Hmily 发表于 2010-4-1 12:54

HideSyser Plugin 1.94

Syser is a wonderfull tool but not have a lot of plugins for it. I make one plugin (in a beta stage) that have 2 functions:

- Use "gta" or "getaddr" command in Syser control panel for get a kernel function memory address, ex."gta DbgPrint" and you get the memory entry point. Only works with Kernel exported functions (Kernel and Hal).

- Use "hide" command to hide Syser against NtCreateFile (a lot of programs try find Syser using it)
- Use "unhide" command to unhide Syser against NtCreateFile

It is a POC. Only tested in Windows XP Proffesional SP2/SP3 in VMWare and without VMWare with success

For install put in the %SystemFolder%\drivers\plugin\386i and reboot Syser

Hmily 发表于 2010-4-1 12:54

老东西,存档下...

不舍远走 发表于 2010-4-1 13:11

下载一份 看看。

Alar30 发表于 2010-4-1 13:37

好像卡卡改过一个版本
呵呵

natyou 发表于 2010-4-1 15:30

good tool ,thanks
页: [1]
查看完整版本: HideSyser Plugin 1.94