![]() |
|
#4
|
|||
|
|||
|
Thanks for both of your comments, the import address table was invalid because the process makes certain API calls only after modifying the kernel with a driver.
Imprec's level 1 trace worked, but it didn't seem like it was executing because "ExitProcess" gets called after it checks for a device/driver it unpacks and loads into the kernel on runtime. It is an evil, piece of software. |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| 64bit Programming and Assembly Issues | moro3391 | x64 OS | 1 | 01-18-2013 18:35 |
| Anti-Piracy Company Issues $40k Hacker Challenge | elephant | General Discussion | 9 | 02-24-2007 06:33 |
| Syser Debugger 1.1 testing versions issues [ attention ] | rockwu | General Discussion | 4 | 08-23-2005 18:09 |