I never messed with YACoin, but I am going to put it through a debugger and dissembler when I get back from eating breakfast. Good day.
I've checked it with Ollydbg IDA HTTPAnalyzer etc. There is no strings like "
http://xxxxx/xxx.php", no sockets connect there, and the exe is not packed or crypted,
file access log is here:
753A2D20 COND: 02F18E54 "C:\Users\MAR\AppData\Roaming\YaCoin\yacoin.conf"
753A2D20 COND: 03DFE44C "C:\Users\MAR\AppData\Roaming\YaCoin\.lock"
753A2D20 COND: 03DFE4AC "C:\Users\MAR\AppData\Roaming\YaCoin\.lock"
753A2D20 COND: 03DF852C "C:\Users\MAR\AppData\Roaming\YaCoin\debug.log"
753A2D20 COND: 03DF8594 "C:\Users\MAR\AppData\Roaming\YaCoin\debug.log"
753A2D20 COND: 03DFE56C "C:\Users\MAR\AppData\Roaming\YaCoin\db.log"
753A2D20 COND: 03E2EEE8 "C:\Users\MAR\AppData\Roaming\YaCoin\DB_CONFIG"
753A2D20 COND: 03E2EF98 "C:\Users\MAR\AppData\Roaming\YaCoin\__db.001"
753A2D20 COND: 03D71548 "C:\Users\MAR\AppData\Roaming\YaCoin\database\log.0000000006"
753A2D20 COND: 03D715D0 "C:\Users\MAR\AppData\Roaming\YaCoin\database\log.0000000006"
753A2D20 COND: 0469CA00 "C:\Users\MAR\AppData\Roaming\YaCoin\database\log.0000000006"
753A2D20 COND: 0469CB10 "C:\Users\MAR\AppData\Roaming\YaCoin\database\log.0000000006"
753A2D20 COND: 0469CB98 "C:\Users\MAR\AppData\Roaming\YaCoin\database\log.0000000005"
753A2D20 COND: 0469CC20 "C:\Users\MAR\AppData\Roaming\YaCoin\database\log.0000000004"
753A2D20 COND: 0469CCA8 "C:\Users\MAR\AppData\Roaming\YaCoin\database\log.0000000003"
753A2D20 COND: 0469CD30 "C:\Users\MAR\AppData\Roaming\YaCoin\database\log.0000000002"
753A2D20 COND: 0469CDB8 "C:\Users\MAR\AppData\Roaming\YaCoin\database\log.0000000001"
753A2D20 COND: 0469CE40 "C:\Users\MAR\AppData\Roaming\YaCoin\database\log.0000000001"
753A2D20 COND: 0469CEC8 "C:\Users\MAR\AppData\Roaming\YaCoin\database\log.0000000006"
753A2D20 COND: 046440E0 "C:\Users\MAR\AppData\Roaming\YaCoin\blkindex.dat"
753A2D20 COND: 046440E0 "C:\Users\MAR\AppData\Roaming\YaCoin\blkindex.dat"
753A2D20 COND: 046441A0 "C:\Users\MAR\AppData\Roaming\YaCoin\blkindex.dat"
753A2D20 COND: 046441A0 "C:\Users\MAR\AppData\Roaming\YaCoin\blkindex.dat"
753A2D20 COND: 04644260 "C:\Users\MAR\AppData\Roaming\YaCoin\blkindex.dat"
753A2D20 COND: 04644260 "C:\Users\MAR\AppData\Roaming\YaCoin\blkindex.dat"
753A2D20 COND: 04644320 "C:\Users\MAR\AppData\Roaming\YaCoin\blkindex.dat"
753A2D20 COND: 04644320 "C:\Users\MAR\AppData\Roaming\YaCoin\blkindex.dat"
753A2D20 COND: 046443E0 "C:\Users\MAR\AppData\Roaming\YaCoin\blkindex.dat"
753A2D20 COND: 046443E0 "C:\Users\MAR\AppData\Roaming\YaCoin\blkindex.dat"
753A2D20 COND: 0469CFD8 "C:\Users\MAR\AppData\Roaming\YaCoin\database\log.0000000006"
753A2D20 COND: 0469CFD8 "C:\Users\MAR\AppData\Roaming\YaCoin\database\log.0000000006"
753A2D20 COND: 0469D060 "C:\Users\MAR\AppData\Roaming\YaCoin\database\log.0000000007"
753A2D20 COND: 0469D0E8 "C:\Users\MAR\AppData\Roaming\YaCoin\database\log.00007"
753A2D20 COND: 0469D170 "C:\Users\MAR\AppData\Roaming\YaCoin\database\log.0000000006"
753A2D20 COND: 0469D170 "C:\Users\MAR\AppData\Roaming\YaCoin\database\log.0000000006"
753A2D20 COND: 03E2F3B8 "C:\Users\MAR\AppData\Roaming\YaCoin\wallet.dat"
753A2D20 COND: 03E2F468 "C:\Users\MAR\AppData\Roaming\YaCoin\wallet.dat"
753A2D20 COND: 03E2F518 "C:\Users\MAR\AppData\Roaming\YaCoin\wallet.dat"
753A2D20 COND: 03E2F5C8 "C:\Users\MAR\AppData\Roaming\YaCoin\wallet.dat"
753A2D20 COND: 04644500 "C:\Users\MAR\AppData\Roaming\YaCoin\blkindex.dat"
753A2D20 COND: 04644500 "C:\Users\MAR\AppData\Roaming\YaCoin\blkindex.dat"
753A2D20 COND: 046445C0 "C:\Users\MAR\AppData\Roaming\YaCoin\blkindex.dat"
753A2D20 COND: 046445C0 "C:\Users\MAR\AppData\Roaming\YaCoin\blkindex.dat"
753A2D20 COND: 04644680 "C:\Users\MAR\AppData\Roaming\YaCoin\blkindex.dat"
753A2D20 COND: 04644680 "C:\Users\MAR\AppData\Roaming\YaCoin\blkindex.dat"
753A2D20 COND: 046BE5FC "C:\Users\MAR\AppData\Roaming\YaCoin\blk0001.dat"
753A2D20 COND: 046BDE44 "C:\Users\MAR\AppData\Roaming\YaCoin\blk0001.dat"
753A2D20 COND: 046BE79C "C:\Users\MAR\AppData\Roaming\YaCoin\blk0001.dat"
753A2D20 COND: 046BEC14 "C:\Users\MAR\AppData\Roaming\YaCoin\blk0001.dat"
753A2D20 COND: 046BF08C "C:\Users\MAR\AppData\Roaming\YaCoin\blk0001.dat"
753A2D20 COND: 046BF504 "C:\Users\MAR\AppData\Roaming\YaCoin\blk0001.dat"
753A2D20 COND: 046BF97C "C:\Users\MAR\AppData\Roaming\YaCoin\blk0001.dat"
753A2D20 COND: 046BFDF4 "C:\Users\MAR\AppData\Roaming\YaCoin\blk0001.dat"
.............................
...............................
Can someone send me a self compiled yacoin client ? (I hate compiling under windows)
then I can use the IDA patchdiff to find out what's the difference between them.