download
mirror
Changelog:
mirror
Changelog:
- add support of windows10 build 10041.
- add -obcb key for dumping object type callbacks. Sample from machine infected with dr.web (btw this north papua av consider wincheck as process.injecter, hell yeah):
ObType Process (FFFFFA800CCCBBC0):
DumpProcedure: 0000000000000000
OpenProcedure: FFFFF80003365620 \SystemRoot\system32\ntoskrnl.exe
CloseProcedure: FFFFF8000334C9A0 \SystemRoot\system32\ntoskrnl.exe
DeleteProcedure: FFFFF8000334BC50 \SystemRoot\system32\ntoskrnl.exe
ParseProcedure: 0000000000000000
SecurityProcedure: FFFFF8000337D530 \SystemRoot\system32\ntoskrnl.exe
QueryNameProcedure: 0000000000000000
OkayToCloseProcedure: 0000000000000000
2 callback(s):
cb[0] operation 3
PreOperation FFFFF88001157914 \SystemRoot\system32\drivers\dwprot.sys
cb[1] operation 3
PreOperation FFFFF88004890E30 \SystemRoot\system32\DRIVERS\VBoxDrv.sys
PreOperation FFFFF8800488EBD0 \SystemRoot\system32\DRIVERS\VBoxDrv.sys - add tables checking inside wudfx02000.dll