Jump to content

schwups

Member
  • Posts

    1,203
  • Joined

  • Last visited

  • Days Won

    3
  • Donations

    0.00 USD 
  • Country

    Germany

Posts posted by schwups


  1. That could have do with low swap space or low HD space. Try to compare the swap space values with enabled and disabled Wi-Fi card, if possible.

     

    You can try to reduce MaxFileCache, e.g. 393216 or less, in the system.ini. Or you can reduce phys memory (RAM), e.g. MaxPhysPage to 10000 (256MB), in the system.ini. 

    example:

    [386Enh]

    ...

    MaxPhysPage=10000

    or

    [vcache]
    MaxFileCache=393216

    or

    [vcache]
    MaxFileCache=
    65536

    It takes effect after restart.
     

  2. 2 hours ago, MiKl said:

    With which app(s) did you test advpack.dll ?

     I didn't test very specific. The OS and all progams like OpenOffice, VLC, Notepad, Notepad++, Opera, Firefox, 7Zip, Foxit Reader, XnView, Faststone, .... show normal behaviour and don't crash so far. 
     

    1 hour ago, MiKl said:

    If it is not an ego-thing I would like to ask you to setup my config, test it and go one from there.

    Do you mean your dll list? My system will never correspond exactly to yours. On the one hand I have ME. There are hell of a lot variables.

  3. Apparently these ROS 0.4.0 files don't harm my systems (ME, KernelEX 4.5.2015.11/12):

    Replaced: ADVPACK.DLL

    Added:

    ATL100.dll

    AUTHHZ.dll

    SAMLIB.dll

    HAL.dll

    Following files are bad:

    ADVAPI32.dll: system unusable

    OLE32.dll: system unusable

    Oleaut32.dll: system unusable

    ----

    OpenGL32.dll: OpenGL doesn't work. "[NTDLL.DLL]vDbgPrintExWithPrefix" could be a problem. Although supported by kexbases (v11) apparently with a stub.? Also shown by the ImportPatcher:

    [gdi32.dll]
    GdiDescribePixelFormat=
    GdiSetPixelFormat=
    GdiSwapBuffers=

    I'll test more files soon.

  4. K Meleon 1.6.0 beta2 or 1.7 alpha run with KernelEX (comp. mode Win2000). Newer versions don't. Maybe someone has found a workaround for newer versions.

    Opera 12.02 runs with KernelEX. Newer versions don't. I've spent a lot of time to find a workaround to run newer versions of Opera without success! I'm able to run Opera 12.5 build 1538, but without working plugins.

  5. Kexbasen.11 revealed an initialization loop vulnerability in the KernelEx 4.5 architecture. I plan to address it more completely in "Kex16."

    For now, the Kernel32 fixes in Kexbasen for TlsAlloc, TlsFree, TlsGetValue, TlsSetValue have been rewritten to be better, faster, and (most importantly) not need preinitialization. Along with restoring the delay-load linker options, Kexbasen should now be stable again with current SE and ME configurations.

    Use Kexbasen.12 with KernelEx.11 and Kexbases.11.

    Many thanks to everyone for their feedback and patience while I worked through this challenging puzzle.

    No problems so far anymore and I'm happy to see Opera with Win2000 mode runs again. Did you work on my problem with Opera?

     

    In any case from me also big thanks!

  6. DumpPE is a 32-bit console app. Run it in a DOS box, or from a batch file such as:

    DumpPE-disasm.bat

    @echo off%0\..\DumpPE -disasm %1 > %1.asmcls
    I have a shortcut (renamed simply "DumpPE -disasm") to this batch file in my SendTo folder.

    Last version of DumpPE is 2.32. I'll add a Wayback link to it in Post #1.

     

    OK, thanks it works:

     

    BFF64198 fn_BFF64198: ; Xref BFF627E2 BFF628C0 BFF6296D BFF62A6B

    BFF64198 A1F8BCFBBF mov eax,[0BFFBBCF8h]

    BFF6419D 8B00 mov eax,[eax]

    BFF6419F FF401C inc dword ptr [eax+1Ch]

    BFF641A2 FF4A10 dec dword ptr [edx+10h]

    BFF641A5 7508 jnz loc_BFF641AF

    BFF641A7 894208 mov [edx+8],eax

     

     

    And how do I make the next step to QT_Thunk and FT_ Thunk?

