Rootkit Detector is impressive. If you could expad this so that you can kill hidden processes, that would be AWESOME. Also i’ve realised i had several API hooked using both detour and table method, if you could add a means to UNHOOK these, that would be AWESOME.
hey krs, I dunno if you’ll read this again or not, but I came onto irc looking for you several times to no avail. If you still need assistance hit me up on msn. somebastardstolemyname@gmail.com.
I just found this blog, and it looked promising. I’m really interested in low-level win32 stuff. Can’t find much of these sites around. But the website was unavailable, i cant follow the links. Can you take a look at it?
Hi,
Firstly thank you very much for your very interesting blog.
I would like to know how can we do to hook the NtCreateKey API through a driver for a well-determined process in order to send the created registrykey to the Userland.
Thank you in advance.
Sincerely.
Zili
Hola si solo queria saber si podemos intercambiar link un saludo dani
dani said this on August 8, 2008 at 2:02 pm
Hi,
Im sorry I dont speak Spanish.
Rhys M. said this on August 10, 2008 at 1:57 pm
Rootkit Detector is impressive. If you could expad this so that you can kill hidden processes, that would be AWESOME. Also i’ve realised i had several API hooked using both detour and table method, if you could add a means to UNHOOK these, that would be AWESOME.
ksbunker@hotmail.com
Ksbunker said this on August 23, 2008 at 7:23 am
Hey,
Thanks. Yeah Ive been meaning to finish the unhooking part of the code. And terminating the processes wont be too much of a problem either.
Rhys M. said this on August 26, 2008 at 7:04 am
Haha, I laughed at the “I don’t speak Spanish part”.
nwongfeiying said this on September 2, 2008 at 6:00 pm
Hi the undead
, can you check your pm @ unrealadmin forums ? would be appreciated
krs said this on September 6, 2008 at 8:17 am
hey krs, I dunno if you’ll read this again or not, but I came onto irc looking for you several times to no avail. If you still need assistance hit me up on msn. somebastardstolemyname@gmail.com.
Rhys M. said this on October 7, 2008 at 10:28 am
UPDATE YOU BASTARD
Mor said this on December 28, 2008 at 9:40 pm
Wait a bit.
Its new years.
I’ve been busy.
Got some cool stuff coming though.
Rhys M. said this on December 29, 2008 at 3:56 pm
You’ve got some pretty imprsesive stuff here, well done, do you write tutorials?, bet I could learn plenty.
C++arl said this on January 6, 2009 at 11:09 am
haha thanks. Nah I dont really have the patience to write tutorials. Whats on this site is about as far as I ever venture into tutorial-territory
Rhys M. said this on January 11, 2009 at 2:04 pm
Hello,
Is your website on atspace.com dead? I cant access anything from that site. http://theundead.atspace.com/
I just found this blog, and it looked promising. I’m really interested in low-level win32 stuff. Can’t find much of these sites around. But the website was unavailable, i cant follow the links. Can you take a look at it?
Thanls.
elfrip said this on June 26, 2009 at 7:18 pm
test to see if the post gets posted.
elfrip said this on June 26, 2009 at 7:19 pm
Hi,
is the link to your atspace webpage down? I cant follow the links to the sources at that site. Can you look into it?
Thanks.
elfrip said this on June 26, 2009 at 7:20 pm
Should be fine. It seems to act up sometimes, but if you try again a few times it eventually goes through.
Rhys M. said this on July 15, 2009 at 6:24 pm
The website at that address just forwards you here.
I just use it to store all the source code (.txt’s) and pictures used here.
Rhys M. said this on October 9, 2009 at 4:32 pm
Hey, i added you in MSN i have a question about something you can also send me a email when you have time.
Arghs said this on November 20, 2009 at 10:15 pm
Hi,
Firstly thank you very much for your very interesting blog.
I would like to know how can we do to hook the NtCreateKey API through a driver for a well-determined process in order to send the created registrykey to the Userland.
Thank you in advance.
Sincerely.
Zili
Zili said this on December 23, 2009 at 2:06 am
dude rock
dude said this on February 18, 2010 at 3:47 pm