4 ms·
Yea, certain routines in windows actually check if the OS is hooked. The PE loader implemented in ntdll verifies that NtOpenSection() (or NtOpenFile, not sure r
by SCHiM 5y ago
Yea, certain routines in windows actually check if the OS is hooked. The PE loader implemented in ntdll verifies that NtOpenSection() (or NtOpenFile, not sure right now) has not been hooked. When I was looking into that it looked like it disabled concurrent module loading if detected a hook(so it became slower), probably as a bug fix for whatever software inserts itself in that place (Stuxnet did too!).