ZeroMemoryEx / Chaos-Rootkit

Now You See Me, Now You Don't
864 stars 135 forks source link

Getting error while trying to hide PID #21

Closed pancibuntus closed 1 month ago

pancibuntus commented 1 month ago

1 2

ZeroMemoryEx commented 1 month ago

Hello @pancibuntus ,It seems that the rootkit doesn't support your Windows build offsets, which is why it blocked you from using those three features due to the risk of a crash. However, I believe your build is compatible, so I'll be adding it in the next update today. Stay tuned!

ZeroMemoryEx commented 1 month ago

@pancibuntus Can you unload the rootkit and load it again while DbgView is open with kernel output enabled, so I can verify your Windows build?

To do this, unload the rootkit by running Command Prompt as admin and typing sc stop chaos-rootkit. T hen, run DbgView as admin, enable kernel output

image

then run ring3-gui, connect to the rootkit, and send me a screenshot of the output in DbgView.

ZeroMemoryEx commented 1 month ago

Your version and other versions of Windows 10 and Windows 11 will be supported in the next update (probably by the end of the week) A massive update will be pushed with other feature, Stay tuned 😎 .