Closed Shhoya closed 4 years ago
Are you using Windows kernel debugger?
Are you using Windows kernel debugger?
Yes, To study, I loaded and debug the driver using VirtualKD. Is this a problem?
Yes, KD uses the same freezing mechanism so it will not work. Switch to a hypervisor based debugger like VMWare's GDB stub.
Hi, i'm newbie.... The "ExHook" test was run on a virtual machine. (Win10 (1809)) The build went well and I loaded the driver via "OSR Loader" but freezing occurred. I checked that HalCallbacks :: Register () freezes while hooking "HalNotifyProcessorFreeze"... The issue is that freezing takes place as soon as you replace "HalPrivateDispatchTable" + 0x1A8 ("HalpTimerNotifyProcessorFreeze") with a hooking function ("HkHalTimerNotifyProcessorFreeze"). Do you know how to solve the problem?
Freeze point: