<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title><![CDATA[RCE Messageboard's Regroupment]]></title>
		<link>http://www.woodmann.com/forum</link>
		<description>Serious reversing, cracking and programming discussions</description>
		<language>en</language>
		<lastBuildDate>Sat, 06 Sep 2008 02:34:14 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>http://www.woodmann.com/forum/images/misc/rss.jpg</url>
			<title><![CDATA[RCE Messageboard's Regroupment]]></title>
			<link>http://www.woodmann.com/forum</link>
		</image>
		<item>
			<title>Rainbow super pro (copier)</title>
			<link>http://www.woodmann.com/forum/showthread.php?t=12048&amp;goto=newpost</link>
			<pubDate>Fri, 05 Sep 2008 18:11:32 GMT</pubDate>
			<description>hi, I have a copier machine and need a rainbow super pro dongle to use the email, fax... etc, then my idea was to connect the dongle to my pc usb port and with a filter driver and library to write a program for capture the raw data of usb and redirect it to copier machine in other usb port (+ - an...</description>
			<content:encoded><![CDATA[<div>hi, I have a copier machine and need a rainbow super pro dongle to use the email, fax... etc, then my idea was to connect the dongle to my pc usb port and with a filter driver and library to write a program for capture the raw data of usb and redirect it to copier machine in other usb port (+ - an usb proxy...), but when I've tried this, the program only show me URB data...<br />
<br />
I wish know if it is posible, capture the dongle raw data(with my idea(proxy)) and burn a microcontroller for emulation(using dongle capture) and connect it to copier machine or I must to crack the firmware of copier....<br />
<br />
ideas?<br />
<br />
sorry, English is not my mother tongue...</div>

]]></content:encoded>
			<category domain="http://www.woodmann.com/forum/forumdisplay.php?f=16">The Newbie Forum</category>
			<dc:creator>ZEALOT</dc:creator>
			<guid isPermaLink="true">http://www.woodmann.com/forum/showthread.php?t=12048</guid>
		</item>
		<item>
			<title>{smartassassin} v1.0</title>
			<link>http://www.woodmann.com/forum/showthread.php?t=12046&amp;goto=newpost</link>
			<pubDate>Thu, 04 Sep 2008 09:32:14 GMT</pubDate>
			<description>{smartassassin} is a reversing engineering tool used to remove string encryption 
from {smartassembly} protected files, its also possible to decompress resources 
compressed by {smartassassin}. 
 
If the original file was strong name signed {smartassassin} will create a new keypair 
and re-sign the...</description>
			<content:encoded><![CDATA[<div>{smartassassin} is a reversing engineering tool used to remove string encryption<br />
from {smartassembly} protected files, its also possible to decompress resources<br />
compressed by {smartassassin}.<br />
<br />
If the original file was strong name signed {smartassassin} will create a new keypair<br />
and re-sign the file with this pair, be carefull since file depending on this file will<br />
need to be edited manaualy to support the new strong name signature.<br />
You can use RE-Sign for this and the editor of your choice<br />
<br />
Also if you like the file re-signed with a specific key place your key in the same<br />
folder as the file you are about to process and rename it to {smartassassin}.snk<br />
now {smartassassin} will use this key for the re-sign process.<br />
<br />
Hope this tool is of any use<br />
<br />
<img src="http://www.reteam.org/tools/ts34.gif" border="0" alt="" /><br />
<br />
Check the tool section on <i><u>www.reteam.org</u></i> for the download</div>

]]></content:encoded>
			<category domain="http://www.woodmann.com/forum/forumdisplay.php?f=3">Tools of our Trade (TOT) Messageboard</category>
			<dc:creator>LibX</dc:creator>
			<guid isPermaLink="true">http://www.woodmann.com/forum/showthread.php?t=12046</guid>
		</item>
		<item>
			<title>White-Box Cryptography</title>
			<link>http://www.woodmann.com/forum/showthread.php?t=12045&amp;goto=newpost</link>
			<pubDate>Thu, 04 Sep 2008 07:44:23 GMT</pubDate>
			<description><![CDATA["White-box cryptography is a technique to hide a secret key into a cryptographic software implementation in a white-box model. In such a model, an adversary has full control over the execution environment.  
 
