Exetools

Exetools (https://forum.exetools.com/index.php)
-   General Discussion (https://forum.exetools.com/forumdisplay.php?f=2)
-   -   Crypt/modify a .sys ? (https://forum.exetools.com/showthread.php?t=13137)

J4H 12-01-2010 08:17

Crypt/modify a .sys ?
 
Hi,
Can someone help me with few information's please ?

1.How to crypt a .sys file ?(I try aspack, but after crypt stop working, windows didn't accept :mad:).
2.How to modify size for a .sys ?(I know an exe/dll few methods) but for .sys after I modify stop working.
3.Have someone a ring 0 dll injector for 64 bit ?(rootkit method:)) ?

10x in advance !

yogi_saw 12-01-2010 11:36

u will to have fix the checksum after modifying sys to make it work use petools or any pe editor to correct checksum

D-Jester 12-01-2010 21:41

Quote:

Originally Posted by J4H (Post 70525)
Hi,
Can someone help me with few information's please ?

1.How to crypt a .sys file ?(I try aspack, but after crypt stop working, windows didn't accept :mad:).

Code Virtualizer

Quote:

Originally Posted by J4H (Post 70525)
2.How to modify size for a .sys ?(I know an exe/dll few methods) but for .sys after I modify stop working.

As yogi_saw mentioned, update checksum.

Quote:

Originally Posted by J4H (Post 70525)
3.Have someone a ring 0 dll injector for 64 bit ?(rootkit method:)) ?

x64 requires digital signatures on all drivers

Fyyre 12-01-2010 23:25

Quote:

Originally Posted by J4H (Post 70525)
1.How to crypt a .sys file ?(I try aspack, but after crypt stop working, windows didn't accept :mad:).

Write your own, or use something like Code Virtualizer.

Quote:

Originally Posted by J4H (Post 70525)
2.How to modify size for a .sys ?(I know an exe/dll few methods) but for .sys after I modify stop working.

Why want to modify size of driver?

Quote:

Originally Posted by J4H (Post 70525)
3.Have someone a ring 0 dll injector for 64 bit ?(rootkit method:)) ?

You will have to port for x64 -->> InjectAPC

-Fyyre

D-Jester 12-02-2010 00:35

@Fyyre: Off topic, but who is that chick in your Avatar?

Av0id 12-02-2010 13:33

vmprotect can protect drivers

Fyyre 12-03-2010 01:46

Quote:

Originally Posted by D-Jester (Post 70537)
@Fyyre: Off topic, but who is that chick in your Avatar?


Me, of course ;)

J4H 12-03-2010 02:09

10x for your great information's guys and girls :D

Have someone to share a good Code Virtualizer or vmprotect ? I have an old version of Code Virtualizer but seem to not work :mad:

I'm not so skilled like you guys and girls but an little tutorial: how to update/rebuild the checksum after I pack/crypt ?

I need to modify size for prevent a stupid detection method who check size&CRC, CRC to modify is simple in fact but if I modify size or CRC the windows don't accept my .sys :mad: tell me: isn't a win 32 bit :mad::mad:

Edit:

I solve the problem for 32 bit platform (IDA Pro(.MAP File) + Code Virtualizer) so 10x for great information guys and girls !
So only for made a comparison, have someone vmprotect ?(last version?)

A little tutorial: how to update/rebuild the checksum after I pack/crypt ?(to learn for myself)

Solved CRC&Size :D

Av0id 12-03-2010 15:30

look inside software release section and you will find everything you want


All times are GMT +8. The time now is 11:13.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX