Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #16  
Old 05-22-2004, 14:10
bollygud
 
Posts: n/a
well, i managed to do it, but the solution doesn't seem to fit every situation so i'll not post any real specifics yet. just wanted everyone to know that it is possible. it took a lot of rebuilding. rebuilding an iat, fixing jumps/calls, etc.

i do have one question, maybe someone can help me out. is there an api that acts the opposite of GetModuleHandleA? in other words, an api that can be feed in a number that is the modules handle, like 77000000, and it will spit out the module name? just curious, cuz something like that could help somewhat.
Reply With Quote
  #17  
Old 05-22-2004, 14:40
nerst
 
Posts: n/a
Quote:
Originally Posted by bollygud
i do have one question, maybe someone can help me out. is there an api that acts the opposite of GetModuleHandleA? in other words, an api that can be feed in a number that is the modules handle, like 77000000, and it will spit out the module name? just curious, cuz something like that could help somewhat.
GetModuleFileNameA ???
Reply With Quote
  #18  
Old 05-23-2004, 00:44
bollygud
 
Posts: n/a
hehe, duh!

thanks. my brain is a little fried
Reply With Quote
  #19  
Old 05-29-2004, 14:48
santa_kewl
 
Posts: n/a
Hi all,

On the last exception you will see anti softice sice too .
hmm still need time to find why the iat is not able to resolve using revirgin or imprec....

Regards
Reply With Quote
  #20  
Old 05-29-2004, 19:10
Darren Darren is offline
Friend
 
Join Date: May 2003
Posts: 28
Rept. Given: 3
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 16
Thanks Rcvd at 5 Times in 4 Posts
Darren Reputation: 0
because an IAT isnt used, aspr engine patches calls/jumps in the user code directly
Reply With Quote
  #21  
Old 05-29-2004, 22:31
Crk
 
Posts: n/a
i managed to make a working dump and found OEP for whereisit? 3.60 ... but can't fix IAT ..has anyone been able to find a solution for this?
Reply With Quote
  #22  
Old 05-30-2004, 02:13
SvensK
 
Posts: n/a
@Crk: britedream just posted that he unpacked latest whereisit. I'm sure he'll tell you how.

Hmm, is the OEP at 006FB5EC ?

Last edited by SvensK; 05-30-2004 at 02:24.
Reply With Quote
  #23  
Old 05-30-2004, 05:36
Crk
 
Posts: n/a
since i couldn't fix IAT i deleted all files... i forgot which one is but manually you will be able to find it ... look with W32Dasm for the string : WHEREISIT.CHM

a little up is OEP where that piece of code start (558BEC......)

there are not stolen bytes!

i'm waiting for britedream tut about fixing IAT
it looks new asprotect and armadillo are using almost same technique to protect IAT this time .. for how long?

Regards.

Last edited by Crk; 05-30-2004 at 06:42.
Reply With Quote
  #24  
Old 05-30-2004, 15:35
SvensK
 
Posts: n/a
@Crk: Ok, then at least I had found the OEP and dumped the exe.
Reply With Quote
  #25  
Old 06-01-2004, 17:01
britedream britedream is offline
Friend
 
Join Date: Jun 2002
Posts: 436
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 7 Times in 7 Posts
britedream Reputation: 0
in the new asprotect just use peid oep finder when checking the protection, it will give you the correct oep if not protected , in the two I checked it gave the correct oep.
Reply With Quote
  #26  
Old 07-20-2004, 20:15
deviljin
 
Posts: n/a
Proposed solution for fixing IAT

Since no one has posted a solution for fixing IAT of new asprotect, i post here a simple solution. I do not know it works in any situation since i did not try it on commercial software but u can check it out. I think that my solution is just an application of different suggestions i find in this forum.

I took the Unpackmenow as an example.

Regards
deviljin
Attached Files
File Type: rar iatfixing.rar (218.3 KB, 80 views)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Help with ASProtect 1.23 RC4 Perdition General Discussion 7 06-09-2004 01:48
New Asprotect?? loman General Discussion 7 02-04-2004 20:34


All times are GMT +8. The time now is 21:54.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )