Show Board Post
  • Current rank: 1 Star. Next Rank at 100 Posts.
    Send a message to shaqun
    ELITE
    shaqun posted on Oct 27, 2018 2:53:24 PM - Report post
     
    I have finally found the reason of SMEP bypass error and trainer functions not working issue reason. Both are related to windows 10 bug on some computers. The trainer is unable to register its own driver because chkernelback.exe having the following issue when it try to register its own kernel driver. Because the following permission issue prevents chkernelback.exe from using Runtimebroker on the system.

    From the event log every time chkernelback.exe is trying to register a driver;

    The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {D63B10C5-BB46-4990-A94F-E40B9D520160}
    and APPID
    {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
    to the user MIKE\real SID (S-1-5-21-783143559-464127781-87900393-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    There are multiple articles and solutions provided on the net for this bug but none of them fixes the problem and I just give up trying to fix it and using the trainer, because it is a pain to fix this issue. The problem is happening on some windows10.