Author Topic: W32Dasm 8.93 fixed by MaRKuS TH-DJM  (Read 576 times)

DARKER

  • [SCF]
  • Administrator
  • Senior Member
  • *****
  • Posts: 336
W32Dasm 8.93 fixed by MaRKuS TH-DJM
« on: October 04, 2006, 12:53:34 PM »
Starucky W32Dasm modifikovany s brat's patchom + nejaky fix od MaRKuS TH-DJM:

- 100% CPU-usage for string-window
- Exports are shown again in bratpatch 3
- path-bug (W32Dasm didn't load exe's with long path)
- while patching, you can still use W32Dasm

(je to stary release ale este som ho tu nevidel)

eraser

  • repe cmpsb
  • Senior Member
  • ****
  • Posts: 268
  • Kill malware!
Re: W32Dasm 8.93 fixed by MaRKuS TH-DJM
« Reply #1 on: January 17, 2007, 02:09:05 PM »
Taká lame otázka... čo sa presne myslí pod 100% CPU-usage for string-window? Je to aplikované iba na Strn Ref okno, či celú aplikáciu? Preto?e mi to plné zaťa?enie CPU lezie na nervy.
th3 r341 f4!1ur3 !5 wh3n y0u d0n't 134rn 4nyth!n6 fr0m 4ny 6!v3n 5!tu4t!0n
the real failure is when you don't learn anything from any given situation

Master

  • [t4C]newbie child
  • VIP
  • *****
  • Posts: 615
Re: W32Dasm 8.93 fixed by MaRKuS TH-DJM
« Reply #2 on: January 17, 2007, 02:17:52 PM »
W32 dasm se uz nepouziva.Nebo velmi malo mozna na nejaky stringy.Jinak OllyDbg rule

eraser

  • repe cmpsb
  • Senior Member
  • ****
  • Posts: 268
  • Kill malware!
Re: W32Dasm 8.93 fixed by MaRKuS TH-DJM
« Reply #3 on: January 17, 2007, 03:08:11 PM »
Dá sa cez OllyDbg vyhotoviť dissasemble reprezentácia a vyexportovať cez spustenia nejakej aplikácie?

Tento nástroj som pou?íval, ale len na krokovanie a hlavne na zistenie volaných parametrov, preklad kon?tánt je nádhera.
th3 r341 f4!1ur3 !5 wh3n y0u d0n't 134rn 4nyth!n6 fr0m 4ny 6!v3n 5!tu4t!0n
the real failure is when you don't learn anything from any given situation

Master

  • [t4C]newbie child
  • VIP
  • *****
  • Posts: 615
Re: W32Dasm 8.93 fixed by MaRKuS TH-DJM
« Reply #4 on: January 17, 2007, 07:57:30 PM »
Nevim presne,co mas na mysli.Jestli jako export zdiassemblovaneho kodu nebo co?

Jiank fakt prejdi na ollyho

llAmElliK

  • [TiME4CRiME]
  • Administrator
  • VIP
  • *****
  • Posts: 960
Re: W32Dasm 8.93 fixed by MaRKuS TH-DJM
« Reply #5 on: January 17, 2007, 08:04:17 PM »
Ono i dnes neni dle meho nazoru adekvatni nahrada za W32 - existuje hodne nahrad (casto i prijemnejsiho vzhledu ,nez W32) ,ale W32 je klasika a navic jeho preklad je velmi presny (coz se odrazi v rychlosti zpracovani ,ktera mne nekdy depta)
Cili k statickemu vypisu W32  pouziva (a objevuje) stale dost lidi, pokud nechteji sahnout k IDA.
TiME AND CRiME ARE ETERNAL-REVERSE ENGINEERiNG iS MODERN PHiLOSOPHY AND iSN'T CRiME
[TiME4CRiME]

eraser

  • repe cmpsb
  • Senior Member
  • ****
  • Posts: 268
  • Kill malware!
Re: W32Dasm 8.93 fixed by MaRKuS TH-DJM
« Reply #6 on: January 17, 2007, 08:06:28 PM »
U? na tom pracujem...

Inak myslel som rovnaký spôsob, aký ma W32dasm, resp. výpis vidím i v OllyDbg, no nemô?em si na neho zvyknúť a e?te sa v ňom neviem dobre pohybovať. Napr. vo W32dasm som pou?íval CALL, JMP a returny, ďalej som videl adresy, odkiaľ sa skákalo, pričom pravoklik na danú adresu ma na dostal na ono miesto.
th3 r341 f4!1ur3 !5 wh3n y0u d0n't 134rn 4nyth!n6 fr0m 4ny 6!v3n 5!tu4t!0n
the real failure is when you don't learn anything from any given situation