Imm_PhantOm Plugin 1.54 January 24, 2009
Posted by reversengineering in Immunity Debugger, TOOLS.trackback
Plug-in for concealment OllyDbg (plugin with the driver). Helps from following methods of detection:
// driver – extremehide.sys
[+] NtQueryInformationProcess.
[+] SetUnhandledExceptionFilter.
[+] OpenProcess.
[+] Invalid Handle.
[+] NtSetInformationThread.
[+] RDTSC.
[+] NtYieldExecution.
[+] NtQueryObject.
[+] NtQuerySystemInformation.
[+] Windows hide.
[+] GetProcessTimes.
[+] NtSetContextThread.
// plugin – PhantOm.dll
[+] PEB BeingDebugged.
[+] PEB NtGlobalFlag.
[+] GetStartupInfo.
[+] Process Heaps.
[+] GetTickCount.
[!] Protect DRx.
[!] Hide DRx.
[!] Fake Windows version.
[!] Custom Handler.
[+] BlockInput
http://vip-file.com/download/8d00af885300/PhantOm-Plugin-v1.54.7z.html
Comments»
No comments yet — be the first.