View Single Post
  #11  
Old 08-16-2002, 16:28
Kalisto
 
Posts: n/a
OEP is 1006420 found with olly dbg. You know how to find OEP so this is not problem. You see line 0100644F. This is first import. Put 1160 (RVA) in imprec and 100 as size. Press get imports.
You see mscvrt.dll ... comdlg32.dll. Rest is junk. You must find kernel and other missing imports. Just put 1000 as RVA and all imports are here. Reduce size to 2F0 to get rid of junk and thats all. Fix dump with add new section, change OEP with LordPE to 6420 and run it. It should work.

01006420 . 55 PUSH EBP
01006421 . 8BEC MOV EBP,ESP
01006423 . 6A FF PUSH -1
01006425 . 68 88180001 PUSH NOTEPAD.01001888
0100642A . 68 D0650001 PUSH NOTEPAD.010065D0 ; JMP to msvcrt._except_handler3
0100642F . 64:A1 00000000 MOV EAX,DWORD PTR FS:[0]
01006435 . 50 PUSH EAX
01006436 . 64:8925 000000>MOV DWORD PTR FS:[0],ESP
0100643D . 83C4 98 ADD ESP,-68
01006440 . 53 PUSH EBX
01006441 . 56 PUSH ESI
01006442 . 57 PUSH EDI
01006443 . 8965 E8 MOV DWORD PTR SS:[EBP-18],ESP
01006446 . C745 FC 000000>MOV DWORD PTR SS:[EBP-4],0
0100644D . 6A 02 PUSH 2
0100644F . FF15 60110001 CALL NEAR DWORD PTR DS:[1001160] ; msvcrt.__set_app_type
01006455 . 83C4 04 ADD ESP,4
01006458 . C705 38990001 >MOV DWORD PTR DS:[1009938],-1

Reply With Quote