Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- The software adds a VMProtect shell, may be some anti-virus software will be reported ... ... Please rest assured that the use of drugs, this is anti-virus software false positives.
- On the software: a puming to (Beijing) Information Technology Co., Ltd., the user is free to use, copy, distribute, disseminate, but did not obtain written authorization author is prohibited for commercial purposes; in addition ban the software used for malicious purposes (for example, As part of the Trojan virus, crack Internet cafes charging system, etc.).
- The use of this software, you need to understand: If you use the software, to you directly or indirectly cause losses, damage, the Company is not responsible. From the moment you use the Software, you will be deemed to have accepted this Disclaimer.
- This software supports XP ~ Win8.1 of all 32-bit system, also supports Win7 ~ Win8.1 64-bit system.
- / ----------------------------- For some reason, this software does not provide a "modifiable system" function command. To use these features, use the PC Hunter interface version ----------------------------- /
- Instructions:
- 1. Direct PCHunter_Cmd.exe run, this will enter into a loop, the cycle repeatedly receive user input commands, exit this cycle, it will automatically uninstall the driver.
- 2.PCHunter_Cmd.exe with parameters to run, this will execute the specific parameters of the command, the program quits, it will uninstall the driver.
- 3. Professional users can key file into PCHunter_Cmd.exe, so you can use some of the special version of the command-specific.
- 4. The software use time: 2013.11.25 ~ 2014.11.24
- Standard version of the specific instructions:
- 1.usage
- No parameters, lists all currently available commands
- 2.tasklist
- No parameters, enumeration process
- 3.ps
- And tasklist equivalent
- 4.lpm
- Two parameters, the first is the decimal process id, the second is the process of hexadecimal object address, the process of enumeration of the order of the module
- 5.lpt
- Two parameters, the first is the decimal process id, the second is the hexadecimal process object address, this command enumeration process thread
- 6. qpsr
- Two parameters, the first is the decimal process id, the second is the hexadecimal process object address, the order of the process of blocking the state of wake-up
- 7.sp
- Two parameters, the first is the decimal process id, the second is the hexadecimal process object address, the command to block the process
- 8.rp
- Two parameters, the first is the decimal process id, the second is the hexadecimal process object address, the command to wake up the blocking process
- 9.qtsr
- Two parameters, the first is the decimal thread id, the second is the hexadecimal thread object address, the command query thread wake-up blocking state
- 10.st
- Two parameters, the first is the decimal thread id, the second is the hexadecimal thread object address, the command block thread
- 11.rt
- Two parameters, the first is a decimal thread id, the second is the hexadecimal thread object address, the command to awaken the blocked thread
- 12.lph
- Two parameters, the first is the decimal process id, the second is the hexadecimal process object address, the command enumeration process handle
- 13.lw
- No arguments, this command enumerates the process window
- 14.lpmemory
- Two parameters, the first is the decimal process id, the second is the hexadecimal process object address, the command enumeration process memory information
- 15.lptimer
- No argument, this command enumerates the process timer
- 16.lphk
- No arguments, this command enumerates the process hotkey
- 17.lkm
- No argument, this command displays the kernel module information
- 18.ckmemory
- Three parameters, the first module is hexadecimal base address, the second is to copy the byte size, the third is the output file name, the command copy the kernel memory
- 19.freboot
- No parameters, the order to restart the computer
- 20.mfreboot
- No parameters, this command is more violent forced restart the computer
- 21.ssdt
- You can use the / all parameter to display all, otherwise only show linked to the function, this command shows SSDT
- 22.shadowssdt
- You can use the / all parameter to display all, otherwise only show linked to the function, this command shows Shadow SSDT
- 23.fsd
- You can use the / all parameter to display all, otherwise only show linked to the function, this command shows the FSD
- 24.tcpip
- You can use the / all parameter to display all, otherwise only show hook function, this command shows TCPIP hook
- 25.kbd
- You can use the / all parameter to display all, otherwise only show hook function, this command shows the hook on the Keyboard
- 26. idt
- You can use the / all parameter to display all, otherwise display only hook-up function, this command shows the hook on the IDT
- 27.objecttype
- You can use the / all parameter to display all, otherwise only show linked to the function, this command shows ObjectType on the hook
- 28.objecttype_callback
- You can use the / all parameter to display all, otherwise display only hooks. This command displays the hooks on the ObjectType Callback
- 29.hhive
- You can use the / all parameter to display all, otherwise only show linked to the function, this command shows HHIVE hook
- 30.callback
- You can use the / all parameter to display all, otherwise only show the hook function, this command displays \ Callback directory tree hook on the object
- 31.nr
- No parameter, this command lists the Notify Routine
- 32.port
- No argument, this command lists the port information
- 33.mbr
- No argument, this command checks the MBR rootkit
- 34.classpnp
- You can use the / all parameter to display all, otherwise only show the hook function, this command shows the classpnp on the hook
- 35.atapi
- You can use the / all parameter to display all, otherwise only show the hook function, this command shows the hook atapi
- 36.acpi
- You can use the / all parameter to display all, otherwise only show hanging enough function, the command shows the hook acpi
- 37.dpctimer
- No parameter. This command displays the DPC timer information
- 38.filter
- No parameters, this command enum filter filter driver
- 39.messagehook
- No argument, the command displays the message hook
- 40.sigcheck
- A parameter, which is a file path, is used to digitally sign a file
- 41.processhook
- Two parameters, the first is the decimal process id, the second is the hexadecimal process object address, the command enumeration process Hook
- 42.processapfn
- Two parameters, the first is the decimal process id, the second is the hexadecimal process object address, you can use the / all parameter that shows all, or only show the hook function, the command enumeration process Apfn
- 43.kernelhook
- No arguments, this command enumerates the kernel module Hook
- 44.copy
- Two parameters, the first is the existence of the file path, the second is the new file path, the command to copy the file
- 45.dir
- A parameter, the parameters for the file directory, the command is equivalent to the Windows console dir command function
- 46.regkey
- One parameter, the parameter is the registry path, this command enumerates the registry subkey information under the path
- 47.regvalue
- One parameter, the parameter is the registry path, this command enumerates the registry value information under the path
- 48.scsi
- You can use the / all parameter to display all, otherwise only show linked to the function, this command shows scsi on the hook
- 49.mouse
- You can use the / all parameter to display all, otherwise only show linked to the function, this command shows the hook on the mouse
- 50.hdt
- No parameters, this command displays HalDispatchTable callback information
- 51.hpdt
- Without parameters, this command displays HalPrivateDispatchTable callback information
- 52.hadt
- No parameters, this command displays HalAcpiDispatchTable callback information
- 53.wdf01000
- You can use the / all parameter to display all, otherwise only show linked to the function, this command shows wdf01000 distribution function on the hook
- 54.wdff
- You can use the / all parameter to display all, otherwise only show linked to the function, this command shows WdfFunction hook
- / RTI & gt;
- No argument, this command displays the filter information
- 56.fs
- No argument, this command displays the file system information
- 57.fst
- No argument, this command displays the Sfilter callback information
- 58.cid
- No arguments, this command displays ClassInitData callback information
- 59.ckdr
- If no parameter is specified, this command displays the system debugging information
- 60.cdrx
- No parameters, this command displays the system register information
- 61.ccdrx
- A parameter, the parameter name for the register, the command to clear the register information
- 62.objhij
- No argument, this command displays object hijack information
- 63.nsiproxy
- You can use the / all parameter to display all, otherwise only show linked to the function, this command shows Nsiproxy on the hook
- 64.tdx
- You can use the / all parameter to display all, otherwise only show linked to the function, this command shows the hook on the Tdx
- 65.npfs
- You can use the / all parameter to display all, otherwise only show the hook function, this command displays the hook on Npfs
- 66.msfs
- You can use the / all parameter to display all, otherwise only show linked to the function, this command shows Msfs hook
- 67.usbport
- You can use the / all parameter to display all, otherwise only show hook function, this command shows Usbport on the hook
- 68.i8042prt
- You can use the / all parameter to display all, otherwise only show linked to the function, this command shows I8042prt on the hook
- 69.ndis
- No argument, this command displays the Ndis processing function information
- 70.exit
- No parameters, this command is used to exit the PCHunter_Cmd program
- 71.quit
- And exit equivalent
- Professional Edition command specific instructions (Professional Edition supports the standard version of the command):
- 1.fmdf
- You can use the / all parameter to display all, otherwise only show linked to the function, this command shows the distribution function FltMgr hook
- 2.fsfcb
- No argument, this command displays the FltMgr file system filter callback information
- 3.fmc
