Note. This method is reliable and task works fine! If you use other versions of Bochs, you can get some problems... Bochs 2.4.6 installation on Windows (for integration with IDA Pro 6.1): ----------------------------------------------------------------------- 1. Download Bochs 2.4.6 installer for Windows at http://bochs.sourceforge.net/ (2.4.6 is suitable for IDA Pro 6.1 integration) 2. Install it 3. Download prepared Bochs 2.4.6 image and config at http://downloads.phdays.com/phd_bochs_images.zip 4. Install Windows XP SP3 or Higher on given disk image (This is very logn process!!! We suggest you to install Windows XP!) 5. Download prepared Bochs 2.4.6 package at http://downloads.phdays.com/phd_bochs_2.4.6.zip (YOU NEED THIS PACKAGE TO SOLVE THE TASK!) 6. Replace original Bochs files with files from archive 7. Now you can open bochsrc_2.4.6.bxrc config file with IDA Pro and start debugging! Bochs 2.6 installation on Windows (for integration with IDA Pro 6.3): ----------------------------------------------------------------------- 1. Download Bochs 2.6 installer for Windows at http://bochs.sourceforge.net/ (2.6 is suitable for IDA Pro 6.3 integration) 2. Install it 3. Download prepared Bochs 2.6 image and config at http://downloads.phdays.com/phd_bochs_images.zip 4. Install Windows XP SP3 or Higher on given disk image (This is very logn process!!! We suggest you to install Windows XP!) 5. Download prepared Bochs 2.6 package at http://downloads.phdays.com/phd_bochs_2.6.zip (YOU NEED THIS PACKAGE TO SOLVE THE TASK!) 4. Replace original Bochs files with files from archive 7. Now you can open bochsrc_2.6.bxrc config file with IDA Pro and start debugging! Known issues: 1. We noticed some bugs in IDA debugger while jumping to the long mode, but Bochs built-in debugger works just fine. ;) 2. Bochs 2.4.6 is not able to boot the system after infection due to its bugs! (The task is still solvable) 3. There can be errors in OS after booting infected system. Use power off/power on instead of reset. (Sorry, we didn’t have time to fix all the bugs!)