View Single Post
  #1  
Old 01-04-2004, 03:40
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
yes, that's right!!! i think it's that code:

00406D1C 50 PUSH EAX
00406D1D 6A 00 PUSH 0
00406D1F E8 F8FEFFFF CALL IconCatc.00406C1C
00406D24 BA 00F14B00 MOV EDX,IconCatc.004BF100
00406D29 52 PUSH EDX
00406D2A 8905 D8344C00 MOV DWORD PTR DS:[4C34D8],EAX
00406D30 8942 04 MOV DWORD PTR DS:[EDX+4],EAX
00406D33 C742 08 00000000 MOV DWORD PTR DS:[EDX+8],0
00406D3A C742 0C 00000000 MOV DWORD PTR DS:[EDX+C],0
00406D41 E8 8AFFFFFF CALL IconCatc.00406CD0
00406D46 5A POP EDX
00406D47 58 POP EAX
00406D48 E8 A7CCFFFF CALL IconCatc.004039F4
00406D4D C3 RETN

after the ret, you are @temp-OEP!
OEP = temp-OEP - stolen bytes
Reply With Quote