|
|
@ -95,4 +95,8 @@ BEDaisy checks the IRP's of every single loaded driver. Below is the checks done
|
|
|
|
|
|
|
|
|
|
|
|
As you can see `0xFFFFF8049905E400` is `DxgkCreateClose`.
|
|
|
|
As you can see `0xFFFFF8049905E400` is `DxgkCreateClose`.
|
|
|
|
|
|
|
|
|
|
|
|
<img src="https://imgur.com/rnkZ7Sl.png"/>
|
|
|
|
<img src="https://imgur.com/rnkZ7Sl.png"/>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
As you can see `0xFFFFF80498F516A0` is `DxgkDeviceIoctl`
|
|
|
|
|
|
|
|
<img src="https://imgur.com/m9YEp50.png"/>
|