This Malware Invades the KERNEL?

Поділитися
Вставка
  • Опубліковано 2 лют 2025

КОМЕНТАРІ • 313

  • @monobrow538
    @monobrow538 2 місяці тому +581

    That's genius using Adobe as a cover for crypto miner,
    Since it's normal for Adobe to hog processing power

    • @theloststarbounder
      @theloststarbounder 2 місяці тому +130

      It's also normal for adobe to fill your PC with spyware and rootkits that keeps calling home (if you do the mistake to buy it)

    • @Block_Piano
      @Block_Piano 2 місяці тому +73

      @@theloststarbounder Adobe is worse, it also takes your money.
      The fake may be less harmfull than the oregano.

    • @rob2rox
      @rob2rox 2 місяці тому +29

      stealthy crypto mining malware will just stop mining once task manager is opened and resume when closed

    • @djsweglord9909
      @djsweglord9909 2 місяці тому

      @@rob2roxthere’s other programs besides task manager to check

    • @Reac2
      @Reac2 2 місяці тому +20

      You're halfway there to realising that Adobe is today's most popular malware

  • @TotallyNotInsomniac
    @TotallyNotInsomniac 2 місяці тому +904

    I hope this Kernel guy is okay

    • @anonimenkolbas1305
      @anonimenkolbas1305 2 місяці тому +184

      "Today we're going to be doing penetration testing on the kernel"
      The Colonel: 😳😳

    • @simo_viewer_pr9030
      @simo_viewer_pr9030 2 місяці тому +30

      kernel sanders

    • @defacube
      @defacube 2 місяці тому +1

      Same bro

    • @undefinedCat
      @undefinedCat 2 місяці тому +19

      @@simo_viewer_pr9030 can't believe they're gonna hack kfc

    • @kirill9064
      @kirill9064 2 місяці тому +15

      Colonel Panic is reporting to General Failure.

  • @45545videos
    @45545videos 2 місяці тому +226

    I know you're in a VM, but I can't imagine ever using a browser without uBlock Origin. Just too much shit.

    • @vladik_yt3186
      @vladik_yt3186 2 місяці тому

      Also if you have some time to practice you can try NoScript, it often fucks up "please disable adblock" thing so it doesn't even shows
      P. S. Idk about UA-cam anti adblock cus I don't use YT on PC

    • @runed0s86
      @runed0s86 2 місяці тому +34

      How tf does this guy live? Over 40% of his page is whitespace and ads 😭

    • @psyclonepman
      @psyclonepman 2 місяці тому +43

      he probably uses the ads to get samples

    • @SniperAWP
      @SniperAWP 2 місяці тому

      i use malwarebytes browser guard works well lmao

    • @NiyaKouya
      @NiyaKouya 2 місяці тому +4

      Well, since he uses Chrome, thanks to the manifest v3 update he can't use a (proper) ad blocker any more anyway :P

  • @NoHandlebars87
    @NoHandlebars87 2 місяці тому +222

    Only kernels I invade is the popcorn kind

    • @drdoubleU
      @drdoubleU 2 місяці тому +19

      Leave the popcorn out of this.

  • @invghost
    @invghost 2 місяці тому +67

    "There's not much risk or installing a kernel level anti-cheat or a kernal level driver in general"
    One sentence. "Crowdstrike wasn't malicious."
    A kernel level process caused so much havoc and that was a simple woopsy daisy we messed up situation. A bad actor with an in at any of these companies could very easily destroy lives.
    Kernel access is given away far too easily and anyone who says otherwise is ignorant of technology.

    • @joopie46614
      @joopie46614 2 місяці тому +5

      When you say it's given away far too easily, I'm not sure if you're referring to Microsoft/Windows signing these drivers, the companies installing the software or users installing drivers, but you can't exactly gate keep kernel level access.

    • @AkisakuLP
      @AkisakuLP 2 місяці тому

      Scrolled to far down to see this. Based opinion.

    • @AkisakuLP
      @AkisakuLP 2 місяці тому

      ​@@joopie46614all three. MS signing a Kernel Level process that basically parses definitions feels like a giant security flaw. Companies/individuals just installing it without critical thinking 'what could go wrong?' is also too easily done.
      Sure MS can't gatekeep kernel level, but also they should atleast be aware that they have ppl relying on their stamp of approval as well as end users should be aware that such systems can lead to such problems.

