BlackINT3 / OpenArk

The Next Generation of Anti-Rookit(ARK) tool for Windows.
https://openark.blackint3.com
GNU Lesser General Public License v2.1
8.29k stars 835 forks source link

"CopyTo..." function in "Kernel Storage" does not use highest privilege. #193

Open PACHAKUTlQ opened 5 days ago

PACHAKUTlQ commented 5 days ago

In "Kernel Storage", the "Force Delete" (in the right-click menu) runs with high privilege possible, so I can delete protected files. However, the "CopyTo..." function (in the right-click menu) does not use high privilege. When trying to copy the backup of a force-deleted protected file back to its original place, I got a fail of "You don't have permission to save in this location.", meaning that this does not run with high privilege as "Force Delete" does.