elite*gold: 0
Join Date: Mar 2010
Posts: 5
Received Thanks: 1
|
i have a question about to bypass Hs
when i open process hacker and choose properties of florensiaEN.bin i see this list:
2412, 2.359.852.290, 0x0, Normal
1804, 25.098.903, ntdll.dll!Ordinal864+0x40, -3
3704, 23.432.472, ntdll.dll!Ordinal864+0x40, Normal
3096, 13.372.893, ntdll.dll!Ordinal864+0x40, TimeCritical
2632, 7.964.244, ntdll.dll!Ordinal864+0x40, Normal
3768, 7.570.593, ntdll.dll!Ordinal864+0x40, TimeCritical
1996, 1.575.972, ntdll.dll!Ordinal864+0x40, Normal
3676, 752.085, ntdll.dll!Ordinal864+0x40, Normal
3680, 362.592, ntdll.dll!Ordinal864+0x40, Normal
3948, 263.007, ntdll.dll!Ordinal864+0x40, TimeCritical
3060, 41.337, ntdll.dll!Ordinal864+0x40, Normal
3840, 28.962, ntdll.dll!Ordinal864+0x40, Normal
3064, 18.855, ntdll.dll!Ordinal864+0x40, Normal
3760, 14.355, ntdll.dll!Ordinal864+0x40, Normal
2228, 13.635, ntdll.dll!Ordinal864+0x40, Normal
2976, 13.257, ntdll.dll!Ordinal864+0x40, Normal
3336, 13.095, ntdll.dll!Ordinal864+0x40, Normal
4000, , ntdll.dll!Ordinal864+0x40, Highest
3896, , ntdll.dll!Ordinal864+0x40, Highest
3892, , ntdll.dll!Ordinal864+0x40, Highest
3792, , ntdll.dll+0x65e58, Highest
3772, , ntdll.dll+0x65e58, Normal
3716, , ntdll.dll!Ordinal864+0x40, Normal
3248, , ntdll.dll+0x65e58, Normal
3224, , ntdll.dll!Ordinal864+0x40, Highest
3116, , ntdll.dll!Ordinal864+0x40, Normal
3092, , ntdll.dll+0x65e58, Highest
2984, , ntdll.dll!Ordinal864+0x40, Highest
2924, , ntdll.dll!Ordinal864+0x40, Normal
2912, , ntdll.dll!Ordinal864+0x40, Highest
2908, , ntdll.dll!Ordinal864+0x40, Highest
2864, , ntdll.dll!Ordinal864+0x40, Highest
2736, , ntdll.dll+0x65e58, Normal
2644, , ntdll.dll!Ordinal864+0x40, Normal
2432, , ntdll.dll!Ordinal864+0x40, TimeCritical
2348, , ntdll.dll+0x65e58, Normal
2308, , ntdll.dll+0x65e58, Normal
2292, , ntdll.dll+0x65e58, Normal
2288, , ntdll.dll!Ordinal864+0x40, Highest
2124, , ntdll.dll!Ordinal864+0x40, Highest
2052, , ntdll.dll!Ordinal864+0x40, Highest
1956, , ntdll.dll+0x65e58, Normal
1788, , ntdll.dll!Ordinal864+0x40, Normal
1560, , ntdll.dll!Ordinal864+0x40, Normal
1428, , ntdll.dll!Ordinal864+0x40, Highest
1376, , ntdll.dll!Ordinal864+0x40, Normal
1300, , ntdll.dll+0x65e58, Normal
988, , ntdll.dll!Ordinal864+0x40, Highest
812, , ntdll.dll!Ordinal864+0x40, Normal
744, , ntdll.dll!Ordinal864+0x40, Highest
my problem is that in the readme it says i have to terminate
5. Select ALL threads from EHSvc.dll right click them and choose "Terminate Thread". and i dont know which of them the rights are
|