[驱动编程] Antisptd

[复制链接]
发表于 2021-5-13 12:22:56
Antisptd是一个驱动程序,它使SoftICE在sptd.sys存在时加载成为可能。它使用Kayaker描述的方法(参见下面的相关URL),也就是说,通过删除notifyroutine sptd集来阻止ntice.sys加载。在ntice.sys被加载之后,它恢复notifyroutine和i8042prt.sys中被sptd.sys拧紧的键盘挂钩
如何使用:
只需将startsi.exe放入antisptd.sys目录并执行startsi.exe。

(Antisptd is a driver that makes it possible for SoftICE to load when sptd.sys is present. It uses the method described by Kayaker (see related URLs below) and that is, by removing the notifyroutine sptd sets to prevent ntice.sys to load. After ntice.sys gets loaded, it restores the notifyroutine and the keyboard hooks in i8042prt.sys that have been screwed by the sptd.sys
How to use it:
Just put the startsi.exe in a directory with antisptd.sys and execute startsi.exe.
Compatibility issues
The driver should work on XP SP2/SP3 with the latest SoftICE installed. I have no idea if it'll work on XP SP1 (cause I have used hard-coded values to locate the patches). If it doesn't work, feel free to modify the sources and recompile the driver yourself. ;))

1620879768929.rar



上一篇:Break-Into-Pattern 壳以及源码
下一篇:ExeSafeguard 1.0 Source Code

使用道具 举报

Archiver|手机版|小黑屋|吾爱开源 |网站地图

Copyright 2011 - 2012 Lnqq.NET.All Rights Reserved( ICP备案粤ICP备14042591号-1粤ICP14042591号 )

关于本站 - 版权申明 - 侵删联系 - Ln Studio! - 广告联系

本站资源来自互联网,仅供用户测试使用,相关版权归原作者所有

快速回复 返回顶部 返回列表