A white-box DES encryption binary with embedded secret key. If you like, try to extract...]]></description>
			<content:encoded><![CDATA[<div>&quot;White-box cryptography is a technique to hide a secret key into a cryptographic software implementation in a white-box model. In such a model, an adversary has full control over the execution environment. <br />
<br />
A white-box DES encryption binary with embedded secret key. If you like, try to extract the secret key, using all information you can find from this implementation (input-ouput attacks, so called black box attacks, are not allowed). &quot;<br />
<br />
here is there demo link (cygwin1.dll is needed):<br />
<i><u>https://www.cosic.esat.kuleuven.be/sopro/wbc/wbDES.exe</u></i><br />
<br />
here is there website:<br />
<i><u>https://www.cosic.esat.kuleuven.be/sopro/</u></i><br />
<i><u>https://www.cosic.esat.kuleuven.be/sopro/wbc/</u></i><br />
<br />
i'm currently working on this and look at the attached file that i have made :P<br />
<br />
come and join to reverse this protection ... sooner the better<br />
<br />
regards,<br />
LaBBa.</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.woodmann.com/forum/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.woodmann.com/forum/attachment.php?attachmentid=1923&amp;d=1220514183">sub_401050.zip</a> (3.3 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.woodmann.com/forum/forumdisplay.php?f=9">Rce Cryptographics</category>
			<dc:creator>LaBBa</dc:creator>
			<guid isPermaLink="true">http://www.woodmann.com/forum/showthread.php?t=12045</guid>
		</item>
		<item>
			<title>Allocating Memory below imagebase</title>
			<link>http://www.woodmann.com/forum/showthread.php?t=12044&amp;goto=newpost</link>
			<pubDate>Wed, 03 Sep 2008 19:23:56 GMT</pubDate>
			<description>hi guys , ive encountered a little problem ... im trying to allocate some free memory below imagebase ..but doesent seem to be doable ..so im wondering is this possible at all from ring3 ? ( hacks ? hehe )  , or will i have to go ring3 to get the power needed to preform this deed .. looking forward...</description>
			<content:encoded><![CDATA[<div>hi guys , ive encountered a little problem ... im trying to allocate some free memory below imagebase ..but doesent seem to be doable ..so im wondering is this possible at all from ring3 ? ( hacks ? hehe )  , or will i have to go ring3 to get the power needed to preform this deed .. looking forward to your responses<br />
<br />
just seems wierd , since i can VirtualQuery them without a problem <br />
<br />
and yes i did check my virtualAlloc call :) if i allocate addr above image..it works</div>