- No argument, this command displays FltMgrCalls information
- 4.wdfli
- You can use the / all parameter to display all, otherwise display only hooks, this command displays the hook on WdfLibraryInfo
- 5.wdfc
- No argument, this command displays Wdf Client information
- 6.ntcb
- Without parameters, this command displays the NdisTdiCallback information
- 7.tpc
- No argument, this command displays the TdiPnpClient information
- 8.ipfltdrv
- No parameter, this command displays Ipfltdrv distribution function information
- 9.ntoh
- Without parameters, this command displays the NdisTcpOffloadHandlers information
- 10.not
- No parameters, this command displays NdisOidTable information
- 11.ftdt
- No argument, this command displays FwpsTcpipDispatchTable information
- 12.wnidt
- No argument, this command displays WfpNblInfoDispTable information
- 13.wss
- No argument, this command displays WfpStreamShim information
- 14.wms
- No argument, this command displays WfpMacShim information
- 15.nlh
- No parameters, this command displays NsiLegacyHandler information
- 16.nlcb
- No parameters, this command displays NetioLayerCallback information
- 17.wdobj
- No argument, this command displays WfpDeviceObject information
- 18.wcout
- No argument, this command displays WfpCallout information
- 19.ncp
- No argument, this command displays NmrProvider (Client) information
- 20.ncn
- No argument, this command displays NsiChangeNotification information
- 21. ncnmc
- No parameters, this command displays NsiChangeNotification_Monitor information
- 22.nii
- No parameters, this command displays the Ndis adapter / interface information
- 23.ipsec
- You can use the / all parameter to display all, otherwise only show linked to the function, this command shows IpsecDispatchFun on the hook
- 24.afd
- You can use the / all parameter to display all, otherwise only show hook function, this command displays the hook on Afd
- 25.ipfw
- No argument, this command displays IpFirewallHook information
- 26.ipft
- No argument, this command displays IpFilterHook information
- 27.regmonitor
- One parameter, the parameter is the registry path, this command enumerates the registry under the path of the application layer registry monitoring information
- / ------------------------------------------------- -------------------------------------------------- ------- /
- Standard Edition is not yet open to specific instructions (because of these features on the system clean-up, modify the function, so temporarily open, so as not to cause damage to the system):
- 1.fpm
- Three parameters, the first is the decimal process id, the second is the hexadecimal process object address, the third is the hexadecimal module base address, the command to uninstall the process module
- 2.kt
- Two parameters, the first is the decimal thread id, the second is the hexadecimal thread object address, the command to kill the thread
- 3.fkt
- Two parameters, the first is the decimal thread id, the second is the hexadecimal thread object address, the command to kill the thread
- 4.kp
- Two parameters, the first is the decimal process id, the second is the hexadecimal process object address, the order to kill the process
- 5.fkp
- Two parameters, the first is the decimal process id, the second is the hexadecimal process object address, this command to kill the process of killing
- 6.cph
- Four parameters, the first is the decimal process id, the second is the hexadecimal process object address, the third is the hexadecimal process handle, the fourth is the hexadecimal process handle object Address, this command closes the process handle
- 7.fcph
- Four parameters, the first is the decimal process id, the second is the hexadecimal process object address, the third is the hexadecimal process handle, the fourth is the hexadecimal process handle object Address, this command forces the process handle to close
- 8.fpmemory
- Four parameters, the first is the decimal process id, the second is the hexadecimal process object address, the third is the hexadecimal process memory address, the fourth is the hexadecimal memory size , The process of the release of memory
- 9.cptimer
- A parameter, which is the hexadecimal timer object address
- 10.cphk
- A parameter with the hexadecimal hotkey object address
- 11.fkm
- Two parameters, the first is the hexadecimal drive object address, the second is the drive service name, two parameters can be a valid, if the two valid priority to use the drive object address, the command to uninstall the driver
- 12. rssdt
- A parameter, the parameters for the decimal SSDT function index, the command to restore SSDT on the Hook
- 13.rshadowssdt
- A parameter, the parameter is a decimal Shadow SSDT function index, this command restores Shadow SSDT on the Hook
- 14. rfsd
- A parameter, which is a decimal FSD function index, restores the Hook on the FSD
- 15.rtcpip
- A parameter, the parameter for the decimal TCPIP function index, this command restores TCPIP Hook
- 16.rkbd
- An argument, which is a decimal Keybaord function index, restores the Hook on the Keyboard
- 17.robjecttype
- Two parameters, the first is the hex ObjectType object type, the second is the function name, the command to restore ObjectType on the Hook
