From Collaborative RCE Tool Library

Jump to: navigation, search

Anti Anti-BPM via SEH, KiUserExceptionFilter Mod

Tool name: Anti Anti-BPM via SEH, KiUserExceptionFilter Mod
Rating: 0.0 (0 votes)
Author: Robert Yates                        
Current version:
Last updated: August, 2003
Direct D/L link:
License type:
Description: This is an idea I had and tried to put into practice. Some protections create faults so they can clear bpms, Asprotect for example, so the idea behind this sys is to modify KiUserExceptionDispatcher to create a snapshot of the drx regs before the users exception occurs then restore them afterwards. It works but the src is rough, currently you have to disassemble ur own ntdll and find some un-used space, (6 dwords) at the end off the .data then subtract the ntdll imagebase and update the NTDT EQU in the .sys. The idea could be improved by only restoring drx values that have become null or the standard dr7 value re-entered.

Have a go, bpm w the code section of an asprotect exe after the sys is loaded.
Related URLs: No related URLs have been submitted for this tool yet

RSS feed Feed containing all updates for this tool.

You are welcome to add your own useful notes about this tool, for others to see!

If you find that any information for the tool above is missing, outdated or incorrect, please edit it!
(please also edit it if you think it fits well in some additional category, since this can also be controlled)

Category Navigation Tree
   Needs New Category  (3)