Nytro Posted August 6, 2013 Report Posted August 6, 2013 (Syscall IDP Engine).Captures all system services(KDR, hidden). Returns control on specified address(int 0x2e/sysenter -> PEB.Filter()). By calling the backdoor control is returned to the kernel(Filter() -> backdoor() -> nt service dispatcher).o X86, KM, MI, KDR.o May be choose SST[0], SST[0] for gui-thread, SST[1] for shadow.Vid Video2.avi — RGhost — ?????????????Org VX ForumSIDE.zipSursa: SIDE. Quote