Quote:
Originally Posted by Byte.
Do you even know about what you are talking?
|
The process already has a new signature every 5 minutes, if VS can do the same for drivers then that would hide it as well.
Check it for yourself.
Quote:
Originally Posted by knuckhead
read the comments there :P
and if you do that BE will probably block it.
|
BE blocks Test Mode, not loading unsigned drivers.
If all else fails I'll look into CE's source code to see how its viewing code from kernel.
Any idea if ntdll can be hooked for ZwReadProcessMemory?