View Single Post
  #5  
Old 02-19-2005, 22:47
niom niom is offline
Friend
 
Join Date: Jul 2004
Posts: 21
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
niom Reputation: 0
you should use windbg instead of softice, because its not that 'intrusive' as softice and you'll need only one simple trick to prevent detection

once you can use a debugger to view interesting parts (like the prodrv06) you'll see a very simple code-decryption, api loading at runtime and a little vm
Reply With Quote