MaxSS was not supposed to alter only partition table?
Tigzy wrote:MaxSS was not supposed to alter only partition table?Only in current version.
A forum for reverse engineering, OS internals and malware analysis
Tigzy wrote:MaxSS was not supposed to alter only partition table?Only in current version.
Tigzy wrote:Some of you got a TDL4 dump for testing purpose? I only got VMs at work, so can't infect a physical machine.Take any dropper from TDL4 dedicated thread (Alureon.DX, not Alureon.FE) and infect VM. It should work.
Tigzy wrote:A little help for decryption?What tool you are using for decryption?
I got the key (0x147 and the begin offset 0x2A).
How the ROR is done? do we shift any byte 0x47 times (don't think so) or do we take all bytes shifted 0x47 times?
Tigzy wrote:A little help for decryption?Intel® 64 and IA-32 Architectures Software Developer’s Manual Volume 1: Basic Architecture
I got the key (0x147 and the begin offset 0x2A).
How the ROR is done? do we shift any byte 0x47 times (don't think so) or do we take all bytes shifted 0x47 times?