![]() |
|
#2
|
|||
|
|||
|
Hi Markus
asprotect dosn't need that long tut, eventhough we appreciate the effort now and always that labba is doing, I think long tut tend to be hard to follow at least for me,here is the way that britedream might do it: 1- stack hard breakpoint on the first push, takes you to pushad, do the same for the pushad takes you to the stolen bytes. 2- memory breakpiont on code section, look at the stack for the oep. 3- fix your iat- done. Last edited by britedream; 01-19-2004 at 00:54. |
|
|