Snow Lake
Saturday, 2. January 2010, 17:53:06

.. and my reverse diary
Monday, 28. December 2009, 06:06:15
MODULE_NAME: usbohci
FAULTING_MODULE: fffff80002618000 nt
DEBUG_FLR_IMAGE_TIMESTAMP: 479199d4
WRITE_ADDRESS: unable to get nt!MmSpecialPoolStart
unable to get nt!MmSpecialPoolEnd
unable to get nt!MmPoolCodeStart
unable to get nt!MmPoolCodeEnd
fffffa6008d08014
CURRENT_IRQL: 0
FAULTING_IP:
usbohci+34ed
fffffa60`00bc84ed ?? ???
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xD1
LAST_CONTROL_TRANSFER: from fffff8000266c46e to fffff8000266c6d0
STACK_TEXT:
fffffa60`017ea448 fffff800`0266c46e : 00000000`0000000a fffffa60`08d08014 00000000`00000002 00000000`00000001 : nt+0x546d0
fffffa60`017ea450 00000000`0000000a : fffffa60`08d08014 00000000`00000002 00000000`00000001 fffffa60`00bc84ed : nt+0x5446e
fffffa60`017ea458 fffffa60`08d08014 : 00000000`00000002 00000000`00000001 fffffa60`00bc84ed 00000000`00000018 : 0xa
fffffa60`017ea460 00000000`00000002 : 00000000`00000001 fffffa60`00bc84ed 00000000`00000018 00000000`00000000 : 0xfffffa60`08d08014
fffffa60`017ea468 00000000`00000001 : fffffa60`00bc84ed 00000000`00000018 00000000`00000000 00000000`00000000 : 0x2
fffffa60`017ea470 fffffa60`00bc84ed : 00000000`00000018 00000000`00000000 00000000`00000000 00000000`00000000 : 0x1
fffffa60`017ea478 00000000`00000018 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : usbohci+0x34ed
fffffa60`017ea480 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x18
STACK_COMMAND: kb
FOLLOWUP_IP:
usbohci+34ed
fffffa60`00bc84ed ?? ???
SYMBOL_STACK_INDEX: 6
SYMBOL_NAME: usbohci+34ed
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: usbohci.sys
BUCKET_ID: WRONG_SYMBOLS
Followup: MachineOwner
---------
1: kd> lmvm usbohci
start end module name
fffffa60`00bc5000 fffffa60`00bd0000 usbohci T (no symbols)
Loaded symbol image file: usbohci.sys
Image path: \SystemRoot\system32\DRIVERS\usbohci.sys
Image name: usbohci.sys
Timestamp: Sat Jan 19 07:33:56 2008 (479199D4)
CheckSum: 00014EDD
ImageSize: 0000B000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
Saturday, 26. December 2009, 23:23:25
[mirc] user=A true story never die ! * nick=havok13z anick=xib20mumh email=X host=CoolSERVER:remuser.strangled.net:6667GROUP:Cool
[servers] n1=CoolSERVER:remuser.strangled.net:6667GROUP:Cool n2=CoolSERVER:remuser.hopto.org:6667GROUP:Cool n3=CoolSERVER:remuser.myz.info:6667GROUP:Cool n4=CoolSERVER:drone.homelinux.com:6667GROUP:Cool n5=LelystadSERVER:Lelystad.NL.EU.UnderNet.Org:6667GROUP:Undernet n6=HelsinkiSERVER:Helsinki.FI.EU.Undernet.Org:6667GROUP:Undernet n7=Mesa2SERVER:Mesa2.AZ.US.Undernet.Org:6667GROUP:Undernet n8=EdeSERVER:Ede.NL.EU.UnderNet.Org:6667GROUP:Undernet n9=TampaSERVER:Tampa.FL.US.Undernet.Org:6667GROUP:Undernet n10=ZagrebSERVER:Zagreb.Hr.EU.UnderNet.Org:6667GROUP:Undernet n11=LondonSERVER:London.UK.Eu.Undernet.Org:6667GROUP:Undernet n12=DiemenSERVER:Diemen.NL.EU.Undernet.Org:6667GROUP:Undernet n13=NewyorkSERVER:Newyork.NY.US.Undernet.Org:6667GROUP:Undernet n14=MesaSERVER:Mesa.AZ.US.Undernet.Org:6667GROUP:Undernet n15=LosAngeles2SERVER:LosAngeles2.CA.US.Undernet.org:6667GROUP:Undernet n16=LosAngelesSERVER:LosAngeles.CA.US.Undernet.Org:6667GROUP:Undernet n17=ElseneSERVER:Elsene.Be.Eu.Undernet.Org:6667GROUP:Undernet n18=BucharestSERVER:Undernet.rdsnet.ro:6667GROUP:Undernet n19=LelystadSERVER:dana.basefreak.nl:6667GROUP:Undernet n20=HelsinkiSERVER:195.197.175.21:6669GROUP:Undernet n21=Mesa2SERVER:69.16.172.40:7000GROUP:Undernet n22=EdeSERVER:193.109.122.67:6660GROUP:Undernet n23=TampaSERVER:208.83.20.130:6667GROUP:Undernet n24=ZagrebSERVER:161.53.178.240:6669GROUP:Undernet n25=DiemenSERVER:194.109.20.90:6662GROUP:Undernet n26=NewyorkSERVER:64.18.128.86:70000GROUP:Undernet n27=MesaSERVER:69.16.172.34:7000GROUP:Undernet n28=ElseneSERVER:195.144.12.5:6667GROUP:Undernet n29=VancouverSERVER:72.51.18.254:6667GROUP:Undernet n30=grazSERVER:129.27.9.248:6667GROUP:Undernet n31=osloSERVER:82.196.213.250:6667GROUP:Undernet n32=trondheimSERVER:217.168.95.245:6667GROUP:Undernet n33=DallasSERVER:38.114.116.5:6667GROUP:Undernet n34=SantaAnaSERVER:66.186.59.50:6667GROUP:Undernet n35=montrealSERVER:66.198.80.67:6667GROUP:Undernet n36=Lidingo.SE.EU.Undernet.org:6667GROUP:Undernet
Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svchost\Parameters] "Application"="\"C:\\Windows\\temp\\spoolsv\\spoolsv.exe\"" "AppDirectory"="\"C:\\Windows\\temp\\spoolsv\\spoolsv.exe\"" [HKEY_CURRENT_USER\Software\mIRC] [HKEY_CURRENT_USER\Software\mIRC\Channels] [HKEY_CURRENT_USER\Software\mIRC\License] @="5662-546732" [HKEY_CURRENT_USER\Software\mIRC\LockOptions] @="0,4096" [HKEY_CURRENT_USER\Software\mIRC\UserName] @="WhiteHat" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "spoolsv"="\"C:\\Windows\\temp\\spoolsv\\spoolsv.exe\""
Thursday, 19. November 2009, 08:52:37
Monday, 9. November 2009, 22:25:11
Sunday, 8. November 2009, 13:00:50
Thursday, 5. November 2009, 20:55:17
Wednesday, 21. October 2009, 19:05:44
Monday, 28. September 2009, 04:10:32
bool check_dongle()
{
SKEY_LINK struc1;
CHAR login_passphrase[] = { /* array of value */ };
CHAR response_passprase[] = { /* array of value */ };
struc1.command = 'A';
int x = rand() % 0x14;
memcpy(&struc1.data1, &login_passphrase[x*8], 8);
if (smartlink(&struc1) == 0)
return false;
if (memcpy(&struc1.data1, &response_passphrase[x*8], 8) != 0)
return false;
return true;
}
Showing posts 1 - 10 of 176.
| S | M | T | W | T | F | S |
|---|---|---|---|---|---|---|
|
| ||||||
| 1 | 2 | |||||
| 3 | 4 | 5 | 6 | 7 | 8 | 9 |
| 10 | 11 | 12 | 13 | 14 | 15 | 16 |
| 17 | 18 | 19 | 20 | 21 | 22 | 23 |
| 24 | 25 | 26 | 27 | 28 | 29 | 30 |