|
OEP is: 407DB4
Stolen bytes:
00407DB4 > $ 53 PUSH EBX
00407DB5 . 56 PUSH ESI
00407DB6 . 57 PUSH EDI
00407DB7 . 83EC 20 SUB ESP,20
00407DBA . 8D5C24 1C LEA EBX,DWORD PTR SS:[ESP+1C]
00407DBE . BA 904C4100 MOV EDX,dvd2one1.00414C90 ; ASCII "FontSize"
00407DC3 . 33C0 XOR EAX,EAX
00407DC5 . E8 F2580000 CALL dvd2one1.0040D6BC <<< this is the call which is executed before going to Temp-OEP!!!
the place where you are is near to OEP, just trace a little bit and you are there!
IAT:
|