I have developed a variation of Dayznavigator called
R0Nav, which can run in hidden and unnoticed for BE. The same works thanks to an injection of type ring0 hiding all threads of the process set (in this case a browser). As you know BE scans system memory sniffing modifications but with this, running in kernel mode, it can not detect the presence of the original
DayzNav code by sd (for now injected only in Firefox). I have verified that it works undetectable from 2 months ago. Unfortunately I'm afraid to publish the program because it is still in testing stage and there is a risk (minimum) to account ban.
I would also have to fix performance problems (a fall of approximately 25% of fps, which for now I can not patch -EDIT: Now FIXED-). Please I ask administrators to advise me what to do. Those who want to help me with testing -at your own risk- please let me know (you must have: 32 bit OS version, XP or 7 only) . You may wonder if it will be free, I reply that while I have time it will. Sorry for my poor English. Greetings from Argentina.
Confirmed: Release date: 11/5/2012
Part of the code that compiles part of ring0 driver:
Code
Code:
#include <ntddk.h>
#include "process.h"
typedef unsigned char BYTE, *PBYTE;
WCHAR *ProcessToHide[128];
ULONG NbProcessToHide=0;
ZWQUERYSYSTEMINFORMATION ZwQuerySystemInformationAddress = NULL;
LONGLONG UserTime=0, KernelTime=0;
NTSTATUS ZwQuerySystemInformationHook(
IN ULONG SystemInformationClass,
IN PVOID SystemInformation,
IN ULONG SystemInformationLength,
OUT PULONG ReturnLength)
{
NTSTATUS status;
PSYSTEM_PROCESS_INFORMATION curr;
PSYSTEM_PROCESS_INFORMATION prev;
ULONG i;
status = ((ZWQUERYSYSTEMINFORMATION)(ZwQuerySystemInformati onAddress)) (
SystemInformationClass,
SystemInformation,
SystemInformationLength,
ReturnLength );
if( !NT_SUCCESS(status) )
return status;
if(SystemInformationClass!=5) // not a process request
return status;
for(i=0; i<NbProcessToHide; i++) {
curr = (PSYSTEM_PROCESS_INFORMATION)SystemInformation;
prev = NULL;
while(curr) {
//DbgPrint("Current item is %x\n", curr);
if (curr->ProcessName.Buffer != NULL) {
if( curr->ProcessName.Length == wcslen(ProcessToHide[i])*2 &&
!memcmp(curr->ProcessName.Buffer,ProcessToHide[i], curr->ProcessName.Length))
{
if(!prev) {
// we are first process
if(curr->NextEntryDelta) // if there is a process after it
// first process becomes this one
(PBYTE)SystemInformation += curr->NextEntryDelta;
else
// no process ! >_>
SystemInformation = NULL;
}
else {
// there was a process before
if(curr->NextEntryDelta) // if there is a process after
// previous process leads to next
prev->NextEntryDelta += curr->NextEntryDelta;
else
// previous process is the last one =)
prev->NextEntryDelta = 0;
}
}
else
// not a process to hide, prev ptr go to this process
prev = curr;
}
// curr go to next process
if(curr->NextEntryDelta)
((PBYTE)curr += curr->NextEntryDelta);
else
curr = NULL;
}
}
return status;
}