A forum for reverse engineering, OS internals and malware analysis 

Forum for discussion about kernel-mode development.
 #5187  by Vrtule
 Sun Feb 27, 2011 3:07 pm
The win32k.sys is not listed in Windows Internals as driver protected by PG. I hooked it several times and never encountered any problems with PG, so it seems that the driver is currently not protected.
 #5411  by RBCC
 Thu Mar 10, 2011 4:24 pm
I am trying to modify the black background boot background. I notice that MS has used patchguard on that file. Is there a way to shutdown pg do my edits then start pg again? I really don't want to bypass it, just shut it down. Thank you, John :D :geek: :arrow:
 #5486  by Fyyre
 Tue Mar 15, 2011 9:31 pm
RBCC wrote:I am trying to modify the black background boot background. I notice that MS has used patchguard on that file. Is there a way to shutdown pg do my edits then start pg again? I really don't want to bypass it, just shut it down. Thank you, John :D :geek: :arrow:
If error occur right after BCD screen (boot selection), resulting black screen w/ error message... problem is --> winload.exe If problem occur ~3s (-/+ 1.5s, machine depending...) after display of Windows 'loading screen' resulting in BSOD --> problem is PatchGuard (ntoskrnl.exe).

-Fyyre