![]() |
|
#3
|
|||
|
|||
|
@hajir:
I think "Kerlingen" knows about what you write since he says that he has patched the imports to point directly to the API. As far as I understand him, he has this kind of code: Code:
(...) call some_label ; E8 call, not FF15 call (...) some_label: jmp dllname!exportname ; "E9" relative jump @kerlingen: Have you tried to find code like this Code:
mov esi, [offset iat+somevalue] call esi ;or jmp dword ptr [xxxxxxxx] ; FF25 jump |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Add imports to DLL import table | jonwil | General Discussion | 5 | 09-07-2020 16:47 |
| How to shuffle names in the PE import table? | Newbie_Cracker | General Discussion | 5 | 08-25-2019 03:59 |
| Reliable PE Library or DLL for Adding Functions to Import Table | omidgl | General Discussion | 3 | 06-28-2008 09:53 |
| Can`t restore import table | thechatter | General Discussion | 9 | 11-14-2003 21:01 |
| Changing Import Table?? | magic | General Discussion | 3 | 09-14-2003 01:59 |