View Single Post
Old 27 September 2012, 23:23   #18
Galahad/FLT
Going nowhere
 
Galahad/FLT's Avatar
 
Join Date: Oct 2001
Location: United Kingdom
Age: 50
Posts: 9,014
Quote:
Originally Posted by Sektor 83 View Post
Having a look at Chase HQ now, I started with the boot and I've found myself somewhere in the region of $11a0/$11ac (before that it just looks like garbage). It seems to be littered with PEA's and Illegal opcodes (which I understand are two traits of a Copylock from what I've read on these boards over time). I'm kinda assuming I'm in the right place and it's just a case of stepping through these instructions and finding out what is passed to the registers, when and why?
I'll give you a small clue, which only works on the easier type Copylocks.

You've found the Copylock header, why not just keep scrolling through it and see if you find anything interesting.

I mean, if a Copylock has a header, it must surely have an end?
Galahad/FLT is offline  
 
Page generated in 0.04257 seconds with 11 queries