这里是一个pte hook,虚拟机环境是1809.虚拟机加载后无法启动,nointegritychecks Yes
testsigning Yes.麻烦大牛解惑,项目代码在附件>bcdedit /enumWindows 启动管理器
--------------------
device partition=\Device\HarddiskVolume1
path \EFI\Microsoft\Boot\bootmgfw.efi
description Windows Boot Manager
locale zh-CN
timeout 30
Windows 启动加载器
-------------------
device partition=C:
path \Windows\system32\winload.efi
description Windows 10
locale zh-CN
displaymessageoverride Recovery
recoveryenabled Yes
nointegritychecks Yes
testsigning Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
osdevice partition=C:
systemroot \Windows
nx OptIn
bootmenupolicy Standard
debug Yesdumpbin -headers C:\Users\Administrator\Desktop\hack\MyDriver1\x64\Debug\MyDriver1\MyDriver1.sysPE signature found
File Type: EXECUTABLE IMAGE
FILE HEADER VALUES 8664 machine (x64) 6 number of sections 69840EE4 time date stamp Thu Feb 5 11:30:44 2026 0 file pointer to symbol table 0 number of symbols F0 size of optional header 22 characteristics Executable Application can handle large (>2GB) addresses
OPTIONAL HEADER VALUES 20B magic # (PE32+) 14.43 linker version 1400 size of code 1600 size of initialized data 0 size of uninitialized data 1190 entry point (0000000140001190) DriverEntry 1000 base of code 140000000 image base (0000000140000000 to 0000000140007FFF) 1000 section alignment 200 file alignment 10.00 operating system version 10.00 image version 10.00 subsystem version 0 Win32 version 8000 size of image 400 size of headers 5379 checksum 1 subsystem (Native) 4160 DLL characteristics High Entropy Virtual Addresses Dynamic base NX compatible Control Flow Guard 100000 size of stack reserve 1000 size of stack commit 100000 size of heap reserve 1000 size of heap commit 0 loader flags 10 number of directories 0 [ 0] RVA [size] of Export Directory 6000 [ 28] RVA [size] of Import Directory 0 [ 0] RVA [size] of Resource Directory 5000 [ B4] RVA [size] of Exception Directory 2400 [ 730] RVA [size] of Certificates Directory 7000 [ 24] RVA [size] of Base Relocation Directory 3348 [ 38] RVA [size] of Debug Directory 0 [ 0] RVA [size] of Architecture Directory 0 [
...(已截断)
---
来源: 看雪论坛
原文链接: https://bbs.kanxue.com/thread-289948.htm
[求助]Pte Hook无法进断点,启动失败
266 浏览
1 回复
槽nim的jb