BlackINT3 / OpenArk

The Next Generation of Anti-Rookit(ARK) tool for Windows.
https://openark.blackint3.com
GNU Lesser General Public License v2.1
8.29k stars 835 forks source link

1.3.2版本进入内核模式失败 #155

Closed newUnityCoder closed 7 months ago

newUnityCoder commented 7 months ago

系统版本:Windows 10 专业版 版本号:22H2 报错信息: [OpenArk::onActionCheckUpdate] [INFO] requset server:http://file.blackint3.com:88/openark/version.txt [OpenArk::onActionCheckUpdate::::operator ()] [INFO] local appver:1.3.2, build:202311110134 [OpenArk::onActionCheckUpdate::::operator ()] [INFO] server responsed:{ "err": 0, "appver": "1.3.2", "appbd": "202311110134", "appcl": "6L+b56iL5aKe5by677ya5aKe5YqgUFBM44CB5YaF5a2Y5omr5o+P44CB57q/56iL566h55CG44CB5qih5Z2X5Y246L2944CB5Y+l5p+E5o+Q5p2D562J5ZCE56eN5Yqf6IO9CuWGheaguOWinuW8uu+8muWinuWKoOemgeeUqC/lkK/nlKjlm57osIPvvIxEdW1w6amx5Yqo44CB5raI5oGv6ZKp5a2Q44CB5by65Yig5paH5Lu244CB5paH5Lu2L+azqOWGjOihqOeuoeeQhuOAgeWQr+WKqOmhueOAgeiuoeWIkuS7u+WKoeOAgeacjeWKoeeuoeeQhuetieWQhOenjeWKn+iDvQrnlYzpnaLlop7lvLrvvJrkvJjljJZVSe+8jOWkp+W5heaPkOWNh+a1geeVheaApwrmlK/mjIHmnIDmlrBXaW4xMQpCVUfkv67lpI3vvIzov5jmnInlhbblroPlvojlpJrmnKrmj5Dlj4rnmoTlip/og70KS2VlcCBTaW1wbGUsIEtlZXAgRXZvbHV0aW9uYXJ5IQotLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0KSW1wb3ZlZCBwcm9jZXNzIG1hbmFnZXI6IEFkZGVkIFBQTCxNZW1vcnlTY2FuLFRocmVhZCx1bmxvYWQgbW9kdWxl44CBY2hhbmdlIGhhbmRsZSBhY2Nlc3MgZXRjLgpJbXBvdmVkIGtlcm5lbCBtYW5hZ2VyOiBBZGRlZCBrZXJuZWwgZmVhdHVyZXMsIGVuYWJsZS9kaXNhYmxlIGNhbGxiYWNrLCBEdW1wIGRyaXZlcixNZXNzYWdlSG9vayxGb3JjZURlbGV0ZSxGaWxlL1JlZy9Cb290IG1hbmFnZXIgZXRjLgpJbXByb3ZlZCBVSSBzdWJzdGFudGlhbGx5LgpTdXBwb3J0IHdpbjExIGxhdGVzdCByZWxlYXNlLgpCdWdmaXhlZCBhbmQgbWFueSBvdGhlciB1bm1lbnRpb25lZCBmZWF0dXJlcy4K", "appurl": "https://github.com/BlackINT3/OpenArk/releases" }

[OpenArk::onActionCheckUpdate::::operator ()] [INFO] OpenArk is latest. [UNONE::ObLoadDriverW] [ERR] NtLoadDriver service:\Registry\Machine\System\CurrentControlSet\Services\OpenArkDrv64 err:c0000603 [UNONE::ObLoadDriverW] [ERR] NtLoadDriver service:\Registry\Machine\System\CurrentControlSet\Services\OpenArkDrv64 err:c0000365 [Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\Lin\AppData\Roaming\OpenArk\symbols\ci.pdb\5237AA90C52BD39ABA76BC76BE10B4551\ci.pdb [Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\Lin\AppData\Roaming\OpenArk\symbols\fltMgr.pdb\C6B7358770920641714F8F39943309AC1\fltMgr.pdb [Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\Lin\AppData\Roaming\OpenArk\symbols\netio.pdb\4EE18C895B06AFCE34AC7F0F7C5862E31\netio.pdb [Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\Lin\AppData\Roaming\OpenArk\symbols\ntkrnlmp.pdb\606FF669409B00F7FC8C61A9C16701291\ntkrnlmp.pdb [Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\Lin\AppData\Roaming\OpenArk\symbols\win32k.pdb\4861D9D8CC375CC7E28E23C9A6E302D71\win32k.pdb [Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\Lin\AppData\Roaming\OpenArk\symbols\win32kbase.pdb\3F12A2CAFDE495F473DA7F57EAC61AB41\win32kbase.pdb [Kernel::ParseKernelSymbol] [INFO] PDB: C:\Users\Lin\AppData\Roaming\OpenArk\symbols\win32kfull.pdb\151C3FD156383785149071174DFF74601\win32kfull.pdb [Kernel::onEnterKernelMode] [INFO] InstallDriver with new workaround. [Kernel::onEnterKernelMode] [ERR] InstallDriver C:\Users\Lin\AppData\Roaming\OpenArk\kernel\OpenArkDrv64.sys err