View Full Version : Rootkits style bypassing
tsunami_okami
9th January 2007, 08:47
ok maybe this has been done before but has any one used a root kit style gamegaurd bypass to keep it from working right?
Opcode&H90
10th January 2007, 05:17
so called Dual Bypass.
It only hides your process so it cant be detected through string scan. GameGuard did more than that, hooks certain kernel api, renders your app useless.
linden
11th January 2007, 17:45
GameGuard itself is a rootkit. And to counter a rootkit, you also need to use rootkit techs!
It can be done, but you need to do a lot more than just hiding processes though. You can cripple GameGuard by hooking several vital kernel api's it uses, and spoofing things it sees.
frogger
21st January 2007, 16:46
In order to code such a rootkit you really have to know what GG does and how to prevent it. Sounds easier to do than it is. Sure, it might be feasible but most peeps aren't able to do it.
Once I even thought about emulating GG -> replacing the GameGuard.des with an own program. But you need to know how it interacts with trickster.bin so I abandoned that idea because I just don't have enough experience in that field.
vBulletin® v3.7.0, Copyright ©2000-2008, Jelsoft Enterprises Ltd.