aobscanmodule(INJECT,trove.exe,F3 0F 10 48 28 0F C6 C0 00 0F 28 D1 F3 0F 59 15 XX XX XX XX 0F 29 44 24 10) // should be unique
alloc(newmem,$1000)
label(code)
label(return)
newmem:
code:
db F3 0F 10 48
jmp return
INJECT:
db F3 0F 10 40
return:
registersymbol(INJECT)
[DISABLE]
INJECT:
db F3 0F 10 48