Repository navigation
v1.3
Support for Windows 7 and XP has been added.
Garbage code removed.
Bug fixes.
Support for service creation has been added, please use the RootkitDriverService.sys if you wish to use a service, or use the RootkitDriverReflective.sys if you wish to use a reflective mapping method, like KDMapper. (I suggest the first one, way easier and less detectable, also permanent).
Service Creation (Permanent, at system start, not boot):
sc create SERVICENAME type= kernel binPath= "C:\Path\To\RootkitDriverService.sys" start= system
Update - I can't really call this less detectable because the driver is unsigned and you must use testsigning in order to load it in the computer, either that or bring your own vulnerable driver attack, which KDMapper uses (so you'll need the reflective version) (DSE Operates this, you may find solutions to disable DSE, or bypass it entirely, I will not introduce those solutions here.)