<>Tlʾ :- | StIc/ TRW2000 Debugg | | | | ><> | PcDump 1.62 | | | | ><> | Ho(Hwk3.10) | | | | ><> | | | | | ><>Pbm:- | SI decп foBPX m(usBPMB xxxxxxxx X) | | | | ><> | | | | | ><>Tg- | ULEAD SmaSaPr3 Trl | | | | ><> | | | | | ><> | Inrucп:- | | | | ><> | | | | | ><>Pa 1 | S USSP.tg tύ'Trl/Info/Qu' ǫ. | | | | ><> | Ps'Ctl-D' tSce | | | | ><> | S 'BPX GPcAdd' & F5 back tWdoze | | | | ><> | Ps'Try' Buѿ d SI wi pop VBoxT410.d. PsF12. TypBC* tcla BPX | | | | ><> | Fo dn ύcodwh F10 uny JL 7007B23 i.elpback upLk dn d cod ");
d("d pc ~ 7007D12 :- | | | | ><> | 5B POP EBX | | | | ><> | C9 LEAVE | | | | ><> | C3 RET | | | | ><> | S BPMB 7007D12 X ( BPX wi s ύmpeprecп VBOX !) | | | | ><> | PsF5 (buildύImpTablfovalid API lks) | | | | ><> | PsF10 uny ۍVBoxB410.d | | | | ><> | CtuF10 uny ۍUSSPRO.PREVIEW cod(~ 537026 n fasbcafu!!) | | | | ><> | PsF10 uny code | | | | ><> | 537030&nb; PUSH FFFFFFFF | | | | ><> | 537035 CALL EAX (x = 4CC1E2 ύEiP w !) | | | | ><> | PsF8 tSTEP tϰca d d'psʙyi elԍEIP gield b4CC1E2 ԤY ۍ ύEiP ύunpack es STOP d lk : | | | | ><> | ");
d("; 55 PUSH EBP | | | | ><> | 8BEC MOV EBP,ESP | | | | ><> | blah PUSH ................. | | | | ><> | (ԍnum stϤ havϰcod EIP unlvabl!) | | | | ><> | | | | | ><>Pa 2 | N w tdump ύtdc d build ύhdewh PcDump. | <");
d("td het=21> | | ><> | Sn wdύfoi depdi yÌtl: | | | | ><> | a) SiC :- 4CC1E2 wh EB FE (ϰcodtJMP EIP iLOOP !) | | | | ><> | Wc n dabla BP SI d psF5 tg back tWdozd run PcDump | | | | ><> | Sc dn ύTk Wd tfd ULEAD USSPRO.EXE.Rclk d ct DUMP (FULL)Sav tyr Pgm Fis\\Uld SmaSaPr3.0 dicty. | | | ><> | N whavtki ύlpi pgm scKILL TASK tҡop . | | | | ><> | Y wi havtsr foEB FE EC wh yÌh od gback ostwbyt55 8B hwy wi a lpi pgm :( | | | | ><> | b) SiCwh PDUMP add :- PAGEIN D 400000 1C8000 C:\\TEMP\\USS-DMP.EXE | | | | ><> | | | | | ><> | c) TRW2000 :- PEDUMP USS-DMP.EXE (oTrMAKEPE if y havύfu vܿ) | | | | ><> | | | | | ><> | If y amyÌw wi bab1.78 gʵd 561 k. | | | | ><> | Wn havttunup Ìdump tmak run Wdoze | | | | ><> | Op / Sw tPcDump agad ct Opпʙd maksu ALL ύSucturcп ۍct wh ckԍImpcп ld hav'D'build impt'.Sec'Rebuild PE' brstyÌdump d clk 'Op' Ԥ ld fix Ìw hded l urun Ìunpack Wdoze98 (pbab n NT4 unftun d n som");
d(" elPC dutύImagTabli FIXED foyÌPC sy) Y ld alseck Ϥ ύEnPoӴύ'Hd' cп y'000CC1E2' sϤ ύImagB 0400000+000CC1E2 = 004CC1E2 = ԍEiP | | | | ><> | MovyÌdump tύrpgm dictd dblclk t . | | | | ><> | | | | | ><>Pa 3 | P yrlf ύbackHavdrkDelύl af15 days. | | | | ><> | | | | | ><>Pa 4 - Debrf | VBox 4.10 w ");
d("fir tpbWJunLi tcǤύsucceotTiLockIu3 (o4 if opп tbuύst) dm VboxX.d ! d .l ttck yÌudۍcrypt d pack d mul CRC prectIw poibltbuild funcпi cck vܿ 4.10 d buύigaբw i 'prect' bύsySusʡi g ύg ǫʩcIӰmu etlrn ύa unpacki md mshʙd awۍpgƼۍuܜ compi+precttҡop ύcuavs/cckԫ camVbox 4.20 wh mprecп d ev m SI rt. N ϨVbox 4.30 :-) Whavlrn httcpgm tfd ύquir EiP (ύpgm rpot) Ϥ ύfir rucп ύrstWalslrn ύk 'sudi' ύswh EB FE p (JMP EIP lp) d tdump ύl wh PcDumpIf y havTRW2000 y c ύMAKEPE t");
d("hpotvb лWdid n focuʿ ύImagTablpbmfon ϰb madvcWϫ lrn tusPcDump (ϙkG-Rom & Co.) tǡύPE Hded fix up ύdump tҎW32 stAgan lki abύImpTabY c n dsblύunpack sәd lk fombugtfix. di p iǺ ;-) | | | | >