Hello,
I've noticed in several AV products really interesting way to hook service table entries. Instead of direct replace of handler with their own, these products allocate in NonPaged pool little callgate which contains jump to real handler.
As for now I know two products - Avira and ESET (however I don't remember exactly version, seems to be in 4.2.64.12 there is no such behavior). Please add more if you know.
I've noticed in several AV products really interesting way to hook service table entries. Instead of direct replace of handler with their own, these products allocate in NonPaged pool little callgate which contains jump to real handler.
As for now I know two products - Avira and ESET (however I don't remember exactly version, seems to be in 4.2.64.12 there is no such behavior). Please add more if you know.
Ring0 - the source of inspiration