首页
社区
课程
招聘
关于How hide ollydbg under win98
发表于: 2004-9-6 22:44 4789

关于How hide ollydbg under win98

2004-9-6 22:44
4789
以下是我的提问:
hi

how can I hide my ollydbg1.1 under win98?
can someone help me

解决方法有待讨论:
you can try renaming OLLYDBG.EXE to something else ( I use onlydbg.exe). Of course you then have to change the references to ollydbg.exe inside all the plugins you are using to the new name but that's fairly easy to do using a hex editor.
Hope it helps.
by:Belisarious

原文出处:
http://www.exetools.com/forum/showthread.php?t=5234

[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)

收藏
免费 1
支持
分享
最新回复 (5)
雪    币: 16
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
2
改名就行了?还有别的办法吗?
2004-9-7 10:29
0
雪    币: 519
活跃值: (1223)
能力值: ( LV12,RANK:650 )
在线值:
发帖
回帖
粉丝
3
I think that's depending on how the software detects OLLY:D
2004-9-7 11:07
0
雪    币: 241
活跃值: (160)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
4
改名也好像不能躲过TELOCK的检测
2004-9-7 11:57
0
雪    币: 383
活跃值: (786)
能力值: ( LV12,RANK:730 )
在线值:
发帖
回帖
粉丝
5
你应该发问How to Hide the debuger flag of ollydbg under win98?
所以你的得到的回答是对应你的提问!:D
2004-9-7 14:44
0
雪    币: 97697
活跃值: (200834)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
6
lordways发言:我经常用这个小工具在W98下隐藏OD

This little tool has 2 buttons.

1.The first, "Hide", hooks th IsDebuggerPresent API and makes it unuseful
against debuggers. The Armadillo software protection system is owned by
this trick ! After having hidden your debuggers, you can restore the
first verion of the API by re-clicking the button, which caption had
changed to "Un-Hide".

2.The second button enables you to activate breakpoints on Windows APIs in
OllyDbg under 9x systems, thing which was impossible. Caution, it makes your
Kernel32 in memory WRITEABLE, so a simple line of code can kill your most
basic Windows functions, until next reboot.
    After having set breakpoints with OllyDBG, if you are not sure your Kernel
is clean, you can fix all the APIs's first byte by clicking "Fix". After that a
messagebox appears, asking you if you want to COMPLETELY clean you Kernel.
If you answer YES, you will be able to execute ALL applications, the
no-imports ones too.
If you answer NO, you will be able to re-fix your Kernel as you want, when
you want, until you click YES.

    All these tricks work, even if you close this tool. It detects if you have the bps enabled or IsDebuggerPresent hooked, and inits itself, following the
different cases.

Hope it will be useful for you,
2004-9-8 08:10
0
游客
登录 | 注册 方可回帖
返回
//