Supremo Phantom wrote:correct me if I am wrong here, but the offset value is:
00DFDDA0
m not so sure but at least on my computer the offset is 0xDFDDAF, yours points me 15 bytes before the activation jump that we need/want to change...
- Code: Select all
333FE9A6 |. E8 24F5FFFF CALL MSO.333FDECF ; <- 0xDFDDA0
333FE9AB |. 8BF0 MOV ESI,EAX
333FE9AD |. 85F6 TEST ESI,ESI
333FE9AF |. 75 48 JNZ SHORT MSO.333FE9F9 ; <- 0xDFDDAF
333FE9B1 |. 3945 08 CMP DWORD PTR SS:[EBP+8],EAX
Not-Patched/Original DLL Checksums...
MD5: 5ade3c7cbab4be62e9c2cbc4426154ac
SHA1: 8874ccbf32cc106ff52526c720ef9fa9c13f751c
SHA256: 1b8cf1e93236143f1511664f2343ebca7fe5a544adfac07ffd0322a9e62a30bc
VirusTotal Analysis
Supremo Phantom wrote:and i haven't seen maorosh's release yet. where is it?
Actually i was wrong (i was reading 03-07-10 from his post as date rather than supported versions xD) seems that maorosh haven't been here for a while.
Best Regards



