搜索资源列表
1
- delphi的驱动 功能是恢复ssdt的地址.-delphi functions is to restore the drive ssdt address.
biostelnet
- 向BIOS中植入模块,HOOK中断向量表,HOOK NTLDR加载过程以及HOOK内核函数,SSDT hook。-Add module into bios,HOOK IVT,HOOK NTLDR loder process and hook knrnel function,just as SSDT HOOK
SSDTdemo
- 驱动文件ssdt恢复的实例,不错的源码。-ssdt examples of recovery, a good source.
reSSDT
- 恢复SSDT突破主动防御,基于c++实现。-Breakthrough initiative to restore SSDT defense, c++ to achieve.
Ring0
- Ring0中Hook SSDT防止进程被结束
Miss920
- Miss920程序行为监视器,运用SSDT HOOK技术,可以简单有效的监控程序行为,现在已经实现了进程监控,文件监控,注册表监控,并且可以有效快捷地进行二次开发。-Miss920 monitor program behavior, the use of SSDT HOOK technology, can be simple and effective monitoring of program behavior, the proces
Registry_protection
- 在内核状态下拦截注册表操作,保护您的注册表不受病毒和*修改。主要是通过ssdt hook实现,含有完整的代码,包括与应用层通信,和界面代码.-State in the core to intercept registry operation to protect you from viruses and Trojan registry modifications. Mainly through the realization of s
Process_protection
- 基于ssdt hook 的进程保护,防止自己的进程被恶意关闭。包含应用层与应用层通信的代码-based on ssdt hook the process of protection against their own process of being shut down malicious. Contains application-layer and application layer communication code
SSDThooksample
- 比较流行的 hook ssdt技术 系统内核钩子-Hook ssdt more popular hook-core technology systems
SSDTunhook
- SSDT UNHOOK DELPHI CODE
_ssdt
- SSDT查看-Show SSDT ........................
cmcark_cw.0.2.2.9.12
- A rootkit detector that allows you to remove the SSDT hooks maden in the OS kernel.
DelphiRESSDT
- 就是delphi还原SSDT,效果还不错-Delphi is to restore the SSDT, the results were good
SSDT_Unhook
- SSDT恢复源代码,恢复被挂钩的SSDT(系统服务调用函数表)-SSDT unhook sourcecode
Ring0RestoreSSDTShadow
- Ring0下恢复SSDT Shadow,是一个完整的VC工程,可以学习学习。-Ring0 resume SSDT Shadow
Ring0HOOKSSDTReg
- DDK开发的在Ring0中通过HOOK SSDT,实现对注册表监控-DDK development in Ring0 through HOOK SSDT, to realize the Registry Monitor
SSTD.ZIP
- SSDT HOOK Source code
driver
- 恢复ssdt 躲过杀软查杀,有利于*进一步存活!-Soft-recovery ssdt escape the killing killing are conducive to the further survival of Trojan!
SyFbt
- 杀Inline-Hook SSDT的进程的C++源码,DDK编写。可以杀冰刃,无法杀IL-Inline-Hook SSDT kill the process C++ source code, DDK preparation. Kill Frostsaber can not kill IL
SSDT_Helper_src
- 通过搜索 SSDT 并和 ZwSystemDebugControl 获取的内容相比较 * 找出不同的SSDT项-通过搜索 SSDT 并和 ZwSystemDebugControl 获取的内容相比较 * 找出不同的SSDT项