PDA

View Full Version : CopyMem 2


S3ri@l CoDe9x
03-23-2003, 03:19 AM
Hi all


I see in one board ( hxxp://www.xtin.org/) one post about CopyMem 2. But i not understand ,this post is written in Russian lenguage , I don't have idea . Anybody can translate in english lenguage?

I hope that anybody know this lenguage .. I attach in this post.

Tnkx

LaptoniC
03-23-2003, 06:43 AM
I dont know russian but, according to source code here ismy guess.He injects inject.dll to armadillo's process and because the dll will have same rights in the process he can dump it.However this code only works on win2k/xp I guess because CreateRemoteThread,VirtualAllocEx are notsupported on win9x/Me.Of couse you can use ELiCZ's Elirt library for this.Hope I am not wrong.

r4g3
03-23-2003, 01:44 PM
babelfish.altavista.com

S3ri@l CoDe9x
03-23-2003, 03:57 PM
Quote:
Originally posted by LaptoniC
I dont know russian but, according to source code here ismy guess.He injects inject.dll to armadillo's process and because the dll will have same rights in the process he can dump it.However this code only works on win2k/xp I guess because CreateRemoteThread,VirtualAllocEx are notsupported on win9x/Me.Of couse you can use ELiCZ's Elirt library for this.Hope I am not wrong.



Yes i understand the source , but i find understand all text and babelfish.altavista.com it's really bad


Best Regards

neviens
03-24-2003, 06:02 AM
Not exact translation.
Neviens.
PS English and Russian are not my mother languages, fatal
errors and BSOD are possible, you have been warned!

S3ri@l CoDe9x
03-24-2003, 02:47 PM
Quote:
Originally posted by neviens
Not exact translation.
Neviens.
PS English and Russian are not my mother languages, fatal
errors and BSOD are possible, you have been warned!




Tnkx!! Itīs good translation.


Best Regards

nikolatesla20
03-24-2003, 02:55 PM
Thank you!

The technique works quite well.

-nt20

JMI
03-24-2003, 03:36 PM
You might also want to check out this article, posted on AntiCrack back in January 2003, entitled: "Armadildo and CopyMem II decryption."


hxxp://www.anticrack.de/modules.php?op=modload&name=News&file=article&sid=3742

Regards.