![]() |
|
#9
|
||||
|
||||
|
if you used the "tc eip<900000", you have to dump after this command (you should be at a jump-command, wich jumps into some code which executes a kernel32.GetModuleHandleA)
then edit the EP with LordPE or any other tool to real OEP but do not dump later or dump will crash (it does for me)Regards, MaRKuS TH-DJM |
|
|