Log data
Address Message
77E7F13A CALL to WriteFile from nop_vm.004010BD
hFile = 00000007
Buffer = nop_vm.00401284
nBytesToWrite = 1
pBytesWritten = nop_vm.00403400
pOverlapped = NULL
77E7F13A Breakpoint at kernel32.WriteFile
string [[esp+8]] = y Opcode0x90, 7 June 2007 -
-----------------------------------------------------
Have phun !
Password pl0x: Yÿ
004010BD Breakpoint at nop_vm.004010BD
77E7F13A CALL to WriteFile from nop_vm.004010BD
hFile = 00000007
Buffer = nop_vm.00401285
nBytesToWrite = 1
pBytesWritten = nop_vm.00403400
pOverlapped = NULL
77E7F13A Breakpoint at kernel32.WriteFile
string [[esp+8]] = Opcode0x90, 7 June 2007 -
-----------------------------------------------------
Have phun !
Password pl0x: Yÿ
004010BD Breakpoint at nop_vm.004010BD
77E7F13A CALL to WriteFile from nop_vm.004010BD
hFile = 00000007
Buffer = nop_vm.00401286
nBytesToWrite = 1
pBytesWritten = nop_vm.00403400
pOverlapped = NULL
77E7F13A Breakpoint at kernel32.WriteFile
string [[esp+8]] = Opcode0x90, 7 June 2007 -
-----------------------------------------------------
Have phun !
Password pl0x: Yÿ
004010BD Breakpoint at nop_vm.004010BD
77E7F13A CALL to WriteFile from nop_vm.004010BD
hFile = 00000007
Buffer = nop_vm.00401287
nBytesToWrite = 1
pBytesWritten = nop_vm.00403400
pOverlapped = NULL
77E7F13A Breakpoint at kernel32.WriteFile
string [[esp+8]] = pcode0x90, 7 June 2007 -
-----------------------------------------------------
Have phun !
Password pl0x: Yÿ
004010BD Breakpoint at nop_vm.004010BD
Call stack of main thread
Address Stack Procedure / arguments Called from Frame
0012FCC0 77F762F3 Includes 7FFE0304 ntdll.77F762F1 0012FCE0
0012FCC4 77F561A5 ntdll.ZwRequestWaitReplyPort ntdll.77F561A0 0012FCE0
0012FCE4 77E92703 ntdll.CsrClientCallServer kernel32.77E926FD 0012FCE0
0012FDD4 77E92588 ? kernel32.77E925DB kernel32.ReadConsoleA+26 0012FDD0
0012FE4C 77E92542 kernel32.ReadConsoleA kernel32.77E9253D 0012FE48
0012FE50 00000003 hConsole = 00000003
0012FE54 00403000 Buffer = nop_vm.00403000
0012FE58 00000400 ToRead = 400 (1024.)
0012FE5C 00403400 pRead = nop_vm.00403400
0012FE60 00000000 pReserved = NULL
00403000 68 65 6C 6C 6F 20 76 6D 20 62 61 62 79 20 68 6F hello vm baby ho
00403010 77 20 61 72 65 20 79 6F 75 20 68 6F 70 65 20 79 w are you hope y
00403020 6F 75 20 61 72 65 20 65 61 73 79 20 0D 0A 00 00 ou are easy ....