ELAM驱动程序(优先启动反病毒驱动程序)

本文介绍了Windows 8及更高版本中引入的ELAM驱动,这是一种早期启动的反病毒驱动,旨在在其他驱动加载之前进行恶意软件检查。内容涵盖ELAM驱动的安装、初始化、回调机制,以及如何注册和卸载。ELAM驱动需要特定的微软签名,并且不能包含设备对象,只能通过非PNP方式安装。
摘要由CSDN通过智能技术生成

WDK中ELAM驱动示例
从MSDN中摘抄的关于这种驱动的简介。链接

简介

  从Windows8起,微软为反病毒软件增加的新的驱动类型:Early-Lunch Anti-Malware驱动(ELAM驱动)。这种驱动启动的比其他boot类型的驱动更加早并且提供了回调向ELAM驱动通知正在被加载的普通boot型驱动,以让反病毒软件有机会在boot型驱动加载前检测并决定是否加载这些驱动。

前提条件

  ELAM驱动需要具有WHQL签名。微软要求ELAM厂商是Microsoft Virus Initiative (MVI) 或者是Virus Information Alliance (VIA)项目的成员。ELAM驱动需要有微软针对ELAM的特殊签名并且不能导入任何Dll。

ELAM驱动的安装

  ELAM驱动的启动类型为SERVICE_BOOT_START,表示驱动由winload加载并随内核的初始化启动。启动组(LoadOrderGroup )则需要设置为Early

  • 1
    点赞
  • 3
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
Driver Signature Enforcement Overrider Windows測試模式 (win7 64位可用) 無須重啟F8 可去除右下測試模式水印 Enable Test Mode Disable Test Mode Sign a System File ------------------------ Sometimes, the watermark still exists on the desktop after reboot, you need to manually rebuild the MUI cache by: Press key "R" in removeWatermark; Or run "mcbuilder.exe". Remove all Watermark on desktop. Such as "Evaluation Copy", "For testing purpose only", "Test Mode", "Safe Mode". Support: Windows Vista /Server 2008 /Windows 7, 64bit(x64) / 32bit(x86), All Service Pack & all language of Windows. 2009.05.09 V0.8 Download Link 1: RemoveWatermark_20090509.zip http://soft3.wmzhe.com/download/deepxw/RemoveWatermark_20090509.zip Download Link 2: RemoveWatermark_20090509.zip http://soft2.wmzhe.com/download/deepxw/RemoveWatermark_20090509.zip Download Link 3: RemoveWatermark_20090509.zip (Click the link to download) http://filekeeper.org/download/deepxw/RemoveWatermark/RemoveWatermark_20090509.zip It is a universal patch! Without language limited, Supports all language of windows! And without limited of Service Pack. This tool provides two ways to remove the watermark. * The default method, modify user32.dll.mui. This method is safe for all Windows. In 64-bit Vista / Windows 7, It needs Re-Build MUI cache, this will take a few minutes, please wait. * Method 2: modifies user32.dll. 100% remove all watermark. (Run program with argument "-enforce") But don't use Method 2 in Windows 7 6956 / 7000 or later version. It likes a unknown bug in these version of Windows. Any modification with user32.dll in Windows 7 6956 will cause application fail to run in compatibility mode. Notes: 1, Can operate in normal mode. Do not need to enter safe mode. 2, Choose the corresponding patch based on you Windows: For 32bit(x86): RemoveWatermarkX86.exe For 64bit(x64): RemoveWatermarkX64.exe 3, If "Test Mode" still exists on the desktop after reboot, you can run RemoveWatermark and Press key "R" to rebuild MUI cache. Or open command prompt as administrator, run mcbuilder.exe again, then restart computer. 4, Command line / argument usages: -silent Patch in silent mode. -view View the string of user32.dll.mui, don't patch file.
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值