Академический Документы
Профессиональный Документы
Культура Документы
The Essay
Obtains the handle to the desktop associated to the executable itself and opens
the handle of an existing event called CZXSDERDAKSIICS_MX, if event exists its
own handle is closed, else a new event (called CZXSDERDAKSIICS_MX9 is created
with Standard SecurityAttributes.
The code here is clear, after enstablishing the System Directory, searches for a
Resource type "MNDLL" and next loads it, the LoadResource give us an intersing
location 00402070, that's an executable image, exploring this executable we can
see some intersing strings http://www.poptang.com/ekey Bind, ConfigAreaName
game.ini, SOFTWARE\Wizet\MapleStory
Regards,
Giuseppe 'Evilcry' Bonfa'