Originally Posted by
~FALLEN~
They will not credit anyone... they're leach's. Also, this isn't anything new a bunch of people have done it before... for instance, dwark( or however he spells it ), helios, mattdog, etc
Besides there are plenty of better ways to hide your module. Regardless though hopefully some people will learn something with this... For those who don't know what it's doing is removing it from the linked list of modules in the pe loader structure within the PEB.
LIST_ENTRY InLoadOrderModuleList;
LIST_ENTRY InMemoryOrderModuleList;
LIST_ENTRY InInitializationOrderModuleList;
I would also remove it from here too : HashTableEntry : LIST_ENTRY HashTableEntry;
LIST_ENTRY is just a bidirectional linked list...
Thanks for sharing though Robin... hopefully people take the time to LEARN from it and not just copy paste it...
-Pyro