Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Critical Issue: WdFilter.sys Driver Still Running After Applying the Script (Confirmed in System Informer)

Abierto
#5 1 comentario 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
5/5
Tiempo estimado
Más de una semana
Aptitud para principiantes
30/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
powershell

Línea de trabajo

Start by reproducing the script's behavior on Windows 11 25H2 and inspect the step that deletes the CurrentControlSet\Services\WdFilter registry key. Use System Informer to verify whether WdFilter.sys and its minifilter context remain active after the script runs. Done means establishing a supported, safe outcome without a BSOD and documenting the verification results.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

The WdFilter.sys kernel driver remains fully active** after running the script. I personally verified this using System Informer (formerly Process Hacker), where the driver can be seen loaded in memory with its minifilter context still operational.

This means that, although the script deletes its registry key (CurrentControlSet\Services\WdFilter), the system does not unload the driver from RAM. Therefore, **the system's real-time file-system protection is still running in the kernel.
Is there a safe way to disable WdFilter.sys without causing a Blue Screen of Death (BSOD)?
I am using Windows 11 version 25H2. 26200.9278

Lenguaje dominante
PowerShell
Estrellas
130
Forks
21
Métricas de merge de PR
Sin PR fusionados en 30 d

Preparar el entorno

Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de zoicware/DefenderProTools

Todos los issues de zoicware/DefenderProTools

Issues similares

Más issues de Operating Systems

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.