<script language="JavaScript" src="http://ads.zndev.com/adx.js" type="text/javascript"></script> <script language="JavaScript" type="text/javascript">
</script> <script language="JavaScript" src="http://ads.zndev.com/adjs.php?n=544241405&what=zone:4&exclude=,&referer=http%3A//bbs.driverdevelop.com/thread.php%3Ffid-98.html" type="text/javascript"></script>
http://www.rootkit.com/vault/uty/NIAPAntiRootkitTools.rar
号称使用了无视一切 Hook 的“镜像系统”:
In these tools, we use some new tech called mirror system (pretty cool, we hope it worth the name ;p). We mirrored the kernel file, file system driver file, and it can do more. We think the effect is that there will be no more hook(code hook, not include data hook, like NDIS or registry hive hook, for now).
号称使用了无视一切 Hook 的“镜像系统”:
In these tools, we use some new tech called mirror system (pretty cool, we hope it worth the name ;p). We mirrored the kernel file, file system driver file, and it can do more. We think the effect is that there will be no more hook(code hook, not include data hook, like NDIS or registry hive hook, for now).
对付
remap ntfs/fatfat, ntoskrnel , 然后add SysetmService,等等无效
对 disk级的无效
对 hal级无效
对XX,XXXX,以及XX1也无效无效
没有走到pool hook的扫描ntfs和fastfat特征...
没有随机设备名
老V那个在CVC上发烂了的BDFILE都可以??