HELLO GUYS...

I HAD USE A SOFTWARE TO FIND THREAD IN MAT CIB...

THE GOOD THING IS IT GIVE ME NAME OF KERNEL...

THERE ARE MANY THREAD IN MAT INCLUDE KERNEL...

BUT I HAD SEEN NOT ALL KERNEL ARE SAME...

ETC=KERNEL32 FUNCTION OF SAPI
=KERNEL32 FUNCTION OF ICECLLIENTTB
=KERNEL32 FUNCTION OF TRLDLOG
=KERNERL32 FUNCTION OF TIME TO ICE PROGRAMME(I HAD DELETE IT BUT ONLY CAN 15 MINUTES)


THAT ALL OF KERNEL32...


THERE IS MORE///


TIMEICECLIENT.DLL
SAPI.DLL(USUALLY IN XUETR 2 ONLY BUT IN MY SOFTWARE IT IS 4 SAPI.DLL)
ADVAPI STILL SAME ONLY 2...



THE WAYS I BYPASS...


I KILL SAPI.DLL
I KILL TIMEICECLIENT.DLL(THIS NOT ICECLIENT.DLL)
I KILL ADVAPI.DLL
AND LAST I KILL KERNEL32>=KERNEL32 FUNCTION OF SAPI
=KERNEL32 FUNCTION OF ICECLLIENTTB
=KERNEL32 FUNCTION OF TRLDLOG
=KERNERL32 FUNCTION OF TIME TO ICE PROGRAMME

THERE WILL BE ONLY 3 KERNEL WILL NOT KILL(CAUSE IF I KILL IT WILL DC THAT TIME )


GIVE YOUR IDEA TO DISSCUS THIS BYPASS

I PROMISE I WILL RELEASED AS FAST AS POSSIBLE IF BYPASS WORK


REMEMBER ONCE AGAIN MY SOFTWARE IS NOT LIKE XUETR AND PROCESS HACKER(CANNOT DETECT KERNEL32>NO NAME AT KERNEL32) BUT MY SOFTWARE IT WILL SHOW NAME OF ALL THREAD IN MAT INCLUDED KERNEL32




FROM ME @Mr DHack