Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 04-20-2026, 17:38
Hadedx9 Hadedx9 is offline
Friend
 
Join Date: Mar 2025
Location: Syria
Posts: 15
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 12
Thanks Rcvd at 2 Times in 2 Posts
Hadedx9 Reputation: 0
TitanHide Blue Death Screen

hello Friends
Is There any Solution For Blue Death Screen Caused By Starting TitanHide Service , The TitanHide.sys Can Be Loaded In the Memory But The Windows Shows The Blue Death Screen When Starting It ,
I have Tried every Possible Solution and this is the result:
1- On Windows 7 Ultimate SP1 x32 it is loading and the windows accept to start it but after 30 seconds the blue death screen appears this for the TitanHide version 9 and Previous Versions and it not accepting to be loaded in the next versions ,
2- On Windows 7 Ultimate SP1 x64 it is not accepting to start any version of TitanHide (the Blue Death Screen)
3- On Windows XP Proffessional SP3 It accepts to start all the old versions (the Supported versions)
- i Have Enabled Test mode before any attempt to start the service on every OS mentioned here and I Have Tried every Possible tool from Github , Tuts4You ,AT4RE, etc and Tried To Disaple PatchGuard But With No Good result.
So , Anyone Can Help ?
Reply With Quote
  #2  
Old 04-20-2026, 17:44
niculaita's Avatar
niculaita niculaita is offline
Family
 
Join Date: Jun 2011
Location: here
Posts: 1,475
Rept. Given: 1,009
Rept. Rcvd 95 Times in 65 Posts
Thanks Given: 5,429
Thanks Rcvd at 508 Times in 359 Posts
niculaita Reputation: 95
send sys file to sign it
__________________
Decode and Conquer
Reply With Quote
The Following User Says Thank You to niculaita For This Useful Post:
Hadedx9 (04-21-2026)
  #3  
Old 04-20-2026, 18:55
tame_mpeg tame_mpeg is offline
Friend
 
Join Date: Oct 2023
Posts: 21
Rept. Given: 0
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 8
Thanks Rcvd at 22 Times in 10 Posts
tame_mpeg Reputation: 1
I have made use of this for TitanHide before.
https://github.com/thesecretclub/SandboxBootkit
I don't know if it still works with the latest versions of Windows Sandbox but it was very easy to use, maybe give it a go
Reply With Quote
The Following 2 Users Say Thank You to tame_mpeg For This Useful Post:
Hadedx9 (04-21-2026), niculaita (04-21-2026)
  #4  
Old 04-21-2026, 01:19
Hadedx9 Hadedx9 is offline
Friend
 
Join Date: Mar 2025
Location: Syria
Posts: 15
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 12
Thanks Rcvd at 2 Times in 2 Posts
Hadedx9 Reputation: 0
Quote:
Originally Posted by niculaita View Post
send sys file to sign it
Thanks,
There it is :
https://www.mediafire.com/file/cklvsprwcx8r4p9/x64.rar/file
Reply With Quote
  #5  
Old 04-21-2026, 03:53
Hadedx9 Hadedx9 is offline
Friend
 
Join Date: Mar 2025
Location: Syria
Posts: 15
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 12
Thanks Rcvd at 2 Times in 2 Posts
Hadedx9 Reputation: 0
Quote:
Originally Posted by tame_mpeg View Post
I have made use of this for TitanHide before.
https://github.com/thesecretclub/SandboxBootkit
I don't know if it still works with the latest versions of Windows Sandbox but it was very easy to use, maybe give it a go
Thank you ❤️
but does it work on VMWare?
Reply With Quote
  #6  
Old 04-21-2026, 04:33
niculaita's Avatar
niculaita niculaita is offline
Family
 
Join Date: Jun 2011
Location: here
Posts: 1,475
Rept. Given: 1,009
Rept. Rcvd 95 Times in 65 Posts
Thanks Given: 5,429
Thanks Rcvd at 508 Times in 359 Posts
niculaita Reputation: 95
https://www.mediafire.com/file/xa7axq5rftsti4y/x64_resigned.rar/file try
but before merge reg, import certif, disable check revocations, Uninstal KB5083769 and restart PC
__________________
Decode and Conquer
Reply With Quote
The Following User Says Thank You to niculaita For This Useful Post:
Hadedx9 (04-21-2026)
  #7  
Old 04-21-2026, 18:23
Hadedx9 Hadedx9 is offline
Friend
 
Join Date: Mar 2025
Location: Syria
Posts: 15
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 12
Thanks Rcvd at 2 Times in 2 Posts
Hadedx9 Reputation: 0
Quote:
Originally Posted by niculaita View Post
https://www.mediafire.com/file/xa7axq5rftsti4y/x64_resigned.rar/file try
but before merge reg, import certif, disable check revocations, Uninstal KB5083769 and restart PC
Thank you❤️
But How to disable check revocations ?
KB5083769 is for windows 11, but i am working on Windows 7 Ultimate SP1 x64 so what i should do before start the service for the Windows 7 OS?

