Está ai pessoal agora é com vocês! /baba
Créditos:Code:#define DisableValidation 0X77BC01C5
#define DisableLookaside 0X77BC0251
#define ShutdownFlags 0X77BC0266
#define DisableEscalation 0X77BC2B32
VOID EhSvcBypass(VOID)
{
DWORD dwEhSvc;
do {
dwEhSvc = FindDll("EhSvc.dll");
Sleep(30);
} while(!dwEhSvc);
WriteOpCode((PVOID)(dwEhSvc + DisableValidation),"\x68\x02\x89\xB8\x77", 5);
WriteOpCode((PVOID)(dwEhSvc + DisableLookaside), "\x68\xD8\x88\xB8\x77", 5);
WriteOpCode((PVOID)(dwEhSvc + ShutdownFlags), "\x68\xBC\x88\xB8\x77", 5);
WriteOpCode((PVOID)(dwEhSvc + DisableEscalation), "\x68\x08\xAB\xB8\x77", 5);
}
debug -> dump da EhSvc.dll
Gellin
kssiobr