![]() |
Armadillo IAT Rebuild
Hi!
Please give me some help with this one: www.chemsw.com/12149.htm You can simply download it with this link: http://tinyurl.com/epzx8 Thanks to hosi... Armadillo target with Debug Blocker which I already unpacked. I'm really lost with IAT rebuild. Mephistos Armadillo tut didn't work nor other tuts. I tried the Scripts also but there is no call to strcmp or any msvcrt.dll function. As DilloDie doesn't work for this I think it should be Armadillo v3 but as the other stuff is very different and not working maybe its another version. For you guys who really want to help: OEP: 425A01 IAT: 44D000 I can post the dumped file if needed! Please note that I don't need a crack for this just the unpacked working file since I need to extract a file format. I'd be really glad for instructions or even the unpacked working file. Thanks for help! |
2 Attachment(s)
This is an old version of Armadillo with debug blocker protection.
After reaching OEP by famous CreateThread method, put hardware bp on one of its imports found by ImpRec. You'll stop here : Code:
00E22266 8B85 74FCFFFF MOV EAX,DWORD PTR SS:[EBP-38C]Code:
00E22200 E8 EB2B0000 CALL 00E24DF0Code:
00E14B58 55 PUSH EBP |
Thanks very much for your help!
I already played in the call you mentioned but couldn't find the magic jmp. After I now again dumped and fixed the imports I get a 1 Mb exe while yours is smaller. Also mine doesn't run. So what did you do to it to make it smaller and runable? |
Make sure you dumped it correctly. Don't use dumper plugins of OllyDbg. Both of them (OllyDump & Olly PE Dumpder) have problem with Armadillo. Try other dumpders like Lord PE & PE Tools.
Make sure you fixed all imports. I said patch JE to JMP, but you should put hardware bp on that CALL and run it again. ;) To make it smaller, wipe 3 sections before .rsrc which are Armadillo codes or use on of them for import addresses and wipe 2 of them. |
and why is that? i dump with ollydump and no problem, only before dump i paste pe header from original exe.
|
Quote:
|
its not bug! just arma destroys header, and in lordpe by default you have paste header from disk
|
You're right in case of OllyDump.
Olly PE Dumpder has the option of paste header from disk, but there's still some problems. |
Request
Could you please put the installer of this target on Rapidshre link?
Thanks in advance |
| All times are GMT +8. The time now is 18:16. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX