Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Crash #3

Open
cryzlasm opened this issue Feb 25, 2019 · 1 comment
Open

Crash #3

cryzlasm opened this issue Feb 25, 2019 · 1 comment

Comments

@cryzlasm
Copy link

image

Shortcut Ctrl+Alt+I is used for two actions:
@idc:py_hotkeycb_0000000007EC6EE8
@idc:py_hotkeycb_0000000007EC6DC8
"@idc:py_hotkeycb_0000000007EC6DC8" will be deleted.
[+] Welcome to Driver Buddy
[+] Checking for DriverEntry...
[+] DriverEntry found
[+] Populating IDA functions....
[+] Searching for interesting C functions....
[+] interesting C functions detected
[+] Found 0x00011aea xref to RtlCopyMemory
[+] Found 0x00011b04 xref to RtlCopyMemory
[+] Searching for interesting Windows functions....
[+] interesting winapi functions detected
[+] Found 0x000110ae xref to ZwQuerySymbolicLinkObject
[+] Found 0x00011197 xref to ZwQuerySymbolicLinkObject
[+] Found 0x00011091 xref to ZwOpenSymbolicLinkObject
[+] Found 0x0001117e xref to ZwOpenSymbolicLinkObject
[+] Found 0x000112ca xref to ObReferenceObjectByPointer
[+] Found 0x00012493 xref to PsCreateSystemThread
[+] Found 0x000110c1 xref to ZwClose
[+] Found 0x000111a6 xref to ZwClose
[+] Found 0x000124ca xref to ZwClose
[+] Found 0x00012639 xref to ZwClose
[+] Found 0x000160d8 xref to ZwClose
[+] Found 0x00012600 xref to ZwMakeTemporaryObject
[+] Found 0x000124bd xref to ObReferenceObjectByHandle
[+] Found 0x000112d5 xref to ObfDereferenceObject
[+] Found 0x00016041 xref to ObfDereferenceObject
[+] Found 0x000118c4 xref to IofCallDriver
[+] Found 0x00011a24 xref to IofCallDriver
[+] Found 0x000125eb xref to ZwCreateDirectoryObject
[+] Searching for interesting driver functions....
[-] No interesting specific driver functions detected
[+] Trying to determine driver type...
[+] Found real DriverEntry address of ffffffffffffffff

@cryzlasm
Copy link
Author

shieldXp.zip

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant