no, actually from export table of the given module.OK
This code full of perversions and this is the way how they get address of service descriptor table by doing memory scan and then work with a shadow table through acquired pointer.Do you know a better way to do so? :geek:
I suggest carefully review anything from this bsod-generator source code.
EDIT: Missing a word...
Last edited by Tigzy on Thu Aug 18, 2011 1:03 pm, edited 1 time in total.