Exetools  

Go Back   Exetools > General > General Discussion

Notices

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1  
Old 07-29-2004, 02:08
Flagmax
 
Posts: n/a
Why can't I re Armadillo it?

I hope this wasn't asked before. If if has, I am sorry and please deleted my thread.

I am newbie at unpacking but maybe found something useful. I dumped few targets protected by Armadillo 3.xx and then I wanted to re-protect it with Armadillo. Well when adding my dumped file in Armadillo, its shows it as already Protected. The reason for that is because of two bytes in PE Header.
*Copy/Paste from Olly*
004000DA 53 DB 53 ; MajorLinkerVersion = 53 (83.)
004000DB 52 DB 52 ; MinorLinkerVersion = 52 (82.)
I don't really know what role these bytes play in but I usually zero out both and then I can Dillo the file.

In the attached pic you see these two bytes in black when looking at them in a hex editor. You basically find "PE" then count 18h bytes from there and you will land on the correct location. They read "SR" in ASCII.

Hope this helped someone.

Here is a Copy/Paste from Hex editor for those that can't download attachments.
Code:
00000000 4D5A 9000 0300 0000 0400 0000 FFFF 0000 B800 0000 0000 0000 MZ......................
00000018 4000 0000 0000 0000 0000 4584 0500 0000 0000 0000 0000 0000 @.........E.............
00000030 0000 0000 0000 0000 0000 0000 C000 0000 0E1F BA0E 00B4 09CD ........................
00000048 21B8 014C CD21 5468 6973 2070 726F 6772 616D 2063 616E 6E6F !..L.!This program canno
00000060 7420 6265 2072 756E 2069 6E20 444F 5320 6D6F 6465 2E0D 0D0A t be run in DOS mode....
00000078 2400 0000 0000 0000 D94B C4DB 9D2A AA88 9D2A AA88 9D2A AA88 $........K...*...*...*..
00000090 1E36 A488 9C2A AA88 F435 A388 9F2A AA88 7435 A788 9C2A AA88 .6...*...5...*..t5...*..
000000A8 5269 6368 9D2A AA88 0000 0000 0000 0000 0000 0000 0000 0000 Rich.*..................
000000C0 5045 0000 4C01 0800 69B4 1E40 5B4C 6F72 6450 455D E000 0F01 PE..L...i..@[LordPE]....
000000D8 0B01 5352 0030 0200 0070 0300 0000 0000 7815 0000 00D0 0100 ..SR.0...p......x.......
Attached Images
File Type: jpg dillo.JPG (118.7 KB, 17 views)

Last edited by Flagmax; 07-29-2004 at 02:19.
Reply With Quote
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Dillo protected DLL 5Alive General Discussion 32 10-08-2005 07:26


All times are GMT +8. The time now is 20:31.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )