• XSS.stack #1 – первый литературный журнал от юзеров форума

Crypt Service | FUD | Persistence | NET/Native | Ring3 Unhook | Scanner

В этой теме можно использовать автоматический гарант!

Complex12

CD-диск
Забанен
Регистрация
19.05.2020
Сообщения
11
Реакции
-3
Пожалуйста, обратите внимание, что пользователь заблокирован
Пожалуйста, обратите внимание, что пользователь заблокирован
Hello , just a question , how did you unhook ring3 with c# ? which winapi you are using? and for which AV engine does it works?
 
Пожалуйста, обратите внимание, что пользователь заблокирован
[QUOTE = "koeir, post: 229605, member: 182916"]
Hello, just a question, how did you unhook ring3 with c #? which winapi you are using? and for which AV engine does it works?
[/ QUOTE]
works with avast bitdefender avg
 
[QUOTE = "Complex12, post: 230526, member: 197617"]
[QUOTE = "koeir, post: 229605, member: 182916"]
Hello, just a question, how did you unhook ring3 with c #? which winapi you are using? and for which AV engine does it works?
[/ QUOTE]
works with avast bitdefender avg
[/ QUOTE]

So it doesn't work with others? and how did you unhook the AV module? by restoring bytes method?
and how would you know the original hooked bytes? from where you got RVA? from the disk or PE itself?
Explain more please.
 


Напишите ответ...
Верх