|
I've quite understood the EDX = 00414C90, but I've not understood how you catch how you find the other stolen bytes, from where?
you say...
>here are some push:
>solves this bytes:
>00407DB4 > $ 53 PUSH EBX
>00407DB5 . 56 PUSH ESI
>00407DB6 . 57 PUSH EDI
how do you catch them????
maybe I'm too newbie to understand it .......
thanks
|