Joined: 09 May 2003 Posts: 25833 Location: The netherlands
Posted: Sun Oct 07, 2012 12:23 pm Post subject:
Run in 64-bit windows...
Anyhow, there is no real difference between ring0 and ring3. It's usually just a jump. Note though, that one function might be hooked that calls another hooked function. (e.g KeStackAttachProcess calls KiSwapProcess which isn't exported and was also hooked by some anti cheats like gg)
One of the methods to bypass that is to call an unmodified copy of the whole kernel. (since relative jumps will point to the unhooked copies)
Just make sure the copy is made before the hooks are done.
And another method besides bypassing ring0 hooks is just change hardware registers like CR3. _________________
Do not ask me about online cheats. I don't know any and wont help finding them.
Like my help? Join me on Patreon so i can keep helping
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum