Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 11-11-2005, 12:14
winndy winndy is offline
VIP
 
Join Date: Sep 2005
Posts: 236
Rept. Given: 104
Rept. Rcvd 26 Times in 12 Posts
Thanks Given: 27
Thanks Rcvd at 16 Times in 13 Posts
winndy Reputation: 26
Unpack aPE.public.version_0.0.8beta==>Upack 2.x - 3.x Heuristic Mode -> Dwing

This packer have some special features.
After I dumped the target,I can found all the IAT valid with ImportREC.
Then fix the dumped.
Run it,it cannot found several dll,I guess It's the temp dll used to decompass
it.
Then use ImportREC cut the thunks those dll can not found.
Fix.Run.All ok!
But when I loaded the fixed ,there is still a section that is not been unpacked.
And you cannot open the resource too.

Any one have experiences with the Upack 2.x - 3.x Heuristic Mode -> Dwing?

The attachment is the dumped exe .

EDIT:

I found it!
When I load the fixed,there is still a packed dll that is qtintf70.dll!!
This is Delphi-Qt2.x Interface Library by Borland.
And I try to unpack the qtintf70.dll,But How could I fix the IAT using ImportREC.exe?
I picked the dll qtintf70.dll,the correct imagebase is 0087000,
While in ImportREC's log window,It said the base is 00400000.
Why?


But the resource is still can not be opened.How to fix it?
Any one could do me a favour to give me some useful suggestions?

BTW:
The dll could not be found was plugins!I made a mistake!

Edit: (11.12)
1.
Reason:Resource fixing porblem solved.
see my thread:
hxxp://forum.exetools.com/showthread.php?p=43408#post43408
But the dll unpacking and fixing IAT problem is still remained.

2.
The dll cannot be found is plugins.The I cut the thunks .I made a mistake.
So I reupload the unpacked.
But It requires that the plugins' dlls are in the same diretory with the unpacked.exe.
I donnot konw why.

Regards
Attached Files
File Type: rar ape_0.0.8_dumped_.rar (967.2 KB, 6 views)

Last edited by winndy; 11-12-2005 at 15:20.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to pass the large data in kernel mode to user mode? benina General Discussion 3 03-06-2010 04:50
How to unpack DOS program working in protected mode? rootra General Discussion 7 05-24-2004 17:28


All times are GMT +8. The time now is 14:20.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )