Alot changes in ntdll in windows 10 make scyllahide failed to hook functions in ntdll.
Example: NtQueryInformationProcess Code:
CPU Disasm Code:
CPU Disasm Code:
CPU Disasm |
Quote:
Regards, |
Quote:
|
Win 10 is a nightmare for "stealth" hooking. Probably they wanted to defeat malware.
I think I can work on it this weekend. |
Call Wow64SystemServiceCall now is seperate for Ntdll & User32.dll .. maybe other dll too. So need to change the NativeContinue structure to suit this.
|
Win10 has more surprises to offer:
https://ntquery.wordpress.com/2015/09/07/windows-10-new-anti-debug-outputdebugstringw/ I also see some weird behavior of NtQueryInformationProcess. You can query ProcessBasicInformation with different buffer sizes. size = 24 -> normal behavior, expected size like in all windows editions size = 32 -> extended information? You can get more information... |
@Carbon is there any update on making this working win 10.
|
Don't ask questions, here is fixed ScyllaHide for Windows 10 x86/x64.
Tested with x64/x32dbg on VMProtect and Obsidium targets. Quote:
|
This is the version of ScyllaHide that I use personally. It includes the fix provided by mudlord in the previous post (fix made by Colin). I also push this to the 'vs13' branch on the original repository.
Code: https://github.com/x64dbg/ScyllaHide Build of the latest version is always available here: https://ci.appveyor.com/project/mrex...uild/artifacts |
Quote:
|
Quote:
|
The error comes from idaserver.cpp:
Code:
int main(int argc, char *argv[]) |
Probably this can be fixed by updating the SDK to the same version as your IDA version...
|
I guess these days everybody has already switched to the latest public IDA...
six dot eight :) BTW, anybody seen this kind of warning (error?) in IDA: --------------------------- Error --------------------------- Failed to unprotect WOW64 gateway --------------------------- OK --------------------------- |
Please fix bug on update Windows 10 in ollydbg1 and ollydbg2
thank you in advance --------------------------- Error --------------------------- Windows 10 SysWowSpecialJmpAddress was not found! --------------------------- §°§¬ --------------------------- --------------------------- ERROR --------------------------- Unknown syscall structure! --------------------------- §°§¬ --------------------------- |
All times are GMT +8. The time now is 22:47. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX