![]() |
|
#2
|
|||
|
|||
|
Windows 7 64 does not allow every driver to get into kernel memory region due to a very strict digital signature check. If the driver has not been digitally signed, Windows won't allow it to be loaded.
So I guess you are rather asking about new modern way - a bootkit? ![]() Probably #1 is TDL3 |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Process hiding with SSDT modification in x64 Win7 | 31337guru | x64 OS | 3 | 05-03-2012 18:16 |