Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 12-01-2010, 08:17
J4H
 
Posts: n/a
Crypt/modify a .sys ?

Hi,
Can someone help me with few information's please ?

1.How to crypt a .sys file ?(I try aspack, but after crypt stop working, windows didn't accept ).
2.How to modify size for a .sys ?(I know an exe/dll few methods) but for .sys after I modify stop working.
3.Have someone a ring 0 dll injector for 64 bit ?(rootkit method) ?

10x in advance !
Reply With Quote
  #2  
Old 12-01-2010, 11:36
yogi_saw yogi_saw is offline
Family
 
Join Date: Jul 2010
Posts: 173
Rept. Given: 57
Rept. Rcvd 52 Times in 32 Posts
Thanks Given: 3
Thanks Rcvd at 13 Times in 13 Posts
yogi_saw Reputation: 52
u will to have fix the checksum after modifying sys to make it work use petools or any pe editor to correct checksum

Last edited by yogi_saw; 12-01-2010 at 11:42.
Reply With Quote
  #3  
Old 12-01-2010, 21:41
D-Jester's Avatar
D-Jester D-Jester is offline
VIP
 
Join Date: Nov 2003
Location: Ohio, USA
Posts: 269
Rept. Given: 39
Rept. Rcvd 61 Times in 41 Posts
Thanks Given: 0
Thanks Rcvd at 4 Times in 4 Posts
D-Jester Reputation: 61
Quote:
Originally Posted by J4H View Post
Hi,
Can someone help me with few information's please ?

1.How to crypt a .sys file ?(I try aspack, but after crypt stop working, windows didn't accept ).
Code Virtualizer

Quote:
Originally Posted by J4H View Post
2.How to modify size for a .sys ?(I know an exe/dll few methods) but for .sys after I modify stop working.
As yogi_saw mentioned, update checksum.

Quote:
Originally Posted by J4H View Post
3.Have someone a ring 0 dll injector for 64 bit ?(rootkit method) ?
x64 requires digital signatures on all drivers
__________________
Even as darkness envelops and consumes us, wrapping around our personal worlds like the hand that grips around our necks and suffocates us, we must realize that life really is beautiful and the shadows of despair will scurry away like the fleeting roaches before the light.
Reply With Quote
The Following User Gave Reputation+1 to D-Jester For This Useful Post:
  #4  
Old 12-01-2010, 23:25
Fyyre's Avatar
Fyyre Fyyre is offline
Fyyre
 
Join Date: Dec 2009
Location: 0°N 0°E / 0°N 0°E / 0; 0
Posts: 295
Rept. Given: 106
Rept. Rcvd 93 Times in 44 Posts
Thanks Given: 203
Thanks Rcvd at 397 Times in 130 Posts
Fyyre Reputation: 93
Quote:
Originally Posted by J4H View Post
1.How to crypt a .sys file ?(I try aspack, but after crypt stop working, windows didn't accept ).
Write your own, or use something like Code Virtualizer.

Quote:
Originally Posted by J4H View Post
2.How to modify size for a .sys ?(I know an exe/dll few methods) but for .sys after I modify stop working.
Why want to modify size of driver?

Quote:
Originally Posted by J4H View Post
3.Have someone a ring 0 dll injector for 64 bit ?(rootkit method) ?
You will have to port for x64 -->> InjectAPC

-Fyyre
Reply With Quote
  #5  
Old 12-02-2010, 00:35
D-Jester's Avatar
D-Jester D-Jester is offline
VIP
 
Join Date: Nov 2003
Location: Ohio, USA
Posts: 269
Rept. Given: 39
Rept. Rcvd 61 Times in 41 Posts
Thanks Given: 0
Thanks Rcvd at 4 Times in 4 Posts
D-Jester Reputation: 61
@Fyyre: Off topic, but who is that chick in your Avatar?
__________________
Even as darkness envelops and consumes us, wrapping around our personal worlds like the hand that grips around our necks and suffocates us, we must realize that life really is beautiful and the shadows of despair will scurry away like the fleeting roaches before the light.
Reply With Quote
  #6  
Old 12-02-2010, 13:33
Av0id Av0id is offline
VIP
 
Join Date: Jan 2006
Posts: 399
Rept. Given: 112
Rept. Rcvd 111 Times in 69 Posts
Thanks Given: 0
Thanks Rcvd at 15 Times in 15 Posts
Av0id Reputation: 100-199 Av0id Reputation: 100-199
vmprotect can protect drivers
Reply With Quote
The Following User Gave Reputation+1 to Av0id For This Useful Post:
  #7  
Old 12-03-2010, 01:46
Fyyre's Avatar
Fyyre Fyyre is offline
Fyyre
 
Join Date: Dec 2009
Location: 0°N 0°E / 0°N 0°E / 0; 0
Posts: 295
Rept. Given: 106
Rept. Rcvd 93 Times in 44 Posts
Thanks Given: 203
Thanks Rcvd at 397 Times in 130 Posts
Fyyre Reputation: 93
Quote:
Originally Posted by D-Jester View Post
@Fyyre: Off topic, but who is that chick in your Avatar?

Me, of course ;)
Reply With Quote
  #8  
Old 12-03-2010, 02:09
J4H
 
Posts: n/a
10x for your great information's guys and girls

Have someone to share a good Code Virtualizer or vmprotect ? I have an old version of Code Virtualizer but seem to not work

I'm not so skilled like you guys and girls but an little tutorial: how to update/rebuild the checksum after I pack/crypt ?

I need to modify size for prevent a stupid detection method who check size&CRC, CRC to modify is simple in fact but if I modify size or CRC the windows don't accept my .sys tell me: isn't a win 32 bit

Edit:

I solve the problem for 32 bit platform (IDA Pro(.MAP File) + Code Virtualizer) so 10x for great information guys and girls !
So only for made a comparison, have someone vmprotect ?(last version?)

A little tutorial: how to update/rebuild the checksum after I pack/crypt ?(to learn for myself)

Solved CRC&Size
Reply With Quote
  #9  
Old 12-03-2010, 15:30
Av0id Av0id is offline
VIP
 
Join Date: Jan 2006
Posts: 399
Rept. Given: 112
Rept. Rcvd 111 Times in 69 Posts
Thanks Given: 0
Thanks Rcvd at 15 Times in 15 Posts
Av0id Reputation: 100-199 Av0id Reputation: 100-199
look inside software release section and you will find everything you want
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Can I crypt the ASProtect section ? H22H General Discussion 2 01-14-2005 06:08


All times are GMT +8. The time now is 03:54.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )