#1
|
|||
|
|||
sys packer
hi,
Looking for a drivers (sys-files) packer. Found nothing yet. Can anybody help with any links (theoretical material maybe)? will be really appreciate for any help. |
#3
|
|||
|
|||
only VMProtect, nothing else?
|
#4
|
|||
|
|||
Code Virtualizer will VM them but no packing.
|
#5
|
|||
|
|||
TDL malware .sys drivers are packed, but this packer is probably private.
|
#6
|
|||
|
|||
There is nothing difficult to pack sys images. But there are a few rules: the result should have a valid OptionalHeader.Checksum (MapFileAndCheckSum), take a look for sections attributes (if the section is non paged, use NonPagedPool for avoid BSOD), kernelmode SEH's are work only if exception handler points to code section (if your packer will move original image somewhere), MmGetSystemRoutineAddress doesn't work with NDIS API's, etc.
|
The Following 2 Users Gave Reputation+1 to SLV For This Useful Post: | ||
Ember (03-31-2012) |
#7
|
||||
|
||||
I also recommend code virtualizer. its doing a quite nice job.
|
|
|
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
New Packer | Kyrios | General Discussion | 3 | 11-11-2005 16:00 |
Another .NET packer | SystemeD | General Discussion | 5 | 09-19-2005 22:04 |
First .NET packer? | SystemeD | General Discussion | 16 | 06-05-2005 15:15 |
What packer would you use | Fade | General Discussion | 35 | 04-03-2004 12:01 |