Veii
Veteran
- Mitglied seit
- Okt 24, 2021
- Beiträge
- 184
- Bewertungspunkte
- 212
- Punkte
- 43
This byte was and i believe is the checksum for the first image ("legacy"). The "0x55 0xAA" included, i think the next byte is the length of the image (byte value) * 0x200.
Top is free
Signature sits mid Legacy GOP ~ but AMD renames its version
Maybe it has a connection, GOP version going to sig, but its not breaking so far
And didn't seem to make a difference
Size of top part * 0x200 ? or ?
Sorry, i don't understand
But you can be right on the date/timestamp
I track them, but non of CS does fall into anything other/changed
Maybe in the top its something
Signature itself also looks to have no cross references, but it looks like it ends before
Well i definitely miss the ATOMTable aware layout. Just assembly misses instructions
Problem for me,
Sig is fully random - it has no logic attached, no familiar bytes. That's annoying because i can not make one
Also nothing directly calls to it - so i can not trace it back and "remove generation" yet. No fingerprints found yet.
Zuletzt bearbeitet
: