-
Copy Function via using assembly
-
Just directly syscalling ZwProtectVirtualMemory instead of calling the export to syscall in ntdll.dll.
-
it can't not be hooked by anything except the Hooking man in kernelland
-
This example is for x86.
- Check masm Compile option.
- make a .asm file on project
- code on .asm file
- Profit
me (Ekdms95) and I will give some credit for sexyyume