- 18.robjecttype_callback
- Two parameters, the first is the hexadecimal object address, the second is the hexadecimal function address, this command to restore ObjectType Callback on the hook
- 19.rhhive
- Two parameters, the first is the hex HHIVE address, the second is the hexadecimal original function address, this command restores HHIVE hook
- 20.rcallback
- Two parameters, the first is the ObjectType address hexadecimal, the second is the hexadecimal SubObject address, this command to restore the \ Callback directory tree hook on the object
- 21.rnr
- Two parameters, the first is the hexadecimal Notify Routine entry function address, the second is the name of the Notify Routine type, this command to delete the Notify Routine
- 22.rclasspnp
- A parameter, the parameter CLASSPNP function decimal index, the command to restore CLASSPNP on the Hook
- 23.racpi
- A parameter, which is a decimal ACPI function index, resumes the Hook on ACPI
- 24.rdpctimer
- A parameter, the parameters for the hexadecimal DPC timer object address, the command to cancel a timer
- 25.rfilter
- Two parameters, the first is the hexadecimal DeviceObject address, the second is the Filter type name, the command to remove the Filter filter driver
- 26. rprocessapfn
- Three parameters, the first is the decimal process id, the second is the hexadecimal process object address, the third is the decimal process Apfn function index, the command recovery process Apfn Hook
- 27.del
- A mandatory parameter, the parameter file path, the command to delete a file, if you need to force the deletion of the file, you can add the file path before the / f switch
- 28.rename
- Two parameters, the first is the existence of the document path, the second is the new document path, the order to rename the document
- 29.delvalue
- Two parameters, the first is the registry path, the second is the registry value, the command to delete a value in the registry entries
- 30. rscsi
- You can use the / all parameter to display all, otherwise only show hanging enough function, the order shows scsi on the hook
- 31.rmouse
- You can use the / all parameter to display all, otherwise only show linked to the function, this command shows the hook on the mouse
- 32.rhadt
- A parameter, the function name for the function, this command to restore HalAcpiDispatchTable Hook
- 33.rwdf01000
- A parameter, the parameter is a decimal function index, this command restores df01000 on the distribution function of the Hook
- 34.rcid
- Two parameters, the first is a decimal function index, the second is the type name, this command to restore ClassInitData callback on the Hook
- 35.rwdff
- A parameter, the parameter is a decimal function index, this command restores the Hook on the WdfFunction
- 36.ratapi
- A parameter, the parameter is the decimal ATAPI function index, this command restores the ATAPI Hook
- 37.rnpfs
- A parameter, the parameter for the decimal Npfs function index, the command to restore Npfs Hook
- 38. rmsfs
- A parameter, the parameter is the decimal Msfs function index, this command restores the Hook on Msfs
- 39.rusbport
- A parameter, the parameter is a decimal Usbport function index, this command to restore Usbport on the Hook
- 40.ri8042prt
- A parameter, the parameters for the decimal I8042prt function index, the command to restore I8042prt the Hook
- Professional Edition is not yet open command Specific instructions:
- 1.rwdfli
- A parameter, the parameter is hexadecimal original function address, this command restores WdfLibraryInfo Hook
- 2.rfmdf
- A parameter, the parameter is a decimal function index, this command restores the FltMgr dispatch function on the Hook
- 3.rfsfcb
- A parameter, the parameter is a decimal function index, the command to restore FltMgr file system callback on the Hook
- 4.rfmc
- A parameter, the parameter is hexadecimal current function address, this command restores Hook on FltMgrCalls
- 5.rckdr
- No argument, this command restores all Hooks on system debugging
- 6.rnsiproxy
- A parameter, the parameter is a decimal function index, this command restores the Hook on Nsiproxy
- 7.rtdx
- A parameter, the parameter is a decimal function index, this command restores the Hook on Tdx
- 8.rntcb
- No argument, this command restores all Hooks on NdisTdiCallback
- 9.ripfltdrv
- A parameter, the parameter is a decimal function index or with [FastIo], this command restores the Hook on the pfltdrv dispatch function
- 10.rntoh
- A parameter, the parameters for the function name, the order to restore NdisTcpOffloadHandlers Hook
- 11.rnot
- A parameter, the name of the function, this command restores the Hook on NdisOidTable
- 12.rwdobj
- No argument, this command restores all Hooks on WfpDeviceObject
- 13.ripsec
- A parameter, the parameter is a decimal function index, this command restores the Hook on ipsecDispatchFun
- 14.rafd
- A parameter, the parameter is a decimal function index, the command to restore Afd on the distribution function Hook
- 15.cipfw
- A parameter, the parameter is a hexadecimal function address, this command clears IpFirewallHook Hook
- 16.cipft
- No argument, this command clears all Hooks on IpFilterHook
Advertisement
Add Comment
Please, Sign In to add comment