Ads
; 32bit
sub esp, 0x130
push ebx
push ebp
mov ebp, dword ptr ss:[esp+0x140]
push ebp
call dword ptr ds:[0x40DD2078]
mov ebx, eax
xor edx, edx
add esp, 0x4
cmp ebx, edx
call ntdll.ZwOpenProcess
pop ebp
xor eax, eax
pop ebx
add esp, 0x130
retn
mov ecx, ebp
push esi
mov esi, ecx
push edi
cli
mov eax, cr0
add eax, not 10000h
mov cr0, eax
call sysenter
Ads
Ads