Quote:
Originally posted by Gera+Jan 6 2007, 23:47--></span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (Gera @ Jan 6 2007, 23:47)</td></tr><tr><td id='QUOTE'> <!--QuoteBegin--anantasia@Jan 6 2007, 23:25
After you pause due to set break point at 403596 and change EIP to 40359C and set breakpoint to new address 4059BC. You must choose debug/run on CE menu to make program to running code again.
|
awesome !!! now i got up to point 5
/*5* Set trap at 403685. When CE stop press F7 to trace in to sub routine 403CF6
00403685 CALL 00403CF6 <- this command to call routine at address 00403CF6 and when hit command RET. It's will return to next address 40368A
0040368A mov eax,[esi+1c]
so i did search for that adress and when i found it i put another break as soon as i made the set breakpoint in there i choosed debug/run again so it went right as you said it should work. BUT i dont understand that part i choose F7 and CE takes me to 00403F6 but i dont kno what to do here at this point. i simply dont get it if i have to edit something or if i haveto click in the screen something.
so does point 6.
/*6* Routine 403CF6 will send you to address 10002860. Press F7 to step to countrymakeinUS.dll
00403CF6 JMP DWORD PTR[00429508] <- Just FYI, this command jump to DLL. DWORD PTR[00429508] = 10002860
i dont kno what is FYI and what do i have to change i have to edit the 00429508 to 10002860?
/*7* Starting tracestep at here, look carefully for miss jump/exit program
10002860 SUB ESP, 000000C8 <- here is starting of countrymakeinus.dll
this is just a warning right?
1000288B CALL 1001E804 <- Nothing to do at here just press F8 to step over
this is easy just press f8 and voila.
and points 8 9 10 are easier like the first ones right?. so im confused now at points 5 6 and 7.
thanks in advance !!!
thanks in advance !! [/b][/quote]
In step 5 - 6 -7 , You just step and trace in call routine. Nothing to do just only F7 till u hit address 10002860,