Driver loaded.
BSODs disabled.
Hook found: NtConnectPort
Hook found: NtCreateFile
Hook found: NtCreateKey
Hook found: NtCreateSection
Hook found: NtCreateThread
Hook found: NtDeleteKey
Hook found: NtDeleteValueKey
Hook found: NtDuplicateObject
Hook found: NtLoadDriver
Hook found: NtOpenFile
Hook found: NtOpenProcess
Hook found: NtOpenSection
Hook found: NtOpenThread
Hook found: NtProtectVirtualMemory
Hook found: NtRenameKey
Hook found: NtRequestWaitReplyPort
Hook found: NtRestoreKey
Hook found: NtSetContextThread
Hook found: NtSetSystemInformation
Hook found: NtSetSystemTime
Hook found: NtSetValueKey
Hook found: NtShutdownSystem
Hook found: NtSuspendProcess
Hook found: NtSuspendThread
Hook found: NtSystemDebugControl
Hook found: NtTerminateJobObject
Hook found: NtTerminateProcess
Hook found: NtTerminateThread
Hook found: NtUnloadKey
Hook found: NtWriteVirtualMemory
Probing 30 function(s) started.
Probing function NtConnectPort(DUDDDDDD) ...
Function NtConnectPort passed the tests.
Probing function NtCreateFile(DDODDDDDDDD) ...
Function NtCreateFile passed the tests.
Probing function NtCreateKey(BDODUDD) ...
NtCreateKey(0x9EF99726, 0xF05BE27E, OBJECT_ATTRIBUTES.ObjectName=0x8FAED965, 0x8D5CDE01, UNICODE_STRING.Buffer=0x8C4B2A2C, 0x88FB230C, 0xE4658455) caused BSOD!
Probing function NtCreateSection(DDODDDD) ...
Function NtCreateSection passed the tests.
Probing function NtCreateThread(DDODDDDD) ...
Function NtCreateThread passed the tests.
Probing function NtDeleteKey(B) ...
NtDeleteKey caused BSOD when its 1st argument was 0xFFFFFFFE.
Probing function NtDeleteValueKey(BU) ...
NtDeleteValueKey(0x8840C091, 0x102B548D) caused BSOD!
Probing function NtDuplicateObject(DDDBDDD) ...
Function NtDuplicateObject passed the tests.
Probing function NtLoadDriver(U) ...
Function NtLoadDriver passed the tests.
Probing function NtOpenFile(DDODDD) ...
Function NtOpenFile passed the tests.
Probing function NtOpenProcess(DDOD) ...
Function NtOpenProcess passed the tests.
Probing function NtOpenSection(BDO) ...
Function NtOpenSection passed the tests.
Probing function NtOpenThread(DDOD) ...
Function NtOpenThread passed the tests.
Probing function NtProtectVirtualMemory(PBDDB) ...
Function NtProtectVirtualMemory passed the tests.
Probing function NtRenameKey(BU) ...
Function NtRenameKey passed the tests.
Probing function NtRequestWaitReplyPort(BDD) ...
Function NtRequestWaitReplyPort passed the tests.
Probing function NtRestoreKey(BDD) ...
NtRestoreKey caused BSOD when its 1st argument was 0xFFFFFFFE.
Probing function NtSetContextThread(PD) ...
Function NtSetContextThread passed the tests.
Probing function NtSetSystemInformation(DDD) ...
Function NtSetSystemInformation passed the tests.
Probing function NtSetSystemTime(DD) ...
Function NtSetSystemTime passed the tests.
Probing function NtSetValueKey(BUDDDD) ...
NtSetValueKey(0x8840C091, 0x102B548D, 0x6C9B2353, 0x54172F7D, 0xE5B1A3ED, 0xFF381560) caused BSOD!
Probing function NtShutdownSystem(D) ...
Function NtShutdownSystem passed the tests.
Probing function NtSuspendProcess(P) ...
Function NtSuspendProcess passed the tests.
Probing function NtSuspendThread(PD) ...
Function NtSuspendThread passed the tests.
Probing function NtSystemDebugControl(DDDDDD) ...
Function NtSystemDebugControl passed the tests.
Probing function NtTerminateJobObject(DD) ...
Function NtTerminateJobObject passed the tests.
Probing function NtTerminateProcess(PD) ...
Function NtTerminateProcess passed the tests.
Probing function NtTerminateThread(PD) ...
Function NtTerminateThread passed the tests.
Probing function NtUnloadKey(O) ...
Function NtUnloadKey passed the tests.
Probing function NtWriteVirtualMemory(PDDDB) ...
Function NtWriteVirtualMemory passed the tests.
Probing complete.
--------------------------------------------------------------------
1.CFP V3(Blue)通過測試!(5/5)
2.uphclean (Red)通過測試!(1/1)
他是微軟出的加速關機程式!
3.EQSecure V3.4 (Green)未通過下面的hook (19/24)
1.Probing function NtCreateKey(BDODUDD) ...
NtCreateKey(0x9EF99726, 0xF05BE27E, OBJECT_ATTRIBUTES.ObjectName=0x8FAED965, 0x8D5CDE01, UNICODE_STRING.Buffer=0x8C4B2A2C, 0x88FB230C, 0xE4658455) caused BSOD!
2.Probing function NtDeleteKey(B) ...
NtDeleteKey caused BSOD when its 1st argument was 0xFFFFFFFE.
3.Probing function NtDeleteValueKey(BU) ...
NtDeleteValueKey(0x8840C091, 0x102B548D) caused BSOD!
4.Probing function NtRestoreKey(BDD) ...
NtRestoreKey caused BSOD when its 1st argument was 0xFFFFFFFE.
5.Probing function NtSetValueKey(BUDDDD) ...
NtSetValueKey(0x8840C091, 0x102B548D, 0x6C9B2353, 0x54172F7D, 0xE5B1A3ED, 0xFF381560) caused BSOD!
[ 本帖最後由 Roger 於 2007-9-20 18:39 編輯 ]