Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 08-10-2004, 10:28
DrPete
 
Posts: n/a
PEiD & W32DSM Questions

Ok, heres another newbie ? I have searched google and the PEiD forums for this one.

I have used PEiD to check a program, it only shows its coded using Visual C++ 6.0. So I assume no protection.

So when I open up program in WDSM and try to find a certain script it shows no scripts.

Just trying to find a certain point in the program where it gives me a certain script message and debug from there.

Some direction on this subject please.

Thanks,
Dr Pete
Reply With Quote
  #2  
Old 08-10-2004, 13:17
maca
 
Posts: n/a
assuming that program is not protected by only PeID checking is quite naive, there are too many possibilites not covered by it.

for example script messages can be encrypted

1. try to search your strings using hex editor. also, browsing file with hex editor can tell you whether the file is encrypted or packed (packed and unpacked bytestreams look different)
2. try to search them in unicode translation.
3. look in the resources String section.

and stop looking for "unpacker for visual c" there is no such thing
Reply With Quote
  #3  
Old 08-10-2004, 14:03
LaDidi LaDidi is offline
VIP
 
Join Date: Aug 2004
Posts: 222
Rept. Given: 2
Rept. Rcvd 11 Times in 10 Posts
Thanks Given: 64
Thanks Rcvd at 54 Times in 29 Posts
LaDidi Reputation: 11
Some help... maybe

What your proggy do BEFORE what you are seeking for (ie FileMon, Regmon) ?
Read the registry ? May be do a search in imports like RegOpenKey, RegQueryValueEx ?
Read a ini file ? GetPrivateProfileString, ....
Have you any string in W32DAsm ?
Best regards

May you give the name of the proggy ?
Reply With Quote
  #4  
Old 08-10-2004, 14:52
DrPete
 
Posts: n/a
LaDidi, The program is a demo which has every feature enabled except 1, which I am sure is just disabled.
The script Iam looking for is when I press this feature button and gives me the message not enabled in demo.
I have used hexworkshop, wdsm and ollydbg to find this script to no avail.

Quote:
Originally Posted by maca
assuming that program is not protected by only PeID checking is quite naive, there are too many possibilites not covered by it.

for example script messages can be encrypted
Any suggestions on what else to try? P.S. Edit your post to reply maca.
Looking into different unpackers for Visual C++ V 6.0.

Quote:
Originally Posted by 2late
If the answer is yes, indeed, Wdasm tends to give rather poor result with later C++ versions. I'd suggest try the app with Bengaly's PVDasm - I found it to be much better to locate and show strings. That's what are you after, seems to me.

Cheers
Will check this out 2late, Good suggestion, not really sure to answer (script or string) Just know its the error box I get after I try and enable the particular function.

Thanks for the help!
Dr Pete

Last edited by DrPete; 08-10-2004 at 14:59.
Reply With Quote
  #5  
Old 08-10-2004, 14:53
2late 2late is offline
Friend
 
Join Date: Nov 2003
Posts: 50
Rept. Given: 5
Rept. Rcvd 6 Times in 3 Posts
Thanks Given: 17
Thanks Rcvd at 12 Times in 10 Posts
2late Reputation: 6
did u mean 'strings' instead of 'scripts'?

If the answer is yes, indeed, Wdasm tends to give rather poor result with later C++ versions. I'd suggest try the app with Bengaly's PVDasm - I found it to be much better to locate and show strings. That's what are you after, seems to me.

Cheers
Reply With Quote
  #6  
Old 08-10-2004, 23:29
ECO
 
Posts: n/a
DrPete

You can Modified the PeHeader to E0000020 with a PeEditor
then you can see the string in WD32ASM.
ECO
Reply With Quote
  #7  
Old 08-11-2004, 00:49
monguz
 
Posts: n/a
my 2 cents...try to break on MessageboxA ,(in wdasm set breakpoint to all occurences of the API) if it breaks look at the code, somwere upwards is somthing conditional, like je,jne,jz etc. on so on..
monguz
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
2 questions about hasp suddenLy General Discussion 3 01-12-2005 01:51
Humor and a few questions. Innocent General Discussion 6 08-10-2004 02:51
2 questions (IDA / Windows 2k/2k3) skyper General Discussion 8 04-22-2004 08:44
questions about code bartster General Discussion 19 02-14-2004 01:31


All times are GMT +8. The time now is 02:25.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )