Exetools  

Go Back   Exetools > General > General Discussion

Notices

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #16  
Old 02-28-2005, 02:30
dyn!o's Avatar
dyn!o dyn!o is offline
Friend
 
Join Date: Nov 2003
Location: Own mind
Posts: 214
Rept. Given: 1
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 8
Thanks Rcvd at 0 Times in 0 Posts
dyn!o Reputation: 1
I suggest you to forget about these cryptos if you don't know them already (you will probably lose too much valuable time on trying to learn them all at one shot).

What you should do in my opinion is not reversing the checksum scheme but find its place of execution.

I would consider the following: (separate ideas, not ordered)

1. Check if the main file size is being verified (by itself or separate process/thread). Is it? Then WHERE?
2. Check if the main file is being read (by itself/process/thread). WHERE?
3. Backtrace the code. This is my favorite method and the most effective if it comes to my experience (e.g. all nowadays anti-xxx tricks can be analyzed this way with easy). The disadvantage is that your memory (brain memory) must be very deep since you have to perform back-step-trace. If you aren't experienced with such an analysis then you can still perform it by noticing everything what happens on a sheet... but usually it's a serious amount of different information (APIs/offsets/data/calls/jmps and finally: the contexture).

Try the first two and let us know about the results, sheriff

By the way, the following fragment is my ExeTools 2005 Golden Quote: (you did not edit your post)
Quote:
I was stoned when i checked my dump!!! Check the attachment!!
I could not upload the attachment, so here are the cryptos.
If the software isn't big can you upload it somewhere (dump+data needed to run it... We may take a look on it)?

JMI: what about an idea of adding a sticky with similar stuff (like Golden Thread/Post/Answer)? You can even add some voting system...

Regards.

Last edited by dyn!o; 02-28-2005 at 02:33.
Reply With Quote
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Olly Crash when this simple app loaded... kunam General Discussion 6 10-10-2023 21:00
Installation of DriverStudio 3.2 causes System Crash rcer General Discussion 7 09-20-2009 09:25
olly & app crash optimus_prime General Discussion 11 06-10-2006 00:03
Strange Crash in Armadilled Program TmC General Discussion 4 06-03-2006 21:08


All times are GMT +8. The time now is 20:42.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )