Skip to content

Drop redundant g_last_seen_* WMI query gating from PR #161 - #194

Merged
kevoreilly merged 1 commit into
kevoreilly:capemonfrom
KillerInstinct:fix-wmi-spoof-regression
Sep 2, 2026
Merged

Drop redundant g_last_seen_* WMI query gating from PR #161#194
kevoreilly merged 1 commit into
kevoreilly:capemonfrom
KillerInstinct:fix-wmi-spoof-regression

Conversation

@KillerInstinct

Copy link
Copy Markdown
Contributor

PR #161 re-applied the old PR #97 patch over the class-aware logic that was introduced with #116. Remove the now redundant g_last_seen_* vars (which also skipped spoofing for CreateInstanceEnum/GetObject/async) and reverting the AdapterRAM overflow handling. Keep the new MaxRefreshRate spoof.

PR kevoreilly#116 made SpoofWmiData resolve the object's WMI __CLASS directly, so
the g_last_seen_disk_query / g_last_seen_physicalmemory flags PR kevoreilly#161
brought back from the old kevoreilly#97 patch are redundant. Worse, gating the
LogicalDisk Size and PhysicalMemory Capacity spoofs on those flags skips
spoofing whenever the class isn't reached via a SELECT on the same thread:
CreateInstanceEnum (Get-CimInstance / Get-WmiObject -Class), GetObject on
an instance, and async results delivered on the WMI sink thread.

Remove the flags and restore both ExecQuery hooks to log-before-call.
The AdapterRAM (realistic 4GB overflow value) and MaxRefreshRate spoofs
from kevoreilly#161 are correct and kept.
@kevoreilly
kevoreilly merged commit 4d913b0 into kevoreilly:capemon Sep 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants