Pure usermode Prevx3 self-protection total bypass.
Main post http://www.rootkit.com/blog.php?newsid=1032
KernelMode.Info exclusive.
Full version, including partial source code (without rtl's and resources).
Tested with latest available Prevx3 under Windows XP, however this method will work anywhere on x86-32.
Note: this version is for 3.0.5.179 version of Prevx, for newest see next in the thread.
pass for source: kernelmode.info
Main post http://www.rootkit.com/blog.php?newsid=1032
KernelMode.Info exclusive.
Full version, including partial source code (without rtl's and resources).
Tested with latest available Prevx3 under Windows XP, however this method will work anywhere on x86-32.
Note: this version is for 3.0.5.179 version of Prevx, for newest see next in the thread.
pass for source: kernelmode.info
Attachments
(52.6 KiB) Downloaded 115 times
Ring0 - the source of inspiration