On Thu, Jul 12, 2012 at 12:09 PM, phocean <0...@phocean.net> wrote: > Could you elaborate please? > What that I haven't done yet? If we agree there is nothing in the RAM dump, > how can we explain the artefacts? > > Musntlive, I never trust any antivirus. > > --- phocean
0x00: MusntLive will always help you. .effmach x86 (or is whatever is your machine amd64, ia64) is your first friend. When you is run this, you come back and let MusntLive know. For then we must use !dml_proc and only is real hacker debug stuff. No script kid stuff. Only for when you is know WinDBG like is back of your hand is you Windows hacker. Not is Immunity or is Olly, this is these are for is how you say rookie. Now you is go dump with is effmach. Then is we can study this is yes with HB Gary memory tools. Because is HB Gary, if we know is find it, HB Gary is will find with is their backdoor into is their tools. We not worry, we find evil 1337 together. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/