![]() |
|
|
|
#1
|
|||
|
|||
|
ah, thats some crap, i dont think that this is yodas crypter but nevermind
aplication is compiled with Borlan delphi if you want to get oep by hand you can do this on easy way, but first you need to make some settings in olly, if you probably have ollyadvanced plugin by marcus, turn on all anty debuging just for case i was dont have time to test then in debuging options in olly in exceptions ignore memory access violations in KERNEL32, INT3 Breaks, Single-step-Break and Memory access violation, save changes and open you aplication now hit F8 and use ESP trick, if you dont know ( in right panel (FPU Registers)) on esp right click and fallow on dump, then set bp hardware on access (dword) hit shift+f9, after this press ALT+M to get memory map and set bp on .code section (bp on access, and hit again shift+f9 ![]() if you do this right you are on oep, if dont try to hit shift+f9 couple times, on my olly works after one click. then you need to dump target and fix import, for fixing imports use trace level 1 thats all ![]() i am not stupid to test is this works, but thats the way, you can test is you want ![]() and now litle about what this crap can do with you thats the links from this trojan for downloading hxxp://www.ac66.cn/down/rx.exe hxxp://www.ac66.cn/down/qq.exe hxxp://www.ac66.cn/down/gezi.exe hxxp://www.ac66.cn/down/aichong.exe hxxp://www.ac66.cn/down/mhxy.exe hxxp://down.136136.net/down/cq.exe also C:\WINDOWS\system32\drivers\etc\hosts http://down.136136.net/down/host.txt and its create file C:\Program Files\Common Files\update\ubdate.exe and calling from regedit from HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run i hope that you understand me, sorry for my gramatical errors i am from serbia and i am limited with english. Best regards |
![]() |
| Thread Tools | |
| Display Modes | |
|
|