    • @Kakerate2
      @Kakerate2 Місяць тому +1

      yeah i was done with league after they wanted kernel anticheat in there lol

  • @mu11668B
    @mu11668B 2 місяці тому +123

    I kinda find it funny people complain about kernel level anti-cheats without mentioning proper privilege controls. Under a standard user account, both UAC bypass and BYOVD will fail. I still argue that kernel anti-cheats are unacceptable, as they break the basic privilege control concepts (a game should not have administrative privilege access). But most complaints I've seen on the internet don't even mention about using a low-privilege account as a security measure, and running random things on an admin account is just as bad as any kernel level access.

    • @belgiumball2308
      @belgiumball2308 2 місяці тому +17

      mfw bios anticheat:

    • @v01d_r34l1ty
      @v01d_r34l1ty 2 місяці тому +12

      the issue is with vulnerability in Anti-Cheats. if Anti-Cheat is exploited, it is Ring 0 access. Now consider all the games with RCEs that went unpatched for weeks or months.

    • @fux3669
      @fux3669 2 місяці тому

      I have a question: what kind of account do I have, if I installed windows 11 clean and never messed around with administrator settings ?

    • @tezcanaslan2877
      @tezcanaslan2877 2 місяці тому

      ⁠@@fux3669 you are admin by default

    • @mu11668B
      @mu11668B 2 місяці тому

      @@fux3669 The default OOB account on Windows is an admin account. You have to go to the settings and explicitly create a new non-admin user account.

  • @rob2rox
    @rob2rox 2 місяці тому +53

    sometimes i wonder why anti cheat providers dont just start flagging malware as well. seems like theyd do a better job compared to half of other AVs

    • @brawldude2656
      @brawldude2656 2 місяці тому +30

      Lmaoo imagine riot games sending tou notifciations about how many attacks they protected you from

  • @JJFX-
    @JJFX- 2 місяці тому +61

    Jokes on them, mine was promoted to GENEREL.
    I'll see myself out.

    • @chipproductions1510
      @chipproductions1510 2 місяці тому

      General, to correct you.

    • @JJFX-
      @JJFX- 2 місяці тому +6

      @@chipproductions1510 Kernel Sanders is telling me otherwise.

  • @BigMunchGSC
    @BigMunchGSC 2 місяці тому +58

    They ought to add killswitches if the current user is "lain" at this point

    • @monad_tcp
      @monad_tcp 2 місяці тому +7

      but what if a legitimate fan of "serial experiments lain" could have been exploited with a cryptominer

    • @BigMunchGSC
      @BigMunchGSC 2 місяці тому +5

      More user protection hah

    • @karanshome
      @karanshome Місяць тому

      Well that'd be bad for me since I've lain with your mother

  • @Honeystraw
    @Honeystraw 2 місяці тому +38

    When I’m in a system-breaking vulnerability competition and my opponent is Windows

    • @cltuxunink
      @cltuxunink Місяць тому

      theyre left there for the cia to use

  • @Gamer_Victorch
    @Gamer_Victorch 2 місяці тому +41

    6:43 Famous Last Words from @Eric Parker for the unpacking

  • @isoettes
    @isoettes 2 місяці тому +15

    I'd rather have a Bitcoin miner then pay for Adobe.

  • @paws-at-you
    @paws-at-you 2 місяці тому +206

    paws at everyone

    • @Ozzymand
      @Ozzymand 2 місяці тому +9

      why are you

    • @kiraaaaaa
      @kiraaaaaa 2 місяці тому +27

      Thank you popular Eric Parker comment section micro celebrity Luna "paws-at-you" Paws At You

    • @kiraaaaaa
      @kiraaaaaa 2 місяці тому +8

      :3

    • @lunalght
      @lunalght 2 місяці тому +7

      paws back

    • @ash-b1x4s
      @ash-b1x4s 2 місяці тому +6

      :3

  • @Sharpless2
    @Sharpless2 2 місяці тому +28

    The risk is substantially higher once a kernel mode driver is signed by microsoft or any reputable signing authority. The problem isnt the kernel itself but rather that Microsoft even allows running code in kernel mode in the first place.

    • @bltzcstrnx
      @bltzcstrnx 2 місяці тому +1

      Even GNU/Linux allows third-party codes to run in kernel space. Only macOS, iOS, and Android in their default configurations (non-rooted, etc.) that don't allow this. My guess is, a lot of people will complain if Microsoft really as strict as those OSes in Windows.

    • @sceerane8662
      @sceerane8662 2 місяці тому +4

      ​@@bltzcstrnx AFAIK while the Linux kernel *does* let you load kernel modules arbitrarily, It only permits modules it was configured in advance to accept. To load anything else in you need to change that configuration and reboot (effectively bypassing the kernel and its restrictions anyway)

  • @monad_tcp
    @monad_tcp 2 місяці тому +7

    Its kinda really smart to target Jetbrains IDE because it already comes with a kernel debugger that's actually WQHL signed.

  • @SoSheolH
    @SoSheolH 2 місяці тому +5

    was helping a friend troubleshoot earlier today after he seemed to have gotten a trojan from an .exe adobe premiere crack setup on a youtube video
    didn't show up in malwarebytes, random ml trojan on windows defender, and despite trying for like an hour to un-quarantine the file and scan it with virustotal he just kept getting denied permissions
    coincidentally this pops up in my recommended later on - getting him on a clean wipe rn

  • @GloombertGoat
    @GloombertGoat 2 місяці тому +11

    Great work tracking it down yourself! The analysis is thorough as usual.

  • @jammerhammer1953
    @jammerhammer1953 2 місяці тому +6

    Wait, JetBrains is an IDE?
    I thought that it was just the name of a font I use on neovim

  • @RustFae
    @RustFae Місяць тому

    I love this type of content!! Please keep making these malware dissections.

  • @3_letter_animal
    @3_letter_animal 2 місяці тому +11

    I have to listen to the video instead of watching it, that white background is killing me. (yes, my HDR is on and I could night shift it to workaround, but cmone...)
    I liked it, ty!

    • @no_name4796
      @no_name4796 2 місяці тому +2

      We are going blind with this one 🗣🗣🗣🔥🔥🔥

    • @pochou8261
      @pochou8261 2 місяці тому

      Why adjusting brightness isn’t an option?

  • @saltyowl3229
    @saltyowl3229 Місяць тому +2

    YES, there IS risk to installing kernel level anticheats. Multiplayer games end up with RCE Exploits ALL the time. If a kernel mode anticheat is ever accidentally (or intentionally. They’re all big fans of “security” through obscurity, and could easily exploit these permissions) exposed to this, your entire machine can be hijacked for playing a game, or even just having the game installed, since most kernel level anticheats run from boot time. Do not downplay the irresponsibility and risk of a GAME demanding full and complete access to your entire computer.

  • @sergeivanov-x7q
    @sergeivanov-x7q 2 місяці тому +4

    every time i get my dinner you post love the videos

  • @SniperAWP
    @SniperAWP 2 місяці тому +5

    Why do people try to get cracked copies of jetbrains when it is so easy to find a license server to use? It is literally on the surface web such as yandex google etc. I can't deal with these types of people and it frusteruates me

  • @NoxernPL
    @NoxernPL 2 місяці тому +17

    Where did you get the sample from? Do you host malware samples somewhere?

    • @EricParker
      @EricParker  2 місяці тому +19

      googling the payload name

    • @NoxernPL
      @NoxernPL 2 місяці тому +8

      @@EricParker Thanks, I completely missed the part when you said that you found it on github

  • @lilkovou7230
    @lilkovou7230 2 місяці тому +23

    Kernal level is insane

  • @starryspace0
    @starryspace0 2 місяці тому +12

    Waiting for Eric to check if NTSCQT is safe or not (VirusTotal says it is)

    • @EricParker
      @EricParker  2 місяці тому +2

      check the source?

    • @starryspace0
      @starryspace0 2 місяці тому +2

      @@EricParker I saw it in a youtube video a lot of people agreed it worked and some had videos on their channels, still not sure.

    • @elrymoe
      @elrymoe 2 місяці тому +4

      @@EricParker Yes just go trough all of the code lol

  • @FireFusionYT_0
    @FireFusionYT_0 2 місяці тому +4

    @ 17:03 I don't have that option. Enterprise Win11?

  • @petertech210
    @petertech210 2 місяці тому +1

    He needed to go to the Kernel to get the recipe.

  • @ardwetha
    @ardwetha 2 місяці тому +12

    Why does windows not block those vulnerable drivers?

    • @kirill9064
      @kirill9064 2 місяці тому +3

      I think it blocks them if memory integrity is enabled.

    • @CstrikeH4X
      @CstrikeH4X 2 місяці тому +2

      There are thausands of drivers with vulnerabilities from thausands of companies. Even Windows Defender has one. No way to stop this.

    • @CstrikeH4X
      @CstrikeH4X 2 місяці тому +1

      @@kirill9064 Yes, this is correct.

    • @tpd1864blake
      @tpd1864blake 2 місяці тому +3

      @@kirill9064 one in a krillion

    • @EricParker
      @EricParker  2 місяці тому +17

      Because some of them are for hardware that might never be updated. People would be more upset if they were blocked, but you can opt into the blocklist.

  • @tato-chip7612
    @tato-chip7612 2 місяці тому +6

    neovim activator exe when

  • @granturismo3wasgreat
    @granturismo3wasgreat 2 місяці тому +1

    i literally don't understand anything this guy says in videos like these but for some reason i still love it lol

  • @Verylegitplayer1789
    @Verylegitplayer1789 2 місяці тому +4

    Can u make a video on Solstice client its a minecraft bedrock client that flags alot as trojans but still the client has a very large player base.

  • @Arin_Hana
    @Arin_Hana 2 місяці тому +3

    Have you ever feel like the malware escaped from vm?
    Or im just too paranoid

    • @psyclonepman
      @psyclonepman 2 місяці тому +6

      it's possible but extremely unlikely to happen, most malware if anything just refuses to run on a vm

    • @xgui4-studios
      @xgui4-studios Місяць тому

      Too paranoid

    • @heckerhecker8246
      @heckerhecker8246 26 днів тому

      it's possible the the software for said VM has an exploit

  • @Sparky_Otter
    @Sparky_Otter 2 місяці тому +18

    Windows kernel more vulnerable than the Linux kernel

    • @TheUncleTedKzy
      @TheUncleTedKzy 2 місяці тому +1

      Linux will never be as popular as Mac and Windows, buddy.

    • @monad_tcp
      @monad_tcp 2 місяці тому +3

      No, its not. Windows Kernel is not more vulnerable than Linux Kernel.
      The guy literally did "sudo install and installed a '.ko' "
      Driver signing isn't even activated by default on most Linuxes distros.
      The Windows user interface might be more vulnerable than KDE (but not Gnome).
      Maybe if you are running SELinux and know what you are doing you can make the Linux Kernel become more secure, but the same is true for Windows, but its absolutely less vulnerable. Both are micro-kernels after all. Its a huge surface of attack.
      People keep saying that the Linux kernel is more secure. The Windows Kernel is absolutely a very well designed and very secure piece of software. Most of the 0-days that happens on Windows are always other weak components running in user mode that allow for privilege escalation, usually because Windows is huge and have a huge surface of attack, so there's always misconfigured permissions.
      Ironically the same thing happens to SELinux all the time, except Linux is a 10 times smaller system, and has 1000 times less users.
      Any system is always insecure as its weakest link, the kernel is not the weakest link.
      I hate people keep saying shit like that, meanwhile I broke the security of my TV the other day, why, the encoder driver running on Linux Kernel Ring0 instead of Ring3. Stupid monolith kernel systems where a mistake.

    • @Z_fentomFentom
      @Z_fentomFentom 2 місяці тому

      ​@@TheUncleTedKzyokay????😂😂

    • @QWERTIOX
      @QWERTIOX 2 місяці тому +2

      ​@@TheUncleTedKzykinda wrong, linux is the most popular kernel for servers

    • @giakhanhvn2mc
      @giakhanhvn2mc 2 місяці тому +2

      @@monad_tcpif MS just open up the windows kernel it’d have real competition with linux (headless windows NT)
      There’s absolutely nothing wrong with the windows kernel, it is the shell of windows that is buggy and vulnerable (user mode). Windows kernel is extremely secure and powerful

  • @theairaccumulator7144
    @theairaccumulator7144 2 місяці тому +4

    Why can't Microsoft revoke the certificate for insecure drivers?

    • @__Brandon__
      @__Brandon__ 2 місяці тому +8

      You would have to download the certificate revoke list. At the end of the video he shows how to enable the blacklist which is the certificate revoke list. It isn't enabled by default because it would break a lot of existing systems

  • @Wiyt
    @Wiyt 2 місяці тому +15

    Being a Valorant player FINALLY paid off in some way. Thanks Eric!

    • @Votexforxme
      @Votexforxme 2 місяці тому +5

      Sorry to hear that you play this garbage.

    • @Wiyt
      @Wiyt 2 місяці тому +2

      @@Votexforxme Sorry that you don’t have more love in your heart.

    • @Votexforxme
      @Votexforxme 2 місяці тому +1

      @@Wiyt Yeah, i dont share "love" with companys that abloslutley dont value their customers.

    • @Wiyt
      @Wiyt 2 місяці тому +1

      @@Votexforxme I could care less if you support Riot or any other company, rando. It’s just sad how negative you are. But that’s okay, I hope you have a good day m8.

    • @dead-l0lz
      @dead-l0lz 2 місяці тому

      @@Votexforxmeforever virgin

  • @Roizor
    @Roizor 2 місяці тому +7

    i could’ve sworn i saw this yestersy

    • @alfonzo7822
      @alfonzo7822 2 місяці тому +2

      Different channel maybes?

    • @SidneyM559
      @SidneyM559 2 місяці тому +2

      mightve been low level learning's video if you watch him

    • @Roizor
      @Roizor 2 місяці тому +1

      @ oh yeah you’re right that’s where i saw it

  • @TheLastDMA
    @TheLastDMA 2 місяці тому

    Can we get an updated tutorial on the stealth VM?

  • @kiriowastaken
    @kiriowastaken 2 місяці тому +2

    not mentioned but, LAIN?!!

  • @x1hax
    @x1hax 2 місяці тому +2

    Thanks Eric this is really intresting

  • @b1.7.3
    @b1.7.3 2 місяці тому +3

    Ubuntu Linux activator for Windows next?

  • @marcocaspers3136
    @marcocaspers3136 2 місяці тому +23

    C is not unsafe. Incompetent programmers are.

    • @jacksoncremean1664
      @jacksoncremean1664 2 місяці тому +10

      Software always has bugs

    • @CommandoBlack123
      @CommandoBlack123 2 місяці тому +8

      C is unsafe because an incompetent programmer can make a vulnerable application easily

    • @chaoticsoap
      @chaoticsoap 2 місяці тому +7

      @@CommandoBlack123 so... any language

    • @CommandoBlack123
      @CommandoBlack123 2 місяці тому +1

      @@chaoticsoap Not true

    • @brawldude2656
      @brawldude2656 2 місяці тому +9

      ​@@CommandoBlack123literally true youcan write an unsafe program in any language. Some are just harder

  • @oflameo8927
    @oflameo8927 2 місяці тому

    Kernel Level Anticheat doesn't need to exist.

  • @50PullUps
    @50PullUps 2 місяці тому +4

    13:32 the hash is slightly different.
    Oh the hash is only *slightly* different 🤨

  • @BGDMusic
    @BGDMusic 2 місяці тому +1

    ms windows is the true kernel level malware

  • @crispycritical
    @crispycritical 2 місяці тому +1

    dont worry thats just the new riot anti-cheat update

  • @lilia_spn
    @lilia_spn 2 місяці тому +1

    why does erics accent change from british english to american english halfway through? just curious lol

  • @ardwetha
    @ardwetha 2 місяці тому +4

    Vanguard makes a better job than windows defender gg.

  • @scratchislifeoriginal
    @scratchislifeoriginal 2 місяці тому +4

    Kernel wants to know:
    🚨Why TF are you downloading viruses

  • @2Kayz177
    @2Kayz177 15 днів тому

    I have jetbrains… better be the right one bro

  • @xwinglover
    @xwinglover 2 місяці тому

    Plot twist: The real malware is Windows... Steelfox is trying to hijack the telemetry processes back off the Windows kernel to save your PC

  • @MoiiE801
    @MoiiE801 2 місяці тому

    I don't understand any of the words he was saying but I appreciate it

  • @suiware
    @suiware 2 місяці тому

    hey, could you look if roblox account manager is a virus? alot of people say it is but some also say its just a false flag

  • @xoxogamewolf7585
    @xoxogamewolf7585 2 місяці тому +2

    weren't there viruses that could invade the BIOS?

    • @Redstoneprojrjr
      @Redstoneprojrjr 2 місяці тому +1

      It’s very rare because you have to specifically target a specific motherboard and it’s version

    • @xgui4-studios
      @xgui4-studios Місяць тому

      Logofail can

  • @ethanturner5298
    @ethanturner5298 2 місяці тому

    Never thought that Vanguard would actually be helpful 🙏🙏🙏

  • @ImmortalPaladin
    @ImmortalPaladin 2 місяці тому

    Love your vids! You should make some troll malware that will just prank people and not harm anything

  • @windws7137
    @windws7137 2 місяці тому +3

    I installed many cracks and am worried now

    • @CommandoBlack123
      @CommandoBlack123 2 місяці тому +5

      As you should be. You should have been worried when you installed them, not now lol

    • @Stormer-vx5kw
      @Stormer-vx5kw 2 місяці тому

      just dont put them on your main system lol

    • @spit.or.swaIIow
      @spit.or.swaIIow 2 місяці тому +1

      This is recent and of course should mostly been in new strains of cracks like modified copies of Medicine, etc

  • @Rift_Walker_Lombax
    @Rift_Walker_Lombax 2 місяці тому

    Your just amazing how you can explain how everythings works

  • @Чумак-щ8и
    @Чумак-щ8и 2 місяці тому +2

    Hello Eric!

  • @LunarLambda
    @LunarLambda 28 днів тому

    "win ring zero dot sys" is an incredible name for a vulnerable driver

  • @Neuromancerism
    @Neuromancerism 2 місяці тому +1

    Wrong. Yes, anticheat is evil. Bethesda shouldve been removed from being allowed on steam after what they did with Doom Eternal.

    • @AraiDigital
      @AraiDigital 2 місяці тому

      that wasn't anticheat, that was drm afaik, two different things

    • @Neuromancerism
      @Neuromancerism 2 місяці тому

      @@AraiDigital It was denuvo anticheat.

  • @VarVarJeg
    @VarVarJeg 2 місяці тому

    Isnt that what vanguard anti cheat does?

  • @UrokLizard
    @UrokLizard Місяць тому

    winring0x64 is spelled wrong 13:10

  • @shortformediocreweirdo
    @shortformediocreweirdo 2 місяці тому

    linux users like me are invading more kernels using the "hand" exploit right now

  • @D3ltaLabs
    @D3ltaLabs 2 місяці тому

    I enjoyed this episode that much, I watched it twice. ❤

  • @richie7425
    @richie7425 28 днів тому

    1.03 Just no, shows a lack of understanding of how kernel drivers work. Venerable kernel drivers are a massive problem. They should not exist! C isn't unsafe...

  • @JeSuisGrenouille
    @JeSuisGrenouille 2 місяці тому +1

    Based Riot Vanguard (for once)

  • @v4n1ty92
    @v4n1ty92 Місяць тому

    I thought most malwares these days ran at kernel level? Isn't that why most anti-virus software runs on the kernel?

    • @VivaPlaysGames
      @VivaPlaysGames Місяць тому

      Almost zero modern malware runs at the kernel level. Rootkits are few and far between.

  • @giridharpavan1592
    @giridharpavan1592 2 місяці тому

    jerbrains with zombies

  • @tobiiorigami
    @tobiiorigami 2 місяці тому

    just in time for dinner

  • @Votexforxme
    @Votexforxme 2 місяці тому +1

    "This Malware Invades the KERNEL?" so any Kernel level aticheat that also does not really prevent cheating.

  • @Sahil_Bhandari
    @Sahil_Bhandari 2 місяці тому +1

    wow what a wonderful piece of code haha!

  • @xmclover
    @xmclover 2 місяці тому

    Can you do more fake download buttons

  • @petrplay5009
    @petrplay5009 2 місяці тому

    F for my popcorn 🍿

  • @theloststarbounder
    @theloststarbounder 2 місяці тому

    Oh so it means the freshly installed Windows 10 is having rootkits and bootkits and kernel trojans already I'm not allowed to run anything other than the very latest version, I tried deleting program compatibility assistant trojan but couldn't fully remove it...

  • @lifehacksukgaming5773
    @lifehacksukgaming5773 2 місяці тому

    Seroxen and darkgate are best rat so far ❤ 🎉

    • @BowInf
      @BowInf 2 місяці тому

      seroxen is discontinued but true

    • @EricParker
      @EricParker  2 місяці тому

      Darkgate is just a loader? currently dealign with one.

  • @Os.-
    @Os.- 2 місяці тому +1

    I continued watching but no cookie!

