View Single Post
  #4  
Old 06-19-2004, 06:56
Jiro-san
 
Posts: n/a
jump to OEP is made by push "OEP", followed by ret. So just search for 68h 00 00 00 00 in after few carefull F7 and F8. Usually they are at the and of section, near a string Kernel32. Put a breakpoint at next instruction - 0C3h and you will see your OEP to emerge on the upper instruction
Reply With Quote