     

    BTW according to the txt file of DumpPE you added

     

    Last version of DumpPE is 2.32. I'll add a Wayback link to it in Post #1.

     version 2.20.

  7. I don't have ME, so you need to tell us what Kernel32 API "0177:bff641a2" is in. "DumpPE -disasm Kernel32.dll" will help. If the code doesn't appear to be in an exported function, check the call stack for an address that is.

    In SE, bff741a2 is in the function:

    BFF74176                    fn_BFF74176:                ; Xref BFF7C9C9 BFF87CFC
    So I would check the call stack for addresses about five (the length of a typical call instruction) higher: BFF7C9CE, BFF87D01. Keep doing the same until you find an exported API.

     

    I had downloaded DumpPE 2.20 from softpedia yesterday. I am not familiar with it. It works, but the box closes or crashes immediately after writing the last line. Is there somewhere a text or log output?

  8. I can't reach the desktop:

     

    latest Kexbasen.dll Release 11

    KernelEx.dll  Release 8

    Kexbases.dll  Release 8

     

     

     

     

    Yesterday I wrote

     

    I get three errors Rundll32 in Kernel32.dll on start.

    SorryI would better have put on my glasses!:

     

    My Faultlog was:

     

    Datum 01/01/2016 Uhrzeit 20:04

    RUNDLL32 verursachte einen Fehler durch eine ungültige Seite

    in Modul KERNEL32.DLL bei 0177:bff641a2.

    Register:

    EAX=c1a17930 CS=0177 EIP=bff641a2 EFLGS=00010202

    EBX=82528948 SS=017f ESP=0063faf8 EBP=0063fb24

    ECX=7d00b90d DS=017f ESI=00000a28 FS=2a87

    EDX=00000000 ES=017f EDI=00000094 GS=0000

    Bytes bei CS:EIP:

    ff 4a 10 75 08 89 42 08 ff 42 04 90 c3 39 42 08

    Stapelwerte:

    7d00b90d 00000094 00000a28 82528948 7c039760 ffffffff 7c00249e 7c002465 00000000 00000fa0 825286c0 0063fbcc 7c002e15 7c002cb5 00000094 00000005

    **********************************************************************

    Datum 01/01/2016 Uhrzeit 20:04

    RUNONCE verursachte einen Fehler durch eine ungültige Seite

    in Modul KERNEL32.DLL bei 0177:bff641a2.

    Register:

    EAX=c1a25230 CS=0177 EIP=bff641a2 EFLGS=00010202

    EBX=8253cca4 SS=017f ESP=0063faf8 EBP=0063fb24

    ECX=7d00b90d DS=017f ESI=00008bb8 FS=19d7

    EDX=00000000 ES=017f EDI=00000094 GS=0000

    Bytes bei CS:EIP:

    ff 4a 10 75 08 89 42 08 ff 42 04 90 c3 39 42 08

    Stapelwerte:

    7d00b90d 00000094 00008bb8 8253cca4 7c039760 ffffffff 7c00249e 7c002465 00000000 00000fa0 8253ca20 0063fbcc 7c002e15 7c002cb5 00000094 00000004

    **********************************************************************

    Datum 01/01/2016 Uhrzeit 20:04

    EXPLORER verursachte einen Fehler durch eine ungültige Seite

    in Modul KERNEL32.DLL bei 0177:bff641a2.

    Register:

    EAX=c1a0b930 CS=0177 EIP=bff641a2 EFLGS=00010202

    EBX=8252dc78 SS=017f ESP=005afaf8 EBP=005afb24

    ECX=7d00b90d DS=017f ESI=00008bb8 FS=19d7

    EDX=00000000 ES=017f EDI=00000094 GS=0000

    Bytes bei CS:EIP:

    ff 4a 10 75 08 89 42 08 ff 42 04 90 c3 39 42 08

    Stapelwerte:

    7d00b90d 00000094 00008bb8 8252dc78 7c039760 ffffffff 7c00249e 7c002465 00000000 00000fa0 825286c0 005afbcc 7c002e15 7c002cb5 00000094 00000004

×
×
  • Create New...