How to unload a driver?

Posts 1–3 of 3 · Page 1 of 1
How to unload a driver?
I was just experimenting with OllyDbg, but she wasn't into it so I went back to the plain old Olly and noticed "womg" when I take Phantom plugin out, I don't get that wierd issue where Themida detects OllyDbg even if its not loaded. I did some research and found out, Phantom loads a driver, and Themida detects the driver, and blah, blah, blah. Point is I was wondering if I could unload the driver. I try to look int Process Explorer for it, but couldn't find the drivers name. It would be nice to remove it from memory rather then shutting down my computer which I hardly ever. I may shut down my computer, 2 or 3 times of month, and restart it maybe 5-10.... hibernation ftw.
Virus scan: VirusTotal - Free Online Virus, Malware and URL Scanner

Code:
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name:
osrloaderv30.zip
Submission date:
2011-03-03 04:59:46 (UTC)
Current status:
finished
Result:
0 /43 (0.0%)
	
VT Community

not reviewed
 Safety score: - 
Compact
Print results
Antivirus 	Version 	Last Update 	Result
AhnLab-V3 	2011.03.03.00 	2011.03.02 	-
AntiVir 	7.11.4.47 	2011.03.03 	-
Antiy-AVL 	2.0.3.7 	2011.03.02 	-
Avast 	4.8.1351.0 	2011.02.23 	-
Avast5 	5.0.677.0 	2011.02.23 	-
AVG 	10.0.0.1190 	2011.03.02 	-
BitDefender 	7.2 	2011.03.03 	-
CAT-QuickHeal 	11.00 	2011.03.03 	-
ClamAV 	0.96.4.0 	2011.03.02 	-
Commtouch 	5.2.11.5 	2011.03.03 	-
Comodo 	7848 	2011.03.02 	-
DrWeb 	5.0.2.03300 	2011.03.03 	-
Emsisoft 	5.1.0.2 	2011.03.03 	-
eSafe 	7.0.17.0 	2011.03.02 	-
eTrust-Vet 	36.1.8193 	2011.03.02 	-
F-Prot 	4.6.2.117 	2011.03.02 	-
F-Secure 	9.0.16160.0 	2011.03.03 	-
Fortinet 	4.2.254.0 	2011.03.03 	-
GData 	21 	2011.03.02 	-
Ikarus 	T3.1.1.97.0 	2011.03.03 	-
Jiangmin 	13.0.900 	2011.03.02 	-
K7AntiVirus 	9.91.4006 	2011.03.02 	-
Kaspersky 	7.0.0.125 	2011.03.03 	-
McAfee 	5.400.0.1158 	2011.03.03 	-
McAfee-GW-Edition 	2010.1C 	2011.03.02 	-
Microsoft 	1.6603 	2011.03.02 	-
NOD32 	5921 	2011.03.02 	-
Norman 	6.07.03 	2011.03.02 	-
nProtect 	2011-02-10.01 	2011.02.15 	-
Panda 	10.0.3.5 	2011.03.02 	-
PCTools 	7.0.3.5 	2011.03.02 	-
Prevx 	3.0 	2011.03.03 	-
Rising 	23.47.02.06 	2011.03.02 	-
Sophos 	4.61.0 	2011.03.03 	-
SUPERAntiSpyware 	4.40.0.1006 	2011.03.03 	-
Symantec 	20101.3.0.103 	2011.03.03 	-
TheHacker 	6.7.0.1.143 	2011.03.02 	-
TrendMicro 	9.200.0.1012 	2011.03.02 	-
TrendMicro-HouseCall 	9.200.0.1012 	2011.03.03 	-
VBA32 	3.12.14.3 	2011.03.02 	-
VIPRE 	8591 	2011.03.03 	-
ViRobot 	2011.3.3.4336 	2011.03.03 	-
VirusBuster 	13.6.231.0 	2011.03.02 	-
Additional information
Show all
MD5   : 7dd8096e43afce0ee68eebce71b640e3
SHA1  : 5bf379984f41811eec2959c13b514d0c8d1944f5
SHA256: 721a8586fbca3bae8a90079dc3ce0f4e99494802d7b5c52a3fc46baeebced714
osrloaderv30.zipattachment deleted · 1 downloads before removal
Ty. sry 4 begging... :P


Now I just have to figure out how to work this thing when the driver is loaded as a resource, meh... ;l
Posts 1–3 of 3 · Page 1 of 1

Post a Reply

Tags for this Thread

None

Need help?