![]() |
|
#12
|
||||
|
||||
|
kernel32!CloseHandle
My friend and about kernel32!CloseHandle it is the same for CheckProcessDebugFlags by Keeping it in User Mode insted of Kernel mode
because some times we need to check this API for other prog so it is not good to make it in Kernel mode ( I think ) Quote:
Quote:
__________________
Ur Best Friend Ahmadmansoor Always My Best Friend: Aaron & JMI & ZeNiX |
| The Following User Gave Reputation+1 to ahmadmansoor For This Useful Post: | ||
mr.exodia (02-05-2014) | ||
| Tags |
| driver, hiding, ssdt, titanhide, x64 |
|
|