View Single Post
  #6  
Old 02-25-2011, 23:09
ahmadmansoor's Avatar
ahmadmansoor ahmadmansoor is offline
Coder
 
Join Date: Feb 2006
Location: Syria
Posts: 1,047
Rept. Given: 517
Rept. Rcvd 374 Times in 142 Posts
Thanks Given: 380
Thanks Rcvd at 416 Times in 119 Posts
ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399
Welcome Vam between us .... and Thanks for response .
I will send the target to ur PM , sorry from all , it is a private software .


Edit:

after it decoded "kernel32.GetVersion" , it produce the trc file , but not produce log file and olly exit
Quote:
005C83ED 8DBF EC6A>lea edi, dword ptr [edi+B5826AEC]
in trc file it end at
Quote:
0x0053992D: ret 58h
but the function end at
Quote:
005C8415 C2 4000 ret 40
to back to this :
Quote:
00447370 E8 0F6F12>call unpacked.0056E284 >>>>> Function
00447375 57 push edi >>>> back from ret 40
00447376 FFD6 call near esi ; kernel32.GetVersion
does VMware affect on the work of this plugin or not ??!!
__________________
Ur Best Friend Ahmadmansoor
Always My Best Friend: Aaron & JMI & ZeNiX
Reply With Quote