搜索资源列表
20021230104551_mgyz
- 魔高一丈的源代码,使用了hook技术,可控制所有的桌面程序都隐藏或恢复--source code of "the devil climbs ten", has used the hook technology, may control all procedure on disktop hide or restore
Bypassing_SDT_Restore
- Bypassing SDT Restore source code
socks4bot
- socks 4 bot +SDT Restore, svchost inject, copy to system dir-socks 4 bot +SDT Restore, svchost inject, copy to system dir
200622314131788
- 键盘全记录密码盗取发送程序 本程序为学习Liu_mazi的例程而完成,StartEXE目录中为安装主程序,主程序编译时会把钩子链接库文件打包进来,运行时会把安还原到系统中,然后在系统中安装一个WH_GETMESSAGE钩-Full Record keyboard to send the password stealing program for the study of this program were completed Liu_mazi routine, StartEXE directo
arktool
- 1、息钩子监视:列举系统上的消息钩子。 2、块加载监视:列举系统上加载的所有内核模块 3、SSDT监视:通过得到原始的SSDT地址来得到被恶意程序HOOK的API以及恢复SSDT 4、注册表保护:对一些重要的注册表项进行保护,防止恶意程序对其进行修改。 5、隐藏进程检测:检测出系统中隐藏的进程。 6、隐藏端口检测:检测出系统中隐藏的端口。 7、进程强杀:能够*系统中的对自身保护的恶意进程。-1, the interest rate hook monitor
exploreDLL
- 保存、恢复桌面图标部署,windows dll 挂钩技术-Save and restore desktop icon Deployment
erasehooker
- 加载驱动,扫描并恢复系统所有函数的HOOK驱动-Restore the system drive all functions of the HOOK
SSDT-Recovery-View-Tool
- SSDT 系统服务描述表恢复的查看工具,让我们更加清晰查看到系统的函数是否已经恢复-System Service Descr iption Table SSDT restore the viewer, let us see more clearly a function of the system is recovered
RestoreShadowInUser
- Ring0下恢复SSDT Shadow,在用户端的情况下恢复系统描述表-Under the recovery Ring0 SSDT Shadow, in the case of the client to restore the system descr iption
VB-Del-Kernel-Hook
- VB恢复内核钩子的一个示例工程文件。可以调试。-VB restore a core sample project file hook. For debugging.
inlinehook_v1.1_by_solosky
- Inline HOOK API V1.1 thanks to 海风月影, xIkUg ,sucsor by solosky <solosky772@qq.com> created at 2011.06.29, updated at 2011.06.30 ---------------------------------- Inline HOOK API V1.1 2011.06.30 ----------------------------
dog-technology-analysis
- 机器狗新变种使用了一些流行的技术,包含了修复 SSDT Hook 、修复 FSDHook 、并对一些系统还原软件进行有针对的 Hook ,使能达到突破还原软件保 护的目的。做了那么多,最终目的还是下载大量的*到用户的系统上。-The machine dog new varieties used some of the more popular technology, including the repair SSDT Hook, repair FSDHook, and for some sys
