![]() |
|
#26
|
|||
|
|||
|
I changed "push 100" to "push 0", put a breakpoint on the first occurrence of EB03, run, revert the patch to not trigger crc checks and you get a 'clean' IAT. You still have to move the IAT with a tool like UIF though...
The push 100 is a call that decrypts a buffer I believe, but I didn't look at it for a long time. |
| The Following User Says Thank You to mr.exodia For This Useful Post: | ||
Benten (11-04-2017) | ||
| Tags |
| armadillo, armadillo unpacking, import elimination, tutorial request |
|
|