Hello, I've made a previous thread for help on a bypass I'm currently working on, but I'd like to know how it is that one would go about reading a dumped EHSVC module. I've opened the client in olly and debugged it, from there attached CE and I can view all of the modules calls by doing so. I've also dumped EHSVC itself so I can stream though it's memory in IDA. What I'm trying to figure out though is what functions call to what. I've been on this for the passed two days and it's mind blowing. If anyone could help me I'd be very grateful. The dumped EHSVC module can be downloaded here : EHSvc - Minus.