]]></content:encoded>
			<category domain="http://www.woodmann.com/forum/forumdisplay.php?f=16">The Newbie Forum</category>
			<dc:creator>Arcane</dc:creator>
			<guid isPermaLink="true">http://www.woodmann.com/forum/showthread.php?t=12044</guid>
		</item>
		<item>
			<title><![CDATA[Kernel Detective - new security & analysis tool]]></title>
			<link>http://www.woodmann.com/forum/showthread.php?t=12043&amp;goto=newpost</link>
			<pubDate>Tue, 02 Sep 2008 21:23:12 GMT</pubDate>
			<description><![CDATA[Kernel Detective is a free tool that help you detect, analyze, manually modify and fix some Windows NT kernel modifications. Kernel Detective gives you the access to the kernel directly so it's not oriented for newbies. Changing essential kernel-mode objects without enough knowledge will lead you...]]></description>
			<content:encoded><![CDATA[<div><i>Kernel Detective is a free tool that help you detect, analyze, manually modify and fix some Windows NT kernel modifications. Kernel Detective gives you the access to the kernel directly so it's not oriented for newbies. Changing essential kernel-mode objects without enough knowledge will lead you to only one result, BSOD !!</i><br />
 <br />
<u><i>Supported NT versions : XP(sp1-sp2-sp3) - Vista Ultimate build 6000</i></u><br />
 <br />
 <br />
<u><b>With Kernel Detective you can:</b></u><br />
 <br />
<b>Enumerate running processes</b> and print important values like Process Id, Parent Process Id, ImageBase, EntryPoint, VirtualSize, PEB block address and EPROCESS block address. Kernel Detective also has special scan methods for detecting hidden processes<br />
 <br />
<b>Enumerate a specific running processe Dynamic-Link Libraries</b>. Also show every Dll ImageBase, EntryPoint, Size and Path .<br />
 <br />
<b>Enumerate loaded kernel-mode drivers</b> and show every driver ImageBase, EntryPoint, Size, Name and Path. Also it has special methods for detecting hidden drivers.<br />
 <br />
<b>Scan the system service table (SSDT) </b>and show every service function address and the real function address. You can restore single service function address or restore the whole table.<br />
 <br />
<b>Scan the shadow system service table (Shadow SSDT)</b> and show every shadow service function address and the real function address. You can restore single shadow service function address or restore the whole table<br />
 <br />
<b>Scan the interrupts table (IDT) </b>and show every interrupt handler offset, selector, type, Attributes and real handler offset. This is applied to every processor in a multi-processors machines.<br />
 <br />
<b>Scan the important system kernel modules, detect the modifications in it's body and analyze it</b>. For now it can detect and restore inline code modifications, EAT and IAT hooks. I'm looking for more other types of hooks next releases of Kernel Detective.<br />
 <br />
<b>A nice disassembler</b> rely on OllyDbg disasm engine, thanks Oleh Yuschuk for publishing the source code of your nice disasm engine . With it you can disassemble, assemble and hex edit virtual memory of a specific process or even the kernel space memory. Kernel Detective use it's own Read/Write routines from kernel-mode and doesn't rely on any windows API. That make Kernel Detective able to R/W processes VM even if NtReadProcessMemory/NtWriteProcessMemory is hooked, also bypass the hooks on other kernel-mode important routines like KeStackAttachProcess and KeAttachProcess<br />
 <br />
<b>Show the messages sent by drivers to the kernel debugger</b> just like Dbgview by Mark Russinovich. It's doing this by hooking interrupt 0x2d wich is responsible for outputing debug messages. Hooking interrupts may cause problems on some machines so DebugView is turned off by default, to turn it on you must run Kernel Detective with &quot;-debugv&quot; parameter.<br />
 <br />
Coded by GamingMasteR -AT4RE<br />
 <br />
Download<br />
 <br />
<i><u><i><u>http://www.at4re.com/tools/Releases/GamingMasteR/Kernel_Detective_v1.0.zip</u></i></u></i></div>

]]></content:encoded>
			<category domain="http://www.woodmann.com/forum/forumdisplay.php?f=3">Tools of our Trade (TOT) Messageboard</category>
			<dc:creator>GamingMasteR</dc:creator>
			<guid isPermaLink="true">http://www.woodmann.com/forum/showthread.php?t=12043</guid>
		</item>
		<item>
			<title>Cracking kit 2010</title>
			<link>http://www.woodmann.com/forum/showthread.php?t=12042&amp;goto=newpost</link>
			<pubDate>Mon, 01 Sep 2008 18:10:38 GMT</pubDate>
			<description>The contents of the CDs are bundled up with the download. 
  
Image: http://img148.imageshack.us/img148/5967/imgra4.jpg  
  
 
---Quote--- 
Cracking kit 2010 is the *biggest* collection of reverse engineering tools ever compiled. 
  
It consists of two ISOs that when unpacked yield over 2GB worth...</description>
			<content:encoded><![CDATA[<div>The contents of the CDs are bundled up with the download.<br />
 <br />
<img src="http://img148.imageshack.us/img148/5967/imgra4.jpg" border="0" alt="" /><br />
 <br />
<div style="margin:20px; margin-top:5px; ">
	<div class="smallfont" style="margin-bottom:2px">Quote:</div>
	<table cellpadding="6" cellspacing="0" border="0" width="100%">
	<tr>
		<td class="alt2">
			<hr />
			
				Cracking kit 2010 is the <b>biggest</b> collection of reverse engineering tools ever compiled.<br />
 <br />
It consists of two ISOs that when unpacked yield over 2GB worth of toolz.<br />
 <br />
 
			
			<hr />
		</td>
	</tr>
	</table>
</div></div>

]]></content:encoded>
			<category domain="http://www.woodmann.com/forum/forumdisplay.php?f=3">Tools of our Trade (TOT) Messageboard</category>
			<dc:creator>ZZZXXX</dc:creator>
			<guid isPermaLink="true">http://www.woodmann.com/forum/showthread.php?t=12042</guid>
		</item>
		<item>
			<title>bit of a simple one here</title>
			<link>http://www.woodmann.com/forum/showthread.php?t=12041&amp;goto=newpost</link>
			<pubDate>Mon, 01 Sep 2008 16:51:28 GMT</pubDate>
			<description>Hi all 
 
Within Ollydbg I am having difficulty finding the part of assembly code i want to add a break point in. What i want to to do is put a break point in the very first instruction the program goes in to after a click of a certain button but i cannot find where this is in the code, is it...</description>
			<content:encoded><![CDATA[<div>Hi all<br />
<br />
Within Ollydbg I am having difficulty finding the part of assembly code i want to add a break point in. What i want to to do is put a break point in the very first instruction the program goes in to after a click of a certain button but i cannot find where this is in the code, is it possble to set an instant breakpoint on submission of any operation.<br />
<br />
I've only been doing simple key gens in the past and been able to manually set my breakpoint.:whoops:</div>

]]></content:encoded>
			<category domain="http://www.woodmann.com/forum/forumdisplay.php?f=16">The Newbie Forum</category>
			<dc:creator>GES1234</dc:creator>
			<guid isPermaLink="true">http://www.woodmann.com/forum/showthread.php?t=12041</guid>
		</item>
		<item>
			<title>NEW!</title>
			<link>http://www.woodmann.com/forum/showthread.php?t=12040&amp;goto=newpost</link>
			<pubDate>Mon, 01 Sep 2008 14:24:30 GMT</pubDate>
			<description><![CDATA[Hey guys and gals, just thought I'd intro myself and congratulate you on a very informative site. 
 
Keep up the good work, I'll be watching as usual :)]]></description>
			<content:encoded><![CDATA[<div>Hey guys and gals, just thought I'd intro myself and congratulate you on a very informative site.<br />
<br />
Keep up the good work, I'll be watching as usual :)</div>

]]></content:encoded>
			<category domain="http://www.woodmann.com/forum/forumdisplay.php?f=16">The Newbie Forum</category>
			<dc:creator>Enter7ainer</dc:creator>
			<guid isPermaLink="true">http://www.woodmann.com/forum/showthread.php?t=12040</guid>
		</item>
		<item>
			<title>Anybody has used Microsoft Base Smart Card CSP yet?</title>
			<link>http://www.woodmann.com/forum/showthread.php?t=12039&amp;goto=newpost</link>
			<pubDate>Mon, 01 Sep 2008 05:47:56 GMT</pubDate>
			<description>Hi all 
Is there anybody who has ever used Microsoft Base Smart Card CSP? 
It is a CSP that works with a small DLL in order to work with Smart Cards. 
I have written one of these DLL and it works well when I use web enrollment of my Smart Card, but when I try to use autoenrollment, it fails. 
is...</description>
			<content:encoded><![CDATA[<div>Hi all<br />
Is there anybody who has ever used Microsoft Base Smart Card CSP?<br />
It is a CSP that works with a small DLL in order to work with Smart Cards.<br />
I have written one of these DLL and it works well when I use web enrollment of my Smart Card, but when I try to use autoenrollment, it fails.<br />
is there any idea what happens that causes failing autoenrollment operation?<br />
<br />
Regards</div>

]]></content:encoded>
			<category domain="http://www.woodmann.com/forum/forumdisplay.php?f=2">Advanced reversing and programming</category>
			<dc:creator>Hero</dc:creator>
			<guid isPermaLink="true">http://www.woodmann.com/forum/showthread.php?t=12039</guid>
		</item>
		<item>
			<title>CRC_DRx crackme</title>
			<link>http://www.woodmann.com/forum/showthread.php?t=12038&amp;goto=newpost</link>
			<pubDate>Sun, 31 Aug 2008 16:09:51 GMT</pubDate>
			<description>ROSASM burnt yet another cr0ckme mit SRC! 
 
kill yO-self now! ~ = D 
 
edit: 
who will BRUTE, will LEAST PENsIL..</description>
			<content:encoded><![CDATA[<div>ROSASM burnt yet another cr0ckme mit SRC!<br />
<br />
kill yO-self now! ~ = D<br />
<br />
edit:<br />
who will BRUTE, will LEAST PENsIL..</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.woodmann.com/forum/images/attach/zip.gif" alt="File Type: zip" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.woodmann.com/forum/attachment.php?attachmentid=1920&amp;d=1220198876">jE!_CRC_DRx.zip</a> (3.7 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.woodmann.com/forum/forumdisplay.php?f=5">Mini Project Area</category>
			<dc:creator>evaluator</dc:creator>
			<guid isPermaLink="true">http://www.woodmann.com/forum/showthread.php?t=12038</guid>
		</item>
		<item>
			<title>.NET question</title>
			<link>http://www.woodmann.com/forum/showthread.php?t=12037&amp;goto=newpost</link>
			<pubDate>Sun, 31 Aug 2008 08:37:09 GMT</pubDate>
			<description><![CDATA[What can this class actually accomplish? 
 
It's from a target that I completed, but decided to go have a look around.  Using DotNET Tracer 0.3, it shows that this class actually DOES some stuff, and I don't see how. 
 
Code: 
--------- 
.class private auto ansi a1 extends [mscorlib]System.Object...]]></description>
			<content:encoded><![CDATA[<div>What can this class actually accomplish?<br />
<br />
It's from a target that I completed, but decided to go have a look around.  Using DotNET Tracer 0.3, it shows that this class actually DOES some stuff, and I don't see how.<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">.class private auto ansi a1 extends [mscorlib]System.Object implements TARGET.IEdition<br />
{<br />
&nbsp; .field public initonly value class [mscorlib]System.DateTime a<br />
<br />
&nbsp; .field private static class a1 a<br />
<br />
&nbsp; .field private class [mscorlib]System.EventHandler a<br />
<br />
&nbsp; .field private bool a<br />
<br />
&nbsp; .field private class [SKCLNET]SKCLNET.LFile a<br />
<br />
&nbsp; .field private value class [resource]TARGET.TARGETEdition a<br />
<br />
<br />
&nbsp; .method private hidebysig specialname void .ctor() noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ldarg.0<br />
&nbsp; &nbsp; call void [mscorlib]System.Object::.ctor()<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method public static hidebysig class a1 a() noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ldnull<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method public hidebysig void a(int32 A_0) noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method public hidebysig bool a() noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ldc.i4.0<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method public hidebysig bool b() noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ldc.i4.0<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method public hidebysig int32 a(int32 A_0, int32 A_1, int32 A_2, int32 A_3, int32 A_4, class System.String A_5) noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ldc.i4.0<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method public hidebysig int32 a(int32 A_0, class System.String A_1, int32&amp; A_2) noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ldc.i4.0<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method public hidebysig bool a(value class [resource]TARGET.TARGETEdition A_0) noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ldc.i4.0<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method public final virtual hidebysig newslot bool a(value class [resource]TARGET.TARGETEdition A_0, bool A_1) noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ldc.i4.0<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method public hidebysig specialname void a(class [mscorlib]System.EventHandler A_0) synchronized noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method public hidebysig specialname void b(class [mscorlib]System.EventHandler A_0) synchronized noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method family hidebysig void c() noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method private hidebysig int32 a(int32 A_0, int32 A_1, int32 A_2, int32&amp; A_3) noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ldc.i4.0<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method private hidebysig void b() noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method private hidebysig void a() noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method private hidebysig void a(bool A_0) noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method public hidebysig specialname bool c() noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ldc.i4.0<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method public hidebysig specialname class [SKCLNET]SKCLNET.LFile a() noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ldnull<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method public final virtual hidebysig newslot specialname value class [resource]TARGET.TARGETEdition a() noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ldnull<br />
&nbsp; &nbsp; unbox [resource]TARGET.TARGETEdition<br />
&nbsp; &nbsp; ldobj [resource]TARGET.TARGETEdition<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
<br />
&nbsp; .method private static hidebysig specialname void .cctor() noinlining<br />
&nbsp; {<br />
&nbsp; &nbsp; ret<br />
&nbsp; }<br />
}</code><hr />
</div>To ME, it looks like a whole lotta nothing.<br />
<br />
Anyone see the magic that I missed?<br />
<br />
Here's the output from DotNET Tracer.  (At least the pertinent parts)<br />
<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">JIT compilation started,&nbsp; name: a1..cctor<br />
JIT compilation started,&nbsp; name: a1..ctor<br />
Assembly load started,&nbsp; ID: 1780144<br />
Module load started,&nbsp; name: C:\WINDOWS\assembly\GAC\SKCLNET\4.3.1.0__d5770e63406d04a0\SKCLNET.dll<br />
Module C:\WINDOWS\assembly\GAC\SKCLNET\4.3.1.0__d5770e63406d04a0\SKCLNET.dll attached to assembly SKCLNET<br />
JIT compilation started,&nbsp; name: a1.b<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile..cctor<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile..ctor<br />
JIT compilation started,&nbsp; name: .__crt_dll_initialize<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.IsDebugLic<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.SetDefaultValues<br />
JIT compilation started,&nbsp; name: SKCLNET.SomeClass.dummy<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.set_StatusChkInterval<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.SetStatusTimer<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.InitStatusTimer<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.set_UseEZTrigger<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.set_EZTrial<br />
JIT compilation started,&nbsp; name: .a<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.set_LFPassword<br />
JIT compilation started,&nbsp; name: cw.m<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.set_LFName<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.Open<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.CheckStatus<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.raise_StatusChanged<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.CheckError<br />
JIT compilation started,&nbsp; name: a1.a<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.GetUserNumber<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.GetVar<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.get_IsDemo<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.get_ExpireMode<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.GetVar<br />
JIT compilation started,&nbsp; name: SKCLNET.LFile.add_StatusChanged<br />
JIT compilation started,&nbsp; name: a1.a<br />
JIT compilation started,&nbsp; name: a1.a</code><hr />
</div></div>

]]></content:encoded>
			<category domain="http://www.woodmann.com/forum/forumdisplay.php?f=16">The Newbie Forum</category>
			<dc:creator>FrankRizzo</dc:creator>
			<guid isPermaLink="true">http://www.woodmann.com/forum/showthread.php?t=12037</guid>
		</item>
		<item>
			<title>SSPro - sproRead questons</title>
			<link>http://www.woodmann.com/forum/showthread.php?t=12034&amp;goto=newpost</link>
			<pubDate>Sat, 30 Aug 2008 13:08:43 GMT</pubDate>
			<description><![CDATA[Hello, 
 
I'm working on Sentinel Super Pro. I have two questions: 
 
