdb\969A6F3F7B6B03139ED9D16D82046A491\fltMgr.pdb [Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\zgj\AppData\Roaming\OpenArk\symbols\netio.pdb\9EE7BD721D3DEF087E3DBC8DD61C95411\netio.pdb [Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\zgj\AppData\Roaming\OpenArk\symbols\ntkrnlmp.pdb\6DE4B1C1DC23B687940A233637EF56DC1\ntkrnlmp.pdb [Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\zgj\AppData\Roaming\OpenArk\symbols\win32kfull.pdb\4383C79AF165716D8125D4968D91E4551\win32kfull.pdb [UNONE::ObLoadDriverW] [ERR] NtLoadDriver service:\Registry\Machine\System\CurrentControlSet\Services\OpenArkDrv64 err:c0000603 [Kernel::onClickKernelMode] [ERR] InstallDriver C:\Users\zgj\AppData\Roaming\OpenArk\kernel\OpenArkDrv64.sys err

ddlong000 commented 10 months ago

经过分析是驱动证书过期了,需要重新驱动签名

SmithAmway commented 10 months ago

同样的问题,请问如何重新驱动签名呢?

BlackINT3 commented 8 months ago

v1.3.2 released.