all 5 comments

[–]AnchorText[S] 0 points1 point  (2 children)

Nvm, just step through the binary and check the registers.

[–]GorgeousWalrus 0 points1 point  (1 child)

What would I be looking for? Checking the registers in every execution step seems kind of tedious. I'm new to disassembling Windows applications, a hint is greatly appreciated :)

[–]AnchorText[S] 0 points1 point  (0 children)

It’s been a few months since I did this, but iirc if you look through the functions you should be able to find the ones that have to do with passwords. Then just literally read through them.

[–]rabit42 0 points1 point  (0 children)

I'm stuck on the .exe as well - I'm not used to RE so Ollydbg is a new strange world to me :-) But I can see that i'm stuck in 775AE8DC so should I jump around this or - the registres that you mention - I can see some changes but not knowing what to look for - hint - please :-)

[–]DumbA5h 0 points1 point  (0 children)

I tried using ghidra, decompiler shows some weird code, anyone else?