-
Notifications
You must be signed in to change notification settings - Fork 35
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Does win7 not support it? #1
Comments
Hello @win-wava , thanks for letting me know. Is the win7 OS 32bit or 64bit? Could you provide the output of the program? |
Before updating: RAX = 0x16 After updating: RAX = 0x16 Before updating: RAX = 0x16 After updating: RAX = 0x16 Before updating: RAX = 0x16 After updating: RAX = 0x16 ...... Keep looping this |
win7 64-bit |
0x16 is NtQueryInformationProcess' SSN, it means the RAX was already replaced, but the hbp is not removed. Interesting, I will look into this. |
OK. Thanks for your hard work |
win10 runs normally
Win7 card loops
The text was updated successfully, but these errors were encountered: