Quote:
|
Originally Posted by Archer
I'm almost sure that OEP can't be 1 byte away from EP of the protected DLL (if it is so, something is wrong, maybe script or you misunderstand something).
|
You are right, and at this point I don't have enough experience to know what is wrong - perhaps both!
Quote:
|
Originally Posted by Archer
And how can PE Explorer show OEP of the protected DLL? AFAIK it can show EP, but not OEP.
|
Yest it's shows the EP only, I was just using this to illustrate that EP and OEP differ by one byte.
Quote:
|
Originally Posted by Archer
And if you enter EP in ImpRec maybe it's trying to restore Arma's import table, but you need real dll's table. Try to look for it with hands and manually enter table's address (do it on OEP).
|
I'll see if I can find the start and size of the table manually, I still need to confirm I've got the right OEP address first.
5aLIVE.