Ok , vado avanti da solo(almeno ci provo).
Stando a quanto detto da Evolution il prog. chiama per le finestre di inserimento password e la messagebox di password errata le api di windows standard.
Queste sono le imports ed exports table ricopiate da IDA PRO , mi potreste indicare quali sono quelle incriminate?
Grazie.
imports
0040F000 17 InitCommonControls COMCTL32
0040F008 GetCurrentDirectoryA KERNEL32
0040F00C SetFilePointer KERNEL32
0040F010 GetTempPathA KERNEL32
0040F014 GetProcAddress KERNEL32
0040F018 LoadLibraryExA KERNEL32
0040F01C GetModuleHandleA KERNEL32
0040F020 GetExitCodeProcess KERNEL32
0040F024 WaitForSingleObject KERNEL32
0040F028 CreateProcessA KERNEL32
0040F02C GetCommandLineA KERNEL32
0040F030 GetStartupInfoA KERNEL32
0040F034 GetModuleFileNameA KERNEL32
0040F038 GetFullPathNameA KERNEL32
0040F03C RemoveDirectoryA KERNEL32
0040F040 HeapAlloc KERNEL32
0040F044 HeapFree KERNEL32
0040F048 GetLastError KERNEL32
0040F04C DeleteFileA KERNEL32
0040F050 FindClose KERNEL32
0040F054 FileTimeToSystemTime KERNEL32
0040F058 FileTimeToLocalFileTime KERNEL32
0040F05C FindFirstFileA KERNEL32
0040F060 FindNextFileA KERNEL32
0040F064 MultiByteToWideChar KERNEL32
0040F068 SetStdHandle KERNEL32
0040F06C GetFileType KERNEL32
0040F070 SetConsoleCtrlHandler KERNEL32
0040F074 ExitProcess KERNEL32
0040F078 TerminateProcess KERNEL32
0040F07C GetCurrentProcess KERNEL32
0040F080 GetVersionExA KERNEL32
0040F084 HeapDestroy KERNEL32
0040F088 HeapCreate KERNEL32
0040F08C VirtualFree KERNEL32
0040F090 VirtualAlloc KERNEL32
0040F094 HeapReAlloc KERNEL32
0040F098 ReadFile KERNEL32
0040F09C SetHandleCount KERNEL32
0040F0A0 GetStdHandle KERNEL32
0040F0A4 CloseHandle KERNEL32
0040F0A8 WriteFile KERNEL32
0040F0AC SetEnvironmentVariableA KERNEL32
0040F0B0 WideCharToMultiByte KERNEL32
0040F0B4 SetEnvironmentVariableW KERNEL32
0040F0B8 UnhandledExceptionFilter KERNEL32
0040F0BC FreeEnvironmentStringsA KERNEL32
0040F0C0 GetEnvironmentStrings KERNEL32
0040F0C4 FreeEnvironmentStringsW KERNEL32
0040F0C8 GetEnvironmentStringsW KERNEL32
0040F0CC FlushFileBuffers KERNEL32
0040F0D0 CreateFileA KERNEL32
0040F0D4 GetTimeZoneInformation KERNEL32
0040F0D8 QueryPerformanceCounter KERNEL32
0040F0DC GetTickCount KERNEL32
0040F0E0 GetCurrentThreadId KERNEL32
0040F0E4 GetCurrentProcessId KERNEL32
0040F0E8 GetSystemTimeAsFileTime KERNEL32
0040F0EC CompareStringA KERNEL32
0040F0F0 GetCPInfo KERNEL32
0040F0F4 CompareStringW KERNEL32
0040F0F8 GetACP KERNEL32
0040F0FC GetOEMCP KERNEL32
0040F100 HeapSize KERNEL32
0040F104 LoadLibraryA KERNEL32
0040F108 RtlUnwind KERNEL32
0040F10C InterlockedExchange KERNEL32
0040F110 VirtualQuery KERNEL32
0040F114 SetEndOfFile KERNEL32
0040F118 GetLocaleInfoA KERNEL32
0040F11C VirtualProtect KERNEL32
0040F120 GetSystemInfo KERNEL32
0040F124 LCMapStringA KERNEL32
0040F128 LCMapStringW KERNEL32
0040F12C GetStringTypeA KERNEL32
0040F130 GetStringTypeW KERNEL32
0040F134 CreateDirectoryA KERNEL32
0040F138 GetDriveTypeA KERNEL32
0040F140 MessageBoxA USER32
0040F148 14 __imp_ntohl WS2_32
exports
start 0040711E
- - - Updated - - -
Evolution dove sei ????????
- - - Updated - - -
Predator pls.......