Description: gh0st original deleted SSDT, the injection process to start the service. Can bypass a lot of soft kill active defense
To Search:
File list (Check if you may need any files):
Server\install\acl.h
......\.......\decode.h
......\.......\inject.h
......\.......\install.cpp
......\.......\install.dsp
......\.......\install.plg
......\.......\install.rc
......\.......\ReadMe.txt
......\.......\RegEditEx.h
......\.......\res\svchost.dll
......\.......\resource.h
......\.......\StdAfx.cpp
......\.......\StdAfx.h
......\svchost\ClientSocket.cpp
......\.......\ClientSocket.h
......\.......\common\AudioManager.cpp
......\.......\......\AudioManager.h
......\.......\......\Buffer.cpp
......\.......\......\Buffer.h
......\.......\......\decode.h
......\.......\......\Dialupass.cpp
......\.......\......\Dialupass.h
......\.......\......\FileManager.cpp
......\.......\......\filemanager.h
......\.......\......\hidelibrary.h
......\.......\......\inject.h
......\.......\......\install.cpp
......\.......\......\install.h
......\.......\......\KernelManager.cpp
......\.......\......\KernelManager.h
......\.......\......\KeyboardManager.cpp
......\.......\......\KeyboardManager.h
......\.......\......\login.h
......\.......\......\loop.h
......\.......\......\Manager.cpp
......\.......\......\Manager.h
......\.......\......\RegEditEx.cpp
......\.......\......\RegEditEx.h
......\.......\......\resetssdt.h
......\.......\......\ScreenManager.cpp
......\.......\......\ScreenManager.h
......\.......\......\ScreenSpy.cpp
......\.......\......\ScreenSpy.h
......\.......\......\ShellManager.cpp
......\.......\......\ShellManager.h
......\.......\......\SystemManager.cpp
......\.......\......\SystemManager.h
......\.......\......\until.cpp
......\.......\......\until.h
......\.......\......\VideoCap.cpp
......\.......\......\VideoCap.h
......\.......\......\VideoManager.cpp
......\.......\......\VideoManager.h
......\.......\hidelibrary.h
......\.......\ReadMe.txt
......\.......\..lease\svchost.exp
......\.......\.......\svchost.lib
......\.......\resource.h
......\.......\StdAfx.cpp
......\.......\svchost.cpp
......\.......\svchost.dsp
......\.......\svchost.plg
......\.......\svchost.rc
......\.ys\makefile
......\...\RESSDT.c
......\...\RESSDT.sys
......\...\sources
gh0st.dsw
remove.bat
Bin\gh0st.exe
common\Audio.cpp
......\Audio.h
......\CursorInfo.h
......\macros.h
......\VideoCodec.h
......\zlib\zconf.h
......\....\zlib.h
......\....\zlib.lib
gh0st\AudioDlg.cpp
.....\AudioDlg.h
.....\BmpToAvi.cpp
.....\BmpToAvi.h
.....\BuildView.cpp
.....\BuildView.h
.....\CJ60Lib\CJ60Lib\CJ60Lib.clw
.....\.......\.......\CJ60lib.cpp
.....\.......\.......\CJ60lib.def
.....\.......\.......\CJ60Lib.dsp
.....\.......\.......\CJ60Lib.dsw
.....\.......\.......\CJ60Lib.positions
.....\.......\.......\CJ60Lib.rc
.....\.......\.......\CJ60StaticLib.dsp
.....\.......\.......\CJCaption.cpp
.....\.......\.......\CJControlBar.cpp
.....\.......\.......\CJDockBar.cpp
.....\.......\.......\CJDockContext.cpp
.....\.......\.......\CJExplorerBar.cpp
.....\.......\.......\CJFlatButton.cpp
.....\.......\.......\CJFlatComboBox.cpp
.....\.......\.......\CJFlatHeaderCtrl.cpp