sha8e / malwarecookbook

Automatically exported from code.google.com/p/malwarecookbook
0 stars 0 forks source link

LdrModules highlights all exe's as suspicious because they're not in the init order list #17

Closed GoogleCodeExporter closed 8 years ago

GoogleCodeExporter commented 8 years ago
use tasks.Peb.ImageBase to match the module's base address with

Original issue reported on code.google.com by michael.hale@gmail.com on 4 Apr 2011 at 10:09

GoogleCodeExporter commented 8 years ago
This issue was closed by revision r55.

Original comment by michael.hale@gmail.com on 8 Apr 2011 at 3:05