Last edited by Hadedx9; 04-21-2026 at 18:44.
Reply With Quote
  #8  
Old 04-21-2026, 20:11
Hadedx9 Hadedx9 is offline
Friend
 
Join Date: Mar 2025
Location: Syria
Posts: 15
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 12
Thanks Rcvd at 2 Times in 2 Posts
Hadedx9 Reputation: 0
Quote:
Originally Posted by Hadedx9 View Post
Thank you❤️
But How to disable check revocations ?
KB5083769 is for windows 11, but i am working on Windows 7 Ultimate SP1 x64 so what i should do before start the service for the Windows 7 OS?
EDIT :

i have done every thing that written in the "readme.txt" and i have uninstalled these two updates on windows 7 SP1 x64 (KB3033929 , KB4474419),
and i have enabled test mode before starting the service but the same Blue Death Screen still appears ,

So Is there somethng else i should do?
Reply With Quote
  #9  
Old 04-21-2026, 21:49
Sound Sound is offline
Family
 
Join Date: Apr 2016
Location: TaiWan
Posts: 110
Rept. Given: 8
Rept. Rcvd 55 Times in 24 Posts
Thanks Given: 41
Thanks Rcvd at 463 Times in 108 Posts
Sound Reputation: 55
try enter forced signature disabling mode .
Reply With Quote
The Following User Says Thank You to Sound For This Useful Post:
Hadedx9 (04-22-2026)
  #10  
Old 04-22-2026, 01:28
Hadedx9 Hadedx9 is offline
Friend
 
Join Date: Mar 2025
Location: Syria
Posts: 15
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 12
Thanks Rcvd at 2 Times in 2 Posts
Hadedx9 Reputation: 0
Quote:
Originally Posted by Sound View Post
try enter forced signature disabling mode .
Thanks ❤️ i will try it
Reply With Quote
  #11  
Old 05-14-2026, 00:45
Hadedx9 Hadedx9 is offline
Friend
 
Join Date: Mar 2025
Location: Syria
Posts: 15
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 12
Thanks Rcvd at 2 Times in 2 Posts
Hadedx9 Reputation: 0
HI Again ❤️
i have tried a lot of solutions but it did not work if anyone has a solution ❤️
Reply With Quote
  #12  
Old 05-16-2026, 18:06
kernel kernel is offline
Friend
 
Join Date: Oct 2023
Posts: 67
Rept. Given: 0
Rept. Rcvd 23 Times in 18 Posts
Thanks Given: 22
Thanks Rcvd at 85 Times in 40 Posts
kernel Reputation: 23
Quote:
Originally Posted by niculaita View Post
https://www.mediafire.com/file/xa7axq5rftsti4y/x64_resigned.rar/file try
but before merge reg, import certif, disable check revocations, Uninstal KB5083769 and restart PC
You better not adding the fake timestamp. Now windows will not load the driver. Without the fake timestamp there is a way to load.
Reply With Quote
The Following User Says Thank You to kernel For This Useful Post:
niculaita (05-17-2026)
  #13  
Old 05-17-2026, 17:17
Hadedx9 Hadedx9 is offline
Friend
 
Join Date: Mar 2025
Location: Syria
Posts: 15
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 12
Thanks Rcvd at 2 Times in 2 Posts
Hadedx9 Reputation: 0
Quote:
Originally Posted by Sound View Post
lack of lock protection for driver read/write operations.
absence of exception protection when the driver's FindCaveAddress function scans kernel memory or other
enabling VT can also cause conflicts and lead to BSOD occasionally.

There are various causes leading to BSOD. Even if you have entered Windows Test Mode and bypassed PG restrictions,
the most effective solution is to fix issues like those I mentioned in the source code.....

BTW:What do you use the TitanHide driver for?
I am trying to run it to hide my debugger from kernel mode Anti-Debugging Techniques
Reply With Quote
  #14  
Old 05-17-2026, 17:19
Hadedx9 Hadedx9 is offline
Friend
 
Join Date: Mar 2025
Location: Syria
Posts: 15
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 12
Thanks Rcvd at 2 Times in 2 Posts
Hadedx9 Reputation: 0
Quote:
Originally Posted by kernel View Post
You better not adding the fake timestamp. Now windows will not load the driver. Without the fake timestamp there is a way to load.
I am Not Familiar to kernel drivers can you please make it Simple To my Knowledge
Reply With Quote
  #15  
Old 05-18-2026, 00:04
Hadedx9 Hadedx9 is offline
Friend
 
Join Date: Mar 2025
Location: Syria
Posts: 15
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 12
Thanks Rcvd at 2 Times in 2 Posts
Hadedx9 Reputation: 0
Quote:
Originally Posted by kernel View Post
You better not adding the fake timestamp. Now windows will not load the driver. Without the fake timestamp there is a way to load.
How To load It without adding The fake timestamp?
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 07:28.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )