A forum for reverse engineering, OS internals and malware analysis 

Ask your beginner questions here.
 #9987  by utsav.0202
 Tue Nov 29, 2011 8:35 am
Hi
How do I get the index of the routines of Shadow SSDT in Windows 7?
For other OS I used Rootkit Unhooker but it does not support Win 7.

Thanks and Regards
Utsav
 #9988  by EP_X0FF
 Tue Nov 29, 2011 9:15 am
utsav.0202 wrote:Hi
How do I get the index of the routines of Shadow SSDT in Windows 7?
For other OS I used Rootkit Unhooker but it does not support Win 7.

Thanks and Regards
Utsav
You are using wrong or outdated version, Rootkit Unhooker supports x86 Win7.
 #9997  by utsav.0202
 Tue Nov 29, 2011 12:35 pm
Version 3.7.300.509 is not working on Win 7

Error loading driver NTSTATUS 0XC0000001 (STATUS_UNSUCCESSFUL)
 #9998  by EP_X0FF
 Tue Nov 29, 2011 12:44 pm
utsav.0202 wrote:Version 3.7.300.509 is not working on Win 7

Error loading driver NTSTATUS 0XC0000001 (STATUS_UNSUCCESSFUL)
Where did you get this museum version? It is 4+ years old.
http://www.kernelmode.info/forum/viewto ... ?f=11&t=10