hydy100 / R3nzSkin

Skin changer for League of Legends (LOL).Everyone is welcome to help improve it.
https://hydy100.top
MIT License
158 stars 4 forks source link

How does it work. is it detectable? #4

Closed ConeDjordjic closed 3 weeks ago

ConeDjordjic commented 3 weeks ago

The vietnamese guy made one that loads it through a driver which is bound to be detected at some point. I was wondering if your approach is bannable. Idc about accounts i was just wondering

hydy100 commented 3 weeks ago

According to my analysis, Riot Vanguard's driver monitors almost all sensitive operation callbacks (processes, threads, objects, image loads, registry, etc.). I can only say that certain functions can be executed successfully if allowed, so theoretically, it knows what you are doing. If you haven't modified any sensitive data, I don't think it will issue a ban.

illitiratehobo commented 3 weeks ago

According to my analysis, Riot Vanguard's driver monitors almost all sensitive operation callbacks (processes, threads, objects, image loads, registry, etc.). I can only say that certain functions can be executed successfully if allowed, so theoretically, it knows what you are doing. If you haven't modified any sensitive data, I don't think it will issue a ban.

W

hydy100 commented 3 weeks ago

The vietnamese guy made one that loads it through a driver which is bound to be detected at some point. I was wondering if your approach is bannable. Idc about accounts i was just wondering

Please don't harbor too much malice. I took a quick look at its program, and actually doesn't use a driver. It's actually a disguise. Haha :)

ConeDjordjic commented 3 weeks ago

The vietnamese guy made one that loads it through a driver which is bound to be detected at some point. I was wondering if your approach is bannable. Idc about accounts i was just wondering

Please don't harbor too much malice. I took a quick look at its program, and actually doesn't use a driver. It's actually a disguise. Haha :)

yeah i figured it was a disguise as well. saw it was calling ornn.sys but not doing anything with it. i thought i didnt look far enough. thank you for doing service to this community.