
Originally Posted by
Sblade
Ring 3 detection routines still have to go into Ring 0 if the program is in stealth mode. It already hides itself in the registry in that mode otherwise it would have been easy for DRM's to circumvent the circumvention.
Securom starts in RING3 and monitors the RING0... otherwise nothing will prevent DT stealth to false registry data and fool Securom.... when I say registry data.... what data CANґT be falsified from RING0 to the naive RING3?
Ring0 overrule Ring3, thatґs a simple fact no one can deny...
Bookmarks