按照上面那位大哥说的"hzqst 把你自己进程的PsIsProtectedProcess里的保护位也置1", 我把自己设置成保护了, 注入的时候debugview里面显示下面的信息, 大概意思就是我没微软的签名, 呵呵了, 这还能有解吗? 00000010 44.31887817 ****************************************************************** 00000011 44.31889343 * This break indicates this binary is not signed correctly: \Device\HarddiskVolume2\Users\Public\test_inject64.dll 00000012 44.31889725 * and does not meet the system policy. 00000013 44.31890106 * The binary was attempted to be loaded in the process: \Device\HarddiskVolume2\Windows\System32\services.exe 00000014 44.31890869 * This is not a failure in CI, but a problem with the failing binary. 00000015 44.31890869 * Please contact the binary owner for getting the binary correctly signed. 00000016 44.31891251 ******************************************************************
我是注services.exe, 把services.exe的保护去掉, 注入依然提示签名不对,我那个dll是有自己的签名但没微软签名 [\\DESKTOP-SSM8QD9] 00000000 0.00000000 BlackBone: OS version 10.0.14393.0.1198 - 0xa00 00000001 0.00467352 BlackBone: PDE_BASE: FFFFFBFDC0000000, PTE_BASE: FFFFFB8000000000 00000002 0.00892114 BlackBone: Dynamic search status: SSDT - SUCCESS, ExRemoveTable - SUCCESS 00000003 10.32149410 ****************************************************************** 00000004 10.32151127 * This break indicates this binary is not signed correctly: \Device\HarddiskVolume2\Users\Public\test_inject64.dll 00000005 10.32151318 * and does not meet the system policy. 00000006 10.32151794 * The binary was attempted to be loaded in the process: \Device\HarddiskVolume2\Windows\System32\services.exe 00000007 10.32152081 * This is not a failure in CI, but a problem with the failing binary. 00000008 10.32152462 * Please contact the binary owner for getting the binary correctly signed. 00000009 10.32152653 ******************************************************************