Interestingly, debug builds of binaries that link with Detours cause Process Explorer to suspect that the binary is packed ("Image is probably packed"). Release builds are not, however.

I would be interested to know how Process Explorer determines that a binary is probably packed.
No comments:
Post a Comment