Code:
[ENABLE] alloc(DetectGM,25) label(ReturnName) 005535E3: //C7 46 0C 00 00 00 00 89 47 04 jmp DetectGM nop nop ReturnName: DetectGM: cmp [eax+70],5D4D475B //[GM] je 00000000 mov [esi+0c],00000000 jmp ReturnName [DISABLE] dealloc(DetectGM) 005535E3: mov [esi+0c],00000000






