Hacker News new | ask | show | jobs
by vertex-four 4511 days ago
VAC streams the DLLs from their server at runtime, so they never actually sit on the disk. There's also a number of DLLs which are loaded and unloaded as necessary, to make it harder for attackers to dump the whole thing. I suspect that there are blackhat forums where people have discussed how to dump parts of VAC.
1 comments

Generally any VAC update is met with a full dump fairly quickly on most sites.
Cheating seems to involve more effort than just playing, getting better at the game.
Reverse engineering is usually more interesting than the game.