evaluator
September 10th, 2002, 21:09
I see very many place is trushed on this MB because of ASS-emulated IAT-tricks.
So for help to MB(!) I wrote here some easy-generic info.
Emulated APIS for latest ASsPR ordered by their adress in ASsPR module:
(calculated from base of ASsPR module)
1 base+10EE8 =======KERNEL32.dll GetProcAddress
2 base+1133C =======KERNEL32.dll GetModuleHandleA
3 base+11358 =======KERNEL32.dll GetVersion
4 base+11388 =======KERNEL32.dll GetCurrentProcess
5 base+11390 =======KERNEL32.dll GetCurrentProcessId
6 base+1139C =======KERNEL32.dll GetCommandLineA
7 base+113B4 =======KERNEL32.dll LockResource
8 base+113C4 =======KERNEL32.dll FreeResource
--
Sometimes also is emulated 1 API from USER32.DLL====DialogBoxParamA
PS.
BAD NEWZ
:
usualy when ASS read thiz, he will update..
GOOD NEWZ
;
we are here..&
_WE WILL,
___WE WILL,
_____ROCK YOUUUUUUU! <-protz
[Licensed to QUEEN]
So for help to MB(!) I wrote here some easy-generic info.
Emulated APIS for latest ASsPR ordered by their adress in ASsPR module:
(calculated from base of ASsPR module)
1 base+10EE8 =======KERNEL32.dll GetProcAddress
2 base+1133C =======KERNEL32.dll GetModuleHandleA
3 base+11358 =======KERNEL32.dll GetVersion
4 base+11388 =======KERNEL32.dll GetCurrentProcess
5 base+11390 =======KERNEL32.dll GetCurrentProcessId
6 base+1139C =======KERNEL32.dll GetCommandLineA
7 base+113B4 =======KERNEL32.dll LockResource
8 base+113C4 =======KERNEL32.dll FreeResource
--
Sometimes also is emulated 1 API from USER32.DLL====DialogBoxParamA
PS.
BAD NEWZ

usualy when ASS read thiz, he will update..
GOOD NEWZ

we are here..&
_WE WILL,
___WE WILL,
_____ROCK YOUUUUUUU! <-protz
[Licensed to QUEEN]