First you will need to apply protection against checking of debug bits. [see plugin above]
press shift-f9 and ignore any exceptions until you stop on the following:
00330000 C3 ret
wtf? why'd we stop =P ?
just one ret in the memory range!
you'll note at the bottom it says we hit a break-on-access.
Odd, since we never set one.
This is a funny trick, Ashkbiz sets the protect on this memory range to the same as mem-bp.
This will make olly stop and pass except.
The protector then checks if ret executed or if exception occured.
Lie.. change the C3 -> CC and cause int3 exception =D
Good idea, weakly implemented.
So good, we changed ret to int3.
Now press ctrl-G and go to LoadLibraryA and set a BP
Continue pressing shift-f9 until we break in LoadLibrary
tracing out of function [ctrl-f9] we end up in internal import resolver.
Note, remember to remove breakpoint in loadlibrary when you are done with it.