Indy
August 5th, 2013, 17:21
(Syscall IDP Engine).
Captures all system services(KDR, hidden). Returns control on specified address(int 0x2e/sysenter -> PEB.Filter()). By calling the backdoor control is returned to the kernel(Filter() -> backdoor() -> nt service dispatcher).
o X86, KM, MI, KDR.
o May be choose SST[0], SST[0] for gui-thread, SST[1] for shadow.
Vid http://rghost.ru/47763708 ("http://rghost.ru/47763708")
Org http://vx.security-portal.cz/ ("http://vx.security-portal.cz/")
2787
Captures all system services(KDR, hidden). Returns control on specified address(int 0x2e/sysenter -> PEB.Filter()). By calling the backdoor control is returned to the kernel(Filter() -> backdoor() -> nt service dispatcher).
o X86, KM, MI, KDR.
o May be choose SST[0], SST[0] for gui-thread, SST[1] for shadow.
Vid http://rghost.ru/47763708 ("http://rghost.ru/47763708")
Org http://vx.security-portal.cz/ ("http://vx.security-portal.cz/")
2787