Unpacking - Tsunami MPEG DVD Author PRO
Hi,
Target: Tsunami MPEG DVD Author PRO 2.1.5.77 hxxp://download1.pegasys-inc.com/download_files/TDAP-retail-2.1.5.77-en.exe This tool is coded in delphi and seems to be protected by some custom packer, Sections: CODE DATA BSS .idata .tls .rdata .reloc .rsrc PEGASYS0 PEGASYS1 PEGASYS2 011AF000 - 011B090B (PEGASYS2) Some Unpacking routines, no anti-debugging 011A1001 (PEGASYS0) Here i begin to loose track, IDA gets fooled and OllyDbg cant analyse it Code:
011A1001 90 NOP but i cant spot the OEP :( Can anyone help me please :o Greetz, Cobi |
Hello:
Have you tried dumping to a file after launching it, when all is unpacked in memory? And what about the rebuilding of import table? Did you manage this? For instance, using Import Reconstructor... Just some ideas... :) Cheers :cool: Nacho_dj |
dvdauthorpro.exe
This is Delphi 6/7 app but i cannot run this app since i don't have SSE instruction compatible procesor (single process , can be dumped from memory ) You see PUSHAD at EP (like UPX ...) ? oep: 9f3628 (no stolen bytes) Dotfix Fakesigner maybe |
Quote:
Isn't there any fix for that issue? it is astonishing... Cheers :cool: Nacho_dj |
no stolen bytes IAT not scrambled ,packer is somethink like modified aspack ... in olly bp on code section then cca 3x retn, then is IAT rebuilded and jmp to OEP ... but dump doesnt run some fixes needed
I forget you must remove analysist if you want to see some code |
hmm, ok thx, great :)
Little OEP Script for Olly: Code:
bp 011B090B maybe some anti-dumping? |
Have you tried standard stack hr bpx? you can then obtain OEP.
If it is a standard packer (upx, asp, etc.) just bpx in IAT, take notice of instruction writing at IAT, rerun and brak at it. Then dump (original IAT will be kept), fix with found OEP, alter IAT pointers with LordPE to point the unscrewed/virgin IAT et voil¨¤ (ImpREC might help you locating real IAT size, I think). Regards, Maximus (btw I found NOP+PUSHAD+CALL in some AsPack EP version) |
Quote:
|
@Nacho_dj
lack of "procesor with SSE instruction built-in support" has nothing to do with Delphi appz |
All times are GMT +8. The time now is 17:26. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX