Process Hacker and Windows discussion

 
Verifier.exe

Security verification failure

16 Mar 2016 09:51

kprocesshacker.sys security verification failed with verifier.exe in Windows 7 /64-bit

Verifier.exe? Open cmd.exe and it is there. See Microsoft documentation for driver verification.
 
User avatar
wj32
Founder
Posts: 948
Joined: 17 Jan 2011 05:19
OS: Windows
Location: Australia
Contact:

Re: Security verification failure

16 Mar 2016 10:50

This is expected. Why are you using verifier on KPH?
 
Guest

Re: Security verification failure

16 Mar 2016 23:12

This is expected. Why are you using verifier on KPH?
I have detected multiple intrusions. I wonder how they are done because firewall didn't show anything very weird. I have been checking drivers.
The firewall driver didn't pass security tests. The signer of the firewall is known to sign spyware too.

Another suspicious driver found was kprocesshacker.sys
 
User avatar
wj32
Founder
Posts: 948
Joined: 17 Jan 2011 05:19
OS: Windows
Location: Australia
Contact:

Re: Security verification failure

17 Mar 2016 02:49

If you haven't used Process Hacker, then it's probably malware that's using the driver.
 
Verifier.exe

Re: Security verification failure

19 Mar 2016 10:06

"This is expected."
Why do you expect this? In 32-bit Vista verifier.exe finds no problem. (I thought the driver is just buggy in 64-bit)

I found multiple anomalies in the windows firewall rules with this:
http://www.binisoft.org/wfc.php Anything was allowed to pretend to be the Core Networking.

There were multiple crashes with verifier.exe until there weren't. No kernel dumps and the system restore points were gone too.
 
User avatar
dmex
Admin
Posts: 1555
Joined: 17 Jan 2011 05:43
Location: Australia

Re: Security verification failure

19 Mar 2016 10:19

I found multiple anomalies in the windows firewall rules with this:
http://www.binisoft.org/wfc.php Anything was allowed to pretend to be the Core Networking.

There were multiple crashes with verifier.exe until there weren't. No kernel dumps and the system restore points were gone too.
How is that related to the KPH driver?