|
Tools:
- Modified Olly (names, classes,exports,....)
- HideOD: all options checked and ZwQueryInformationProcess (method 2)
after bypassing <CreateProcessA> Fill with NOP <ResumeThread> API (very important) then continue unpacking....
Last edited by Magic_h2001; 01-09-2008 at 16:10.
|