A forum for reverse engineering, OS internals and malware analysis 

Forum for discussion about user-mode development.
 #15800  by EP_X0FF
 Sat Sep 29, 2012 10:58 am
Hello,

Test complete. PoC working - Kaspersky v13.0.1.4190 with default settings successfully prevented from work (including service). All job done from user mode - Kaspersky don't popup any warnings etc, all it hooks stay in place. GJ. Seems this method can be adopted for some malware usage.
 #15804  by R00tKit
 Sat Sep 29, 2012 1:38 pm
YES YES i love this works :D
kaspersky lol lol
more info?
EP_X0FF is now chief executive of KIAKP : kernelmode.info Institution of approving Kaspersky killer POC :mrgreen: :mrgreen: :lol: :lol: :lol:

Propaganda: you have kasperkiller ? send to us (Public relations of KIAKP ) :lol: :lol:
 #15808  by 0x16/7ton
 Sat Sep 29, 2012 5:17 pm
EP_X0FF wrote:Hello,

Test complete. PoC working - Kaspersky v13.0.1.4190 with default settings successfully prevented from work (including service). All job done from user mode - Kaspersky don't popup any warnings etc, all it hooks stay in place. GJ. Seems this method can be adopted for some malware usage.
Thanks EP_X0FF.As time appears,maybe i create new PoC.
 #15818  by EP_X0FF
 Sun Sep 30, 2012 3:15 am
Thanat0S wrote:so who will share this POC with us? :P
Obviously it's only author will decide - will he share or not.
 #15889  by R00tKit
 Fri Oct 05, 2012 5:59 am
@0x16/7ton
hi amigo
what version of kaspersky?
if it is 2012 so what difference compare with my Code make this code beneficial ? i think nothing

thanks
 #15890  by 0x16/7ton
 Fri Oct 05, 2012 7:10 am
NtCl0$e wrote:@0x16/7ton
hi amigo
what version of kaspersky?
if it is 2012 so what difference compare with my Code make this code beneficial ? i think nothing

thanks
Of course it is Kaspersky v13.0.1.4190 .

my regards :)
  • 1
  • 3
  • 4
  • 5
  • 6
  • 7
  • 13