Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 09-02-2004, 02:09
hobgoblin hobgoblin is offline
Friend
 
Join Date: Jan 2002
Posts: 124
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 2
Thanks Rcvd at 5 Times in 5 Posts
hobgoblin Reputation: 0
???

I did run Olly without having the Memory Access Violation checked. After one F9 and two SHIFT F9's I end up here:

004978F4 F0:F2: LOCK PREFIX REPNE: ; LOCK prefix is not allowed
004978F6 F9 STC
004978F7 B0 F4 MOV AL,0F4
004978F9 B1 B0 MOV CL,0B0
004978FB B0 B0 MOV AL,0B0
004978FD B0 F0 MOV AL,0F0
Reply With Quote
  #2  
Old 09-02-2004, 05:21
zzsx
 
Posts: n/a
Many packers and protectors checks the first bytes of the API functions to decide whether breakpoints, "INT3" (CCh), are placed.

Thefore, you could defeat the API detector by breaking at the next second or third instructions.
Reply With Quote
  #3  
Old 09-02-2004, 16:21
nikita@work
 
Posts: n/a
Not so easy... many protectors use disasm engine (like zombie's xde) and check more than 2-3 instructions.
Reply With Quote
  #4  
Old 09-03-2004, 00:26
Kyrios Kyrios is offline
Friend
 
Join Date: Feb 2003
Posts: 48
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Kyrios Reputation: 0
Quote:
I did run Olly without having the Memory Access Violation checked. After one F9 and two SHIFT F9's I end up here:
Then u another Shift+F9 pressing till you meet the similar codes i type above. Because i set some custom exceptions in "Ignore also following custom exceptions or ranges".

kyrios
Reply With Quote
  #5  
Old 09-03-2004, 03:47
ilya
 
Posts: n/a
Quote:
Originally Posted by Kyrios
Then u another Shift+F9 pressing till you meet the similar codes i type above. Because i set some custom exceptions in "Ignore also following custom exceptions or ranges".

kyrios
completely agree
Reply With Quote
  #6  
Old 09-03-2004, 04:10
hobgoblin hobgoblin is offline
Friend
 
Join Date: Jan 2002
Posts: 124
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 2
Thanks Rcvd at 5 Times in 5 Posts
hobgoblin Reputation: 0
Hmmm

Thanks for the input, but it doesn't work on my computer. when I hit Shift F9 once more I end up here:

0049F1B1 EC IN AL,DX ; I/O command
0049F1B2 8BF5 MOV ESI,EBP
0049F1B4 2031 AND BYTE PTR DS:[ECX],DH
0049F1B6 3132 XOR DWORD PTR DS:[EDX],ESI

If I push Shift F9 once more after this,the program terminates.
Reply With Quote
  #7  
Old 09-03-2004, 06:11
xastey
 
Posts: n/a
make sure you have all bp removed includeing hw bps.. Also just keep restarting the program over and over.. after a while i will run. I have seen this problem with a lot of arma apps.

BTW anyone that runs winxp sp2 does the hidedebugger plugin work for you?
Reply With Quote
  #8  
Old 09-03-2004, 16:47
ilya
 
Posts: n/a
Quote:
Originally Posted by hobgoblin
If I push Shift F9 once more after this,the program terminates.
try use Hide Debugger v1.0.1,must operate
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ASPR, ARMA question sgdt General Discussion 3 04-09-2006 03:38
About Arma hobgoblin General Discussion 1 02-02-2004 19:53


All times are GMT +8. The time now is 06:12.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )