Heh, you're right. Or, you should be. However, I changed an AVP dll file (inserted an int 3), but it didn't seem to care at all about that (patched it back in mem, when it triggered, but there should have been something before that). Ofcourse there could have been silent alarms, but since the app went on about its business as if nothing happened whatsoever, it is a bit amusing/worrying
Heh, and speaking of antivirus that should do selfchecks: I remember toying with mcafee once. Found a good spot for patching and went about my business, but mcafee ofcourse complained. Then I tried patching another place in the same file, and everything went smooth. Far as I could tell, their crc-routine only cared about every other byte, making a onebyte patch in the right place work fine. Talk about security (but then again, what should one expect from a company that doesn't have decent security on it's ftp).
Fake