hi..
in my tutorials.... all you do..
when you reach OEP, search for FF25
follow this in dump, set a BP HW on WRITE DWORD.
restart. you get the nag... get past this..
then you break.. on the HW BP.
scroll up a bit and you see TEST EAX, EAX
then a JE somewhere.
above this is a CALL... enter this call... scroll down till you see a JA above a JMP. the JA is the magic jump.
set a BP HW on EXECUTION...
restart.. when you break on the JA.. make it JMP...
then remove the BP..
get to OEP..
dump, fix anti-dump...
attach IAT...
sometimes a couple are invalid..
the two will be GetProcAddress and GetModuleHandleA
just hexview one of them.. should say it in the disassembly..
thats about it..
if you have trouble with OEP...
execute the PUSHAD
set a BP HW on ACCESS WORD for the first two bytes of ESP...
this will get you there..
after you get past the nag you will break..
or if you really want..
just patch it ..
the nags are easy..
look in my site.. i have a tutorial on inline patching Prot. Plus.
later
H3rCuL3s