Get the Whitepaper called Windows 7 x86’s !nt scandown method on ring 0 (kernel ASLR bypass).
You can download it from the following link: https://packetstormsecurity.com/files/download/90546/scandown-method.txt
Source: https://packetstormsecurity.com/files/90546/Windows-7-x86-Scandown-Method.html