EquiFox / KsDumper

Dumping processes using the power of kernel space !
MIT License
969 stars 215 forks source link

how to dump EAC games #3

Closed FocuzJS closed 5 years ago

FocuzJS commented 5 years ago

You could just rename r5apex to eaclauncher and then it would've let you dump with Scylla. Sick job tho with all the work you put into this, im sure you'll improve much with your drivers as you rethink what's possible from kernel ;)

EquiFox commented 5 years ago

Yeah, I literally understood that trick 5 mins after pushing this to Github haha. Anyway, it might help someone learn :)

FocuzJS commented 5 years ago

I sure hope it does, I too recently was a victim of the KMDF learning curve as well ;)

FocuzJS commented 5 years ago

also do note you should look into clearing capcom traces when working with anti-cheats like EAC, just a suggestion since people here are having issues where capcom is the reason people using PI are getting banned. Specifically MmUnloadedDrivers in the case of EAC. The registries are less of a concern. :)

eXCoreX commented 5 years ago

I think this is more of a private stuff, what's the point of giving away a finished product in this case?

FocuzJS commented 5 years ago

the code is already pasted everywhere. sharing knowledge like this is power for anyone reading this that's interested, that's the correct way of doing so if you're not using a bug like empty driver name ;)

ghost commented 4 years ago

код уже наклеен везде. делиться такими знаниями-это власть для тех, кто читает это, что интересно , это правильный способ сделать это, если вы не используете ошибку, такую как пустое имя драйвера ;)

You can try league dumper, with UAC disabled, or at the boot input .