@gsuberland idk, I've been trying to figure it out for a while. My assumption (due to lack of HW breakpoint triggers) is the driver is manually mapping the DLL. I've tried to attach a kernel debugger and figure who's writing the memory / hooks, but as it turns out I'm really bad at working with the page table and debugging from KM in general.