吾爱破解 - 52pojie.cn

 找回密码
 注册[Register]

QQ登录

只需一步,快速开始

查看: 11346|回复: 7
收起左侧

[OllyDbg 1.x Plugin] ScyllaHide 1.2

  [复制链接]
A-new 发表于 2014-9-29 12:45
海风牛的sod好久没更新了,看到这个也不知道怎么样大家试试
这个有od2.X、IDA、x64_dbg 的插件一起发这里算了,不上传了,给链接
ScyllaHide is an open-source x64/x86 usermode Anti-Anti-Debug library. It hooks various functions in usermode to hide debugging. This will stay usermode! For kernelmode hooks use TitanHide.

Debugger Hiding:
- PEB - BeingDebugged, NtGlobalFlag, Heap Flags
- NtSetInformationThread - ThreadHideFromDebugger
- NtQuerySystemInformation - SystemKernelDebuggerInformation, SystemProcessInformation
- NtQueryInformationProcess - ProcessDebugFlags, ProcessDebugObjectHandle, ProcessDebugPort, ProcessBasicInformation, ProcessBreakOnTermination, ProcessHandleTracing
- NtSetInformationProcess - ProcessBreakOnTermination, ProcessHandleTracing
- NtQueryObject - ObjectTypesInformation, ObjectTypeInformation
- NtYieldExecution
- NtSetDebugFilterState
- NtUserBuildHwndList - EnumWindows
- NtUserFindWindowEx - FindWindowA/W, FindWindowExA/W
- NtUserQueryWindow
- NtClose
- NtCreateThreadEx
- BlockInput
- Remove Debug Privileges
- OutputDebugStringA - OutputDebugStringW

Timing Hooks:
- GetTickCount
- GetTickCount64
- GetLocalTime
- GetSystemTime
- NtQuerySystemTimeHook
- NtQueryPerformanceCounter

Special functions:
- prevent Thread creation - for protectors like Execryptor. Only use if you know what you are doing !
- Malware RUNPE Unpacker - Hooks NtResumeThread and terminates + dumps the process created by malware

Protecting and Stealthing DRx (Hardware Breakpoints):
- NtGetContextThread
- NtSetContextThread
- KiUserExceptionDispatcher (only x86)
- NtContinue (only x86)

Hooks:
- Stealth hooks for 32-bit targets (Tested against Themida/VMProtect)
lOllyDbg 1.xx Plugins :https://tuts4you.com/download.php?view.3596
OllyDbg 2.xx Plugins :https://tuts4you.com/download.php?view.3560
IDA Plugins:https://tuts4you.com/download.php?view.3597
x64_dbg Plugins:https://tuts4you.com/download.php?view.3598
ScyllaHide.JPG

免费评分

参与人数 2热心值 +2 收起 理由
a1014 + 1 鼓励转贴优秀软件安全工具和文档!
Syer + 1 鼓励转贴优秀软件安全工具和文档!

查看全部评分

发帖前要善用论坛搜索功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。

Godfather.Cr 发表于 2014-9-29 13:06
还是等有大牛汉化吧
E文是硬伤啊
軒雲閣 发表于 2014-9-29 13:31
最好能打包提供就好了,不过还是要谢谢楼主........
manbajie 发表于 2014-9-30 09:48
kkkwz 发表于 2014-9-30 11:28
a牛最近身体怎嘛样,好些了,如果以后身体不适,建议你来这个地方看,河北保定满城第二中医院,找武占元大夫,医术绝对可以,论中医排中国前五水平,医术比华佗不差
xxhaishixx 发表于 2015-1-4 02:29
希望汉化啊啊
kevinmou 发表于 2015-4-23 15:23
这个如何到X x64_dbg里呀?我放了没有反应。在x64_dbg里的Plugins菜单里,看不到。
evedeity 发表于 2017-1-29 21:39
这个要怎么在OD里用啊,我把这个都复制到plugin里面了也显示不出来呀
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则

返回列表

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-11-16 14:44

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表