Search found 4219 matches

by EP_X0FF
Mon May 21, 2018 9:18 am
Forum: Kernel-Mode Development
Topic: why ExFreePool will blue screen
Replies: 3
Views: 128

Re: why ExFreePool will blue screen

Are you kidding or what?

You allocated 4 byte long buffer and passed it to function giving it size as 36 bytes long.

You don't need to allocate memory for PROCESS_DEVICEMAP_INFORMATION. It is structure with fixed size.
by EP_X0FF
Sat May 05, 2018 5:03 am
Forum: Newbie Questions
Topic: Dont know what this exe does
Replies: 1
Views: 422

Re: Dont know what this exe does

It is trojan downloader. Obfuscated strings from inside. "Software\\Microsoft" "\\Windows\\Currentversion\\Run" "Taskhst" "Environment" "Cq" "cmd /c start %Cq% " "&& exit" "ntuser" "toolsd.exe" "aday.primeservices.mobi" "/IXR/goprim.php" "Connection: keep-alive" "Content-type: application/x-www-form...
by EP_X0FF
Thu May 03, 2018 8:28 am
Forum: Kernel-Mode Development
Topic: need help Explain this code
Replies: 6
Views: 490

Re: need help Explain this code

This driver constructs shellcode in runtime in allocated from NonPaged pool memory, hooks IRP of some legitimate ms drivers and quits leaving shellcode work in callback routines. Later driver file can be removed by loader. That's why there is no "file" and "ark" won't detect it as "driver". However ...
by EP_X0FF
Wed May 02, 2018 4:15 am
Forum: Kernel-Mode Development
Topic: need help Explain this code
Replies: 6
Views: 490

Re: need help Explain this code

It is DriverEntry. That's all what you can get as an answer from posting raw IDA HexRays dump. If you want help seriously then you should attach actual file not useless HexRay dump.
by EP_X0FF
Sun Apr 29, 2018 4:05 am
Forum: Kernel-Mode Development
Topic: how to delete driver file and still Keep communication
Replies: 10
Views: 870

Re: how to delete driver file and still Keep communication

Starting from Windows 10 you cannot delete file of loaded driver as it locked on disk.
If you want similar functionality from your screenshot you need to send IRP to filesystem device driver. Search for KSBinSword for "code". However conseqences of this is unknown for Windows 10.
by EP_X0FF
Wed Apr 18, 2018 7:29 am
Forum: Newbie Questions
Topic: c - How implement a realloc function in kernel mode?
Replies: 6
Views: 923

Re: c - How implement a realloc function in kernel mode?

This code with small modifications copy-pasted from stackoverflow. What is the point in this? Vrtule already gave you code for "realloc". Ex*** memory pool manager does not have this function. You either implement it yourself (which you are unable to do no matter what you copy-paste), or you clarify...
by EP_X0FF
Mon Apr 16, 2018 3:20 am
Forum: Newbie Questions
Topic: ArrayList: trouble with a custom IndexOf() routine
Replies: 6
Views: 772

Re: ArrayList: trouble with a custom IndexOf() routine

You can't manage basic level programming tasks with pointer list and want to write a driver. Please stop here.
by EP_X0FF
Fri Apr 13, 2018 3:38 am
Forum: Newbie Questions
Topic: ArrayList: trouble with a custom IndexOf() routine
Replies: 6
Views: 772

Re: ArrayList: trouble with a custom IndexOf() routine

Have you really read and understand my previous reply?

All your code is broken and unworkable by design.