Restoring a user-mode hook

10/10/2014 22:42 csirkepap#1
Hi guys. I'm struggling with a problem for days since now.
I have to restore a hooked function, but I don't know what it was before hooking. So I can't just store it and restore later.

Could anyone help me how could I get the original starting bytes of a function from system DLL? Probably I have to struggle with file reading & RVA/VAs, but I don't know where to start.

Thank you!
10/11/2014 12:12 Dr. Coxxy#2
read the dll from disk and get the original bytes from there