  • @nerd3131
    @nerd3131 2 місяці тому +1

    that's crazy

  • @AdaptedClouds
    @AdaptedClouds 2 місяці тому +3

    crazy

  • @vroometernal
    @vroometernal 2 місяці тому +4

    smh why waste 3 hours trying to dump it from the loader, when you can just dump the process using a kernel driver

    • @dead-l0lz
      @dead-l0lz 2 місяці тому +13

      go back to reviewing awful minecraft clients lil bro

    • @dafoc6418
      @dafoc6418 2 місяці тому +5

      @@dead-l0lz😭

    • @vroometernal
      @vroometernal 2 місяці тому

      @@dead-l0lz only minecraft video is my own project from long ago, the others are cracks

    • @vroometernal
      @vroometernal 2 місяці тому

      @@dead-l0lz kinda funny u switched topic, imagine learning from a guy who doesnt know what he is talking about stupid ahh

    • @windws7137
      @windws7137 2 місяці тому +5

      @@dead-l0lz Savage☠

  • @pncka
    @pncka 2 місяці тому

    kernelwaaaaaaaaaaaaa
    -poland

  • @bruhhy-111
    @bruhhy-111 2 місяці тому +2

    Hi

  • @kosratbaway3119
    @kosratbaway3119 2 місяці тому

    How much knowledge you need to be able to learn from your skool?

  • @fennoman9241
    @fennoman9241 2 місяці тому +8

    I use arch btw.

    • @brawldude2656
      @brawldude2656 2 місяці тому +5

      You are not safe either
      Check your door.

  • @quogxd
    @quogxd 2 місяці тому

    hmmm

  • @95DreadLord
    @95DreadLord 2 місяці тому +3

    At least someone recognizes that kernel level anti cheat isn't inherently bad. Riot games gets so much shit for being first to openly claim kernel level anti cheat when the haters have been running other kernel level anti cheat just fine until now

    • @wietvergiet
      @wietvergiet 2 місяці тому +1

      Riot was far from the first to do it. ESEA for counterstrike has been doing it for a decade, and FACEIT has been doing it for a long time as well. The only difference is that Riot markets it as if it's something new.

    • @LiEnby
      @LiEnby 29 днів тому

      No if is inherently bad, its blindly trusting the client and its security through obscurity

  • @brys6577
    @brys6577 2 місяці тому

    Andrew tate?

  • @NightTerrorYT
    @NightTerrorYT 2 місяці тому +1

    Nu e nimic nou frate

  • @Nickerarx
    @Nickerarx 2 місяці тому +1

    this is same as vanguard lol

    • @elrymoe
      @elrymoe 2 місяці тому +1

      are you stupid, vanguard is safe

  • @Lorh_o
    @Lorh_o 2 місяці тому

    WOOOOOOOO

  • @aab.videos
    @aab.videos 2 місяці тому +3

    ....riot vanguard

    • @elrymoe
      @elrymoe 2 місяці тому +1

      is not a malware, but an anticheat you dumbass

    • @berkekadircelik6282
      @berkekadircelik6282 2 місяці тому +1

      The best antivirus

  • @Dailystories2789
    @Dailystories2789 2 місяці тому +1

    activate windows -_-

  • @yung-megafone
    @yung-megafone 2 місяці тому +1

    Ahh, i love kernels
    Oh wait this isnt a corn tutorial 🌽 :/

  • @vroometernal
    @vroometernal 2 місяці тому +1

    6:39 this guy doesn't know what he is talking about 😂

    • @Sharpless2
      @Sharpless2 2 місяці тому +8

      one shouldnt judge a book by its cover, but... If we take a look at your pfp, your name, the content you upload and the date your account was made, we conclude that you are AT MOST 16 years old and that you have no real world experience whatsoever. You really shouldnt be talking like that. Thats the type of behavior that gets you in trouble.

    • @AraiDigital
      @AraiDigital 2 місяці тому

      They don't know? Alright, explain this to us! I'd like to see you even try to take a crack at it.

    • @vroometernal
      @vroometernal 2 місяці тому

      ​@@AraiDigital he says oh it has "VirtualProtect" it should be easy to unpack. virtual protect is an api for changing protection of a memory region, most of the time its not even being used by malware because they use direct syscalls. so if it was so easy why didnt he put a bp on virtualprotect and dumped it from there and ended the video in 3mins? The fact that he said if you dont wanna spend 3 hours unpacking it like me go join my school is hilarious lmao. Literally all you had to do is use dump the process from kernel 💀

  • @jammerhammer1953
    @jammerhammer1953 2 місяці тому

    Wait, JetBrains is an IDE?
    I thought that it was just the name of a font I use on neovim

  • @RandomytchannelGD
    @RandomytchannelGD 2 місяці тому +2

    Hi