вы все еще верите написанному кириллицей ?
Насколько корректна диагностика UNKNOWN для win32k_sdt:Shadow SDT: 9D97E000, limit 339win32k_sdt[318] (NtUserAttachThreadInput) hooked, addr 88740D20 UNKNOWNwin32k_sdt[402] (NtUserGetAsyncKeyState) hooked, addr 8A110758 UNKNOWNwin32k_sdt[434] (NtUserGetKeyboardState) hooked, addr 8A1106C0 UNKNOWNwin32k_sdt[436] (NtUserGetKeyState) hooked, addr 886D6708 UNKNOWNwin32k_sdt[448] (NtUserGetRawInputData) hooked, addr 8A111388 UNKNOWNwin32k_sdt[490] (NtUserMessageCall) hooked, addr 88B5F438 UNKNOWNwin32k_sdt[508] (NtUserPostMessage) hooked, addr 8A111D78 UNKNOWNwin32k_sdt[509] (NtUserPostThreadMessage) hooked, addr 88B5F4C0 UNKNOWNwin32k_sdt[585] (NtUserSetWindowsHookEx) hooked, addr 8873B3C0 UNKNOWNwin32k_sdt[588] (NtUserSetWinEventHook) hooked, addr 8873B6B0 UNKNOWNhttp://yadi.sk/d/jjQR8UaKGuvB2
well, if you don`t trust to my tool - you always can check what happens with windbgit seems that your machine has some nasty AV with "rich GUI" who try to protect itself - in your case this is symantec endpoint protection
Этот комментарий был удален администратором блога.
Насколько корректна диагностика UNKNOWN для win32k_sdt:
ОтветитьУдалитьShadow SDT: 9D97E000, limit 339
win32k_sdt[318] (NtUserAttachThreadInput) hooked, addr 88740D20 UNKNOWN
win32k_sdt[402] (NtUserGetAsyncKeyState) hooked, addr 8A110758 UNKNOWN
win32k_sdt[434] (NtUserGetKeyboardState) hooked, addr 8A1106C0 UNKNOWN
win32k_sdt[436] (NtUserGetKeyState) hooked, addr 886D6708 UNKNOWN
win32k_sdt[448] (NtUserGetRawInputData) hooked, addr 8A111388 UNKNOWN
win32k_sdt[490] (NtUserMessageCall) hooked, addr 88B5F438 UNKNOWN
win32k_sdt[508] (NtUserPostMessage) hooked, addr 8A111D78 UNKNOWN
win32k_sdt[509] (NtUserPostThreadMessage) hooked, addr 88B5F4C0 UNKNOWN
win32k_sdt[585] (NtUserSetWindowsHookEx) hooked, addr 8873B3C0 UNKNOWN
win32k_sdt[588] (NtUserSetWinEventHook) hooked, addr 8873B6B0 UNKNOWN
http://yadi.sk/d/jjQR8UaKGuvB2
well, if you don`t trust to my tool - you always can check what happens with windbg
ОтветитьУдалитьit seems that your machine has some nasty AV with "rich GUI" who try to protect itself - in your case this is symantec endpoint protection
Этот комментарий был удален администратором блога.
ОтветитьУдалить