Hello, for the ones who know about it... Is there another way I could get the current EIP (instruction pointer) on a running process (attached, for example, with MHS and without any live debugger), so I could pause the execution of that given process, get the EIP, and then trace back (manually) execution up to an instruction I wanted to change its behavior?
Well, probably while tracing back the execution I could get caught by instruction jumps (given an address, many many jumps could have thrown the EIP there, what could make life harder w/out a debugger). But it is a last resort method and maybe I can round down alternatives by triying and trying... who meant it to be easy anyway... heh