Quote:
Originally posted by Lake292@Feb 26 2007, 19:33
that new function rocks! can u pls tell me how to make it work?
<hr>Append on Feb 26 2007, 14:09<hr> im trying to follow your steps but i dont understand wht u mean with unhook...
and those first 4 steps set window hooked.... i do nothing? thats just info?
<hr>Append on Feb 26 2007, 14:33<hr> ill ask once more and tell wht im doing wrong thank u in advice
so these are your steps:
this 4 steps i didnt do anything... thats just getting pass and id if im right
/*
10003664 call dword ptr [10033390] <- set hook window
10003707 call dword ptr [10033178]
100038b5 call dword ptr [100333a0] <- get window text
100038dd call dword ptr [100333a0] <- get window text
*/
here i changed to that jump but thats 2bit operation so 6 bits left i changed with 90
0040F310 <-BP and JMP 40F31E
same
0040F34D <-BP and JMP 40F360
here i just changed
0040F489 call 4144DE
here i didnt do anything it was there written just this way
004144DE jmp dword ptr 100035b0
nop 90
100035B0 <-BP
jmp and nop
100037D4 <-BP and JMP 100037DF
this one i dont understand... u mean put there nop?
100037DD call esi <- Unhook *avoid*
jmp and nop
1000383B <- BP and JMP 10003846
this i dunno also... u mean nop to all call esi? cause there is like alot call esi
1000XXXX call esi <- Unhook *avoid*
im not great at assembly codes but i understand it a little... so if u could help me i would be very thankfull
|
** This dll still infected with Trojan.PWS.Lenmir.30 please use as your own risk **
/*
10003664 call dword ptr [10033390] <- set hook window
10003707 call dword ptr [10033178]
100038b5 call dword ptr [100333a0] <- get window text
100038dd call dword ptr [100333a0] <- get window text
*/
Above is address that call function in user32.dll. It's just info for reference
here i changed to that jump but thats 2bit operation so 6 bits left i changed with 90
0040F310 <-BP and JMP 40F31E
I'm not sure what command on this but u can change it to JMP 40F31E (2 obcode)
same
0040F34D <-BP and JMP 40F360
here i just changed
0040F489 call 4144DE
No change here just info to set break point and trace to 4144DE
here i didnt do anything it was there written just this way
004144DE jmp dword ptr 100035b0
nop 90
100035B0 <-BP
jmp and nop
100037D4 <-BP and JMP 100037DF
this one i dont understand... u mean put there nop?
100037DD call esi <- Unhook *avoid*
If u jump from above command it's will jump above 100037DD. Just for your info that why i jump this instruction code.
jmp and nop
1000383B <- BP and JMP 10003846
this i dunno also... u mean nop to all call esi? cause there is like alot call esi
1000XXXX call esi <- Unhook *avoid*
Same as above it's only change 2 jmp on countrymakeinus.dll
If u read and understand 1-6 in first post. I think u can know what i say.