Air14 / HyperHide

Hypervisor based anti anti debug plugin for x64dbg
MIT License
1.23k stars 279 forks source link

HookedNtYieldExecution return value error #19

Closed taodaqiao closed 2 years ago

taodaqiao commented 2 years ago

if(Hider::IsHidden(IoGetCurrentProcess(), HIDE_NT_YIELD_EXECUTION) == TRUE) { OriginalNtYieldExecution(); return STATUS_SUCCESS; //return here STATUS_NO_YIELD_PERFORMED }

Air14 commented 2 years ago

To be honest, this is irrelevant, because in a non-debugged application NtYieldExecution returns STATUS_SUCCESS as often as STATUS_NO_YIELD_PERFORMED