A forum for reverse engineering, OS internals and malware analysis 

Ask your beginner questions here.
 #3245  by marcbuchanan
 Wed Oct 27, 2010 10:53 pm
I was thinking a long time whether I should post this again - now in this forum - because I don't want to be a spammer. So sorry if I annoy anyone - I apologize it for this stupid question:

I wrote a driver which accesses the PageDirectoryEntries in Windows 7 32 Bit PAE - normally they should be something at 0xC0600000 but I got at there only zeros. There is a I want to clear out this question - currently I run 64Bit Win - but this question takes me still some sleep. My reason is that I think that this Win 32 partition has a trojan who relocates the PDT. Is this possible? With MiGetPdeAddress I get another values? What's going on?