1) sproREAD() 
Output from Toro: 
In:> Read Address=21 (0x15) 
Out:> Read Address=21 (0x15) -> Status=0x3 
Data=255 (0xFF)]]></description>
			<content:encoded><![CDATA[<div>Hello,<br />
<br />
I'm working on Sentinel Super Pro. I have two questions:<br />
<br />
1) sproREAD()<br />
Output from Toro:<br />
In:&gt; Read Address=21 (0x15)<br />
Out:&gt; Read Address=21 (0x15) -&gt; Status=0x3<br />
Data=255 (0xFF)<br />
<br />
What does Data=255 (0xFF) mean? (Did any error occured reading from cell15?)<br />
Why do I get from some other cells the output: Data=0 (0x0)? What's the difference?<br />
<br />
<br />
2) How should Cell0 be treated? <br />
<br />
quote from SDK:<br />
&quot;Key serial number; sequentially assigned per key.&quot;<br />
<br />
I read in a tutorial that this cell needs to be filled with the dongle serial number. Is there any general way to find the dongle serial number or what has to be put into this cell?<br />
<br />
Thank you for help!<br />
<br />
Best regards<br />
keen<br />
<br />
PS: I read all tutorials from CrackZ and the SDK-Doc.</div>

]]></content:encoded>
			<category domain="http://www.woodmann.com/forum/forumdisplay.php?f=16">The Newbie Forum</category>
			<dc:creator>keen2k</dc:creator>
			<guid isPermaLink="true">http://www.woodmann.com/forum/showthread.php?t=12034</guid>
		</item>
		<item>
			<title>Reversing a QT-GUI-Framework based Application</title>
			<link>http://www.woodmann.com/forum/showthread.php?t=12033&amp;goto=newpost</link>
			<pubDate>Sat, 30 Aug 2008 00:05:42 GMT</pubDate>
			<description><![CDATA[Hi there, 
 
what i'm trying to do is to patch away a popup-window in a QT-GUI-Framework (_http://trolltech.com/products/qt) based application written in VC++.  
 
As the framework has its own routines to create windows, there's no way to set breakpoints on createwindow and stuff (or at least I...]]></description>
			<content:encoded><![CDATA[<div>Hi there,<br />
<br />
what i'm trying to do is to patch away a popup-window in a QT-GUI-Framework (_http://trolltech.com/products/qt) based application written in VC++. <br />
<br />
As the framework has its own routines to create windows, there's no way to set breakpoints on createwindow and stuff (or at least I wasn't able to do it).<br />
<br />
A small sample of code for a window in QT looks like this<br />
<br />
<div style="margin:20px; margin-top:5px">
	<div class="smallfont" style="margin-bottom:2px">Code:</div>
	<hr /><code style="margin:0px" dir="ltr" style="text-align:left">QWinWidget *w = new QWinWidget(hWnd, 0, 0);<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  w-&gt;showCentered();<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  <font color="Red">QMessageBox *mb = new QMessageBox(&quot;Qt on Win32 - modeless&quot;,<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  &quot;Is this dialog modal?&quot;,<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  QMessageBox::NoIcon,<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  QMessageBox::Yes | QMessageBox::Default,<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  QMessageBox::No&nbsp; | QMessageBox::Escape,<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  QMessageBox::NoButton, w);<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  mb-&gt;setModal(false);<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  mb-&gt;setAttribute(Qt::WA_DeleteOnClose);<br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;  mb-&gt;show();</font></code><hr />
</div>My question is how can I identify this code in the debugger? My idea was to break in where the show() function (in its compiled state of course :-) ) is called ...<br />
<br />
Thanks for any hint!<br />
<br />
fxxx</div>

