Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 06-28-2004, 07:31
Crk
 
Posts: n/a
here it is... it just miss IAT .use Imprec for IAT

you can use some PE realigner and PE fixer on it .. just in case
Reply With Quote
  #2  
Old 06-28-2004, 07:41
BetaMaster BetaMaster is offline
Friend
 
Join Date: Dec 2002
Posts: 77
Rept. Given: 6
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 0
Thanks Rcvd at 2 Times in 2 Posts
BetaMaster Reputation: 3
Quote:
Originally Posted by Crk
here it is... it just miss IAT .use Imprec for IAT

you can use some PE realigner and PE fixer on it .. just in case
you say it as if it is trivial!

well body, why don't you do the IAT fix too, I am sure that you'll know then that you haven't taken a step yet.

Last edited by BetaMaster; 06-28-2004 at 07:49.
Reply With Quote
  #3  
Old 06-28-2004, 07:51
Crk
 
Posts: n/a
attached...
Reply With Quote
  #4  
Old 06-28-2004, 16:04
BetaMaster BetaMaster is offline
Friend
 
Join Date: Dec 2002
Posts: 77
Rept. Given: 6
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 0
Thanks Rcvd at 2 Times in 2 Posts
BetaMaster Reputation: 3
hmmm, thanks ... nice work but where did ordinal at rva 1094 go? I think Real|sty stuck with the same entry.ok, I'll try to find it by myself.

Thanks again Crk for the dump and the IAT tree file.
Reply With Quote
  #5  
Old 06-28-2004, 21:41
Crk
 
Posts: n/a
can't find it neither.. maybe is invalid to fool with us ??? if invalid then just nop it
Reply With Quote
  #6  
Old 07-01-2004, 10:00
Crk
 
Posts: n/a
OK... after analyzing the working IAT for v2.07 i found out that the missing one is DllFunctionCall ... i could be wrong .. but correct me anytime if i'm mistaken ... here are attached new dumped including added IAT + IAT tree for new and old version.

btw the app. still crash always at same offset ... i believe this most be a crc check

btw i used as OEP 0000137A to get the IAT for v3.0.4
Reply With Quote
  #7  
Old 07-01-2004, 17:59
BetaMaster BetaMaster is offline
Friend
 
Join Date: Dec 2002
Posts: 77
Rept. Given: 6
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 0
Thanks Rcvd at 2 Times in 2 Posts
BetaMaster Reputation: 3
thanks Crk again, so nice of you to complete the job.
I appreciate it very much.
Reply With Quote
  #8  
Old 07-01-2004, 18:56
BetaMaster BetaMaster is offline
Friend
 
Join Date: Dec 2002
Posts: 77
Rept. Given: 6
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 0
Thanks Rcvd at 2 Times in 2 Posts
BetaMaster Reputation: 3
ok, after some analysis it seems neither is correct, the added entry or the oep.

the missing entry is away from msvbvm60.dll, perhaps it's decryption routine, or some sort on code injection routine.

I think if the author of the product spent his time enhancing his product more than the time he spent to over-protect it, that would have been much much better for him.I cannot imagine that a little program to change some entries in registry, or do things that freeware program does, can have such protection.
Reply With Quote
  #9  
Old 07-01-2004, 20:23
Crk
 
Posts: n/a
this is right OEP and the way it should be... check more VB. app. and you'll know why
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 23:32.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )