首页
社区
课程
招聘
[ZT]PhantOm plugin 1.25
发表于: 2008-4-2 10:37 14206

[ZT]PhantOm plugin 1.25

2008-4-2 10:37
14206
--- [PhantOm plugin 1.25 ]------------------------------------------ --------
by Hellsp @ wn & Archer

/ / spring aggravation:
/ / IHA! PEOPLE WITH ALL DAY! SPRING WALKS! BEER begins! GULYAYTE DEVUSHKAMI X!
/ / ZHIVITE FULL LIFE!

| Privety fly to:
| Bronco, kioresk, RSI, lord_Phoenix, HoBleen, Grim Fandango,
| Guru.eXe, vad8787, PE_Kill.
-------------------------------------------------- ---------------------------

The plug to hide OllyDbg (with driver).
Helps detection of the following methods:

/ / driver - extremehide.sys

[+] NtQueryInformationProcess.
[+] SetUnhandledExceptionFilter.
[+] OpenProcess.
[+] Invalid Handle.
[+] NtSetInformationThread.
[+] RDTSC.
[+] NtYieldExecution.
[+] NtQueryObject.
[+] NtQuerySystemInformation.
[+] Windows hide.
[+] GetProcessTimes.
[+] NtSetContextThread.

/ / plug - PhantOm.dll

[+] PEB BeingDebugged.
[+] PEB NtGlobalFlag.
[+] GetStartupInfo.
[+] Process Heaps.
[+] GetTickCount.
[!] Protect DRx.
[!] Hide DRx.
[!] Fake Windows version.
[!] Custom Handler.
[+] BlockInput

What's New - 1.25

You may now ask the very name services
HIDENAME and RDTSCNAME.

Some minor bugs.

Fixed bug with memory breakpoints.

What's New - 1.20

Added own processing exceptions (C0000005).

Added the title change of the main window.

Added own processing exceptions (OUTPUT_DEBUG_STRING_EVENT).

int 3 at EP correctly removed if the stop
at the point of the system failed.

Added BlockInput interception. (WinXP only)

Added own processing exceptions (C0000094).

Added hide from GetStartupInfo.

Fixed bug with the settings plug.

Added protection from detection drivers.

What's New - 1.15

Several bugs.

What's New - 1.10

hook GetProcessTimes - moved to the driver.

hook NtSetContextThread - moved to the driver.

The bug and removing the "EP break."

Several bugs related to downloading options.

In ini added "DELTARDTSC which will regulate the spread RDTSC.

What's New - 1.04

Fixed bsod while loading drivers.

What's New - 1.03

Fixed bug with windows.

What's New - 1.01

Fixed bug in the driver.

What's New - 1.00

Added protection OllyDbg windows.

Now OllyDbg patchitsya regardless of ImageBase.

What's New - 0.60

Added own processing exceptions (C000001E, 80000001, C000001D).

Added removal int3 with EntryPoint.

Fixed bug with GetTickCount.

Added methods in anti-detekta driver.

What's New - 0.58

Fixed bug with Hide from peb on some systems.

What's New - 0.57

Fixed bug with the attachment to the process.

Added protection from GetProcessTimes.
[-] Removed option Fake Windows version (at the time).

What's New - 0.55

Improved imulyatsiya GetTickCount.

Added emulation RDTSC.

Fixed bug with not zeroing ServicePack.

A bit optimized code.

What's New - 0.53

Now the driver is in resources.

NtSetInformationThread added protection.

Fixed bug with Fake Windows version.

What's New - 0.51

Fixed bug in the GetTickCount

Fixed bug with a patch PEB 'and

/ / Notes:

-- if you have changed the settings in the plug, but you open any file in OllyDbg,
necessarily have to restart it (Ctrl-F2) program.

-- plug-in displays debug messages Log (Alt + L), so the first run
advised to put all the options and examine the Log for errors.

-- tested only on Windows 2000 SP4, XP SP2.

-- with the plug, it is recommended to turn off programs that can prevent
loading drivers (Antivirus, PC).

-- incorrect in the work are encouraged to try to plug the "native" OllyDbg,
without extraneous plugins.

/ / Contact author:
www: hellspawn.nm.ru
mail: for.hellspawn @ gmail.com
-------------------------------------------------- ----------[ 01.04.2008] ---

[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)

上传的附件:
收藏
免费 0
支持
分享
最新回复 (63)
雪    币: 8201
活跃值: (2701)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
2
俄文网站没见更新的消息呀?
只知道дата是data的意思,Форум是forum论坛的意思,进入论坛全是俄文,完全看不懂
2008-4-2 10:56
0
雪    币: 1844
活跃值: (35)
能力值: ( LV3,RANK:30 )
在线值:
发帖
回帖
粉丝
3
哦,有这样的事情 , 下 ,谢

测试了一下,选取 HOOT RDTSC 会出现错误,OD 打开文件退出

具体情况还没查看
上传的附件:
  • 1.jpg (1.86kb,1140次下载)
2008-4-2 11:19
0
雪    币: 250
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
4
看看稳定性如何
2008-4-2 11:30
0
雪    币: 209
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
5
强悍的东西。
2008-4-2 11:38
0
雪    币: 259
活跃值: (10)
能力值: ( LV8,RANK:130 )
在线值:
发帖
回帖
粉丝
6
这个插件好像和我无缘,都是导致OD错误,郁闷死我了
2008-4-2 12:55
0
雪    币: 707
活跃值: (1301)
能力值: ( LV9,RANK:190 )
在线值:
发帖
回帖
粉丝
7
直接蓝了....XP SP2.........无缘
2008-4-2 13:12
0
雪    币: 202
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
8
先下来收藏。
2008-4-2 13:36
0
雪    币: 215
活跃值: (11)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
9
改进了以后可以调试新版THEMIDA不?
2008-4-2 13:51
0
雪    币: 107
活跃值: (404)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
10
看来不稳定。。。收藏先。。
2008-4-2 14:18
0
雪    币: 225
活跃值: (25)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
11
4月1号发布的东西
2008-4-2 14:24
0
雪    币: 1485
活跃值: (884)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
12
load driver一选择OD就出错了~
2008-4-2 15:14
0
雪    币: 716
活跃值: (162)
能力值: ( LV9,RANK:250 )
在线值:
发帖
回帖
粉丝
13
不敢相信,123
2008-4-2 15:40
0
雪    币: 275
活跃值: (130)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
14
[QUOTE=KuNgBiM;436064]--- [PhantOm plugin 1.25 ]------------------------------------------ --------
by Hellsp @ wn & Archer

/ / spring aggravation:
/ / IHA! PEOPLE ...[/QUOTE]
感觉4月1号发布的东西都不太敢相信………= =
2008-4-2 15:52
0
雪    币: 144
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
15
崩溃中。。。。。。
2008-4-2 16:28
0
雪    币: 277
活跃值: (2026)
能力值: ( LV6,RANK:90 )
在线值:
发帖
回帖
粉丝
16
load driver选中,OD出现无法载入任何程序
2008-4-2 16:40
0
雪    币: 97697
活跃值: (200829)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
17
AGAIN:

Privety fly to:
| Bronco, kioresk, RSI, lord_Phoenix, HoBleen, Grim Fandango,
| Guru.eXe, vad8787, PE_Kill

AND REVENGE TEAM !
2008-4-2 23:20
0
雪    币: 202
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
18
Hello,

the new version crasht olly if you use the driver.

I have Windows Xp Sp2 all updates.

greetz
2008-4-3 01:05
0
雪    币: 205
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
19
崩溃中。。。。。。
2008-4-3 10:31
0
雪    币: 234
活跃值: (10)
能力值: ( LV3,RANK:30 )
在线值:
发帖
回帖
粉丝
20
这PhantOm plugin 1.25
大多数人都无法使用
该不会由于是四月一日的原因
呵呵
2008-4-4 05:35
0
雪    币: 88
活跃值: (115)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
21
这个又更新了……支持把~~~
2008-4-4 13:44
0
雪    币: 205
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
22
感谢      !!!!!
2008-4-11 17:29
0
雪    币: 200
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
23
kankanna   支持你 的
2008-4-16 13:25
0
雪    币: 226
活跃值: (10)
能力值: ( LV8,RANK:130 )
在线值:
发帖
回帖
粉丝
24
LOAD DRIVER 直接挂。 THEMIDA 不能调试
2008-4-18 00:30
0
雪    币: 200
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
25
可惜无法下载,从其他坛下载的,测试一下,崩溃中。。。
2008-4-19 16:37
0
游客
登录 | 注册 方可回帖
返回
//