Page 1 of 1

Force unload kernel driver

PostPosted:Thu Jul 04, 2019 10:17 pm
by 0xdeadc0de
Hello, I am writing an anti-rootkit tool that has the functionality of force unload on suspect drivers, how to do a force unload driver by kernel?

Re: Force unload kernel driver

PostPosted:Wed Aug 14, 2019 3:47 am
by EP_X0FF
Just do BSOD. Force unloads everything.
The feature you are planning is BSOD generator by design. There is no way to safely unload driver if it not support unloading itself, otherwise just call it driver unload function and pray for no BSOD.