]]></content:encoded>
			<category domain="http://www.woodmann.com/forum/forumdisplay.php?f=16">The Newbie Forum</category>
			<dc:creator>fxxx</dc:creator>
			<guid isPermaLink="true">http://www.woodmann.com/forum/showthread.php?t=12033</guid>
		</item>
		<item>
			<title>Find all Commands Plugin</title>
			<link>http://www.woodmann.com/forum/showthread.php?t=12032&amp;goto=newpost</link>
			<pubDate>Fri, 29 Aug 2008 23:01:21 GMT</pubDate>
			<description><![CDATA[Hi, 
 I'm looking for a plugin that will "Find all Commands", without the "Too few Operands" you get with Olly. 
 To be able to type in any command such as "mov" and have all the mov commands show would be great! 
 Does anyone know of such a plugin or is that able to be done? 
Thanks for your help!]]></description>
			<content:encoded><![CDATA[<div>Hi,<br />
 I'm looking for a plugin that will &quot;Find all Commands&quot;, without the &quot;Too few Operands&quot; you get with Olly.<br />
 To be able to type in any command such as &quot;mov&quot; and have all the mov commands show would be great!<br />
 Does anyone know of such a plugin or is that able to be done?<br />
Thanks for your help!</div>

]]></content:encoded>
			<category domain="http://www.woodmann.com/forum/forumdisplay.php?f=16">The Newbie Forum</category>
			<dc:creator>Cougar</dc:creator>
			<guid isPermaLink="true">http://www.woodmann.com/forum/showthread.php?t=12032</guid>
		</item>
		<item>
			<title>does this tmp5.tmp install any driver</title>
			<link>http://www.woodmann.com/forum/showthread.php?t=12031&amp;goto=newpost</link>
			<pubDate>Fri, 29 Aug 2008 20:01:50 GMT</pubDate>
			<description>found this in %alluserprofile%\startup folder seems to be autorunning  
av doesnt sound any alarm  
 
creates two three files using MoveFileEx (....,...,DELAY_UNTIL_REBOOT) 
 
 
and LoadLibs this tmp_tmp# (i did not let it and just grabbed this) 
 
the original launcher is Finding DeviceIoControl...</description>
			<content:encoded><![CDATA[<div>found this in %alluserprofile%\startup folder seems to be autorunning <br />
av doesnt sound any alarm <br />
<br />
creates two three files using MoveFileEx (....,...,DELAY_UNTIL_REBOOT)<br />
<br />
<br />
and LoadLibs this tmp_tmp# (i did not let it and just grabbed this)<br />
<br />
the original launcher is Finding DeviceIoControl through GetProcAddress<br />
<br />
so if someone want to check if there is any driver involved <br />
<br />
i googled the random name of MOVEFILE (msupd123456 blah)<br />
<br />
looks like a driver is involved from google <br />
<br />
<i><u>http://support.microsoft.com/kb/894278</u></i><br />
<br />
but i couldnt locate any random driver <br />
<br />
so may be it was dormant and hadnt yet spat out its venom coz the comp in question hasnt been rebooted for some time <br />
<br />
<br />
<font color="Red">MALWARE BEWARE</font><br />
<br />
password malware</div>


	<br />
	<div style="padding:6px">

	

	

	

	
		<fieldset class="fieldset">
			<legend>Attached Files</legend>
			<table cellpadding="0" cellspacing="3" border="0">
			<tr>
	<td><img class="inlineimg" src="http://www.woodmann.com/forum/images/attach/rar.gif" alt="File Type: rar" width="16" height="16" border="0" style="vertical-align:baseline" /></td>
	<td><a href="http://www.woodmann.com/forum/attachment.php?attachmentid=1916&amp;d=1220040087">somevirus.rar</a> (36.3 KB)</td>
</tr>
			</table>
		</fieldset>
	

	</div>
]]></content:encoded>
			<category domain="http://www.woodmann.com/forum/forumdisplay.php?f=4">Malware Analysis and Unpacking Forum</category>
			<dc:creator>blabberer</dc:creator>
			<guid isPermaLink="true">http://www.woodmann.com/forum/showthread.php?t=12031</guid>
		</item>
	</channel>
</rss>
