Closed 0ca closed 8 years ago
@0ca What exactly happens? Does it crash?
It doesn't crash. I need to take a deeper look.
There was a problem switching from 32 bits to 64 bits in the dll syswow64.dll. It is a tricky things, so I identify the magic insturction is doing the switch and I am doing step over that call to skip the switching:
if (last_triton_instruction->getDisassembly().find("call dword ptr fs:[0xc0]") != -1)
{
msg("wow64 switching! request_step_over();\n");
request_step_over();
}
If I got a best solution from the IDA forum I will use it: https://forum.hex-rays.com/viewtopic.php?f=8&t=4070
Probably is related with a incorrectly disassembled instruction.