|
|
Thread Tools | Display Modes |
#1
|
|||
|
|||
Unpack aPE.public.version_0.0.8beta==>Upack 2.x - 3.x Heuristic Mode -> Dwing
This packer have some special features.
After I dumped the target,I can found all the IAT valid with ImportREC. Then fix the dumped. Run it,it cannot found several dll,I guess It's the temp dll used to decompass it. Then use ImportREC cut the thunks those dll can not found. Fix.Run.All ok! But when I loaded the fixed ,there is still a section that is not been unpacked. And you cannot open the resource too. Any one have experiences with the Upack 2.x - 3.x Heuristic Mode -> Dwing? The attachment is the dumped exe . EDIT: I found it! When I load the fixed,there is still a packed dll that is qtintf70.dll!! This is Delphi-Qt2.x Interface Library by Borland. And I try to unpack the qtintf70.dll,But How could I fix the IAT using ImportREC.exe? I picked the dll qtintf70.dll,the correct imagebase is 0087000, While in ImportREC's log window,It said the base is 00400000. Why? But the resource is still can not be opened.How to fix it? Any one could do me a favour to give me some useful suggestions? BTW: The dll could not be found was plugins!I made a mistake! Edit: (11.12) 1. Reason:Resource fixing porblem solved. see my thread: hxxp://forum.exetools.com/showthread.php?p=43408#post43408 But the dll unpacking and fixing IAT problem is still remained. 2. The dll cannot be found is plugins.The I cut the thunks .I made a mistake. So I reupload the unpacked. But It requires that the plugins' dlls are in the same diretory with the unpacked.exe. I donnot konw why. Regards Last edited by winndy; 11-12-2005 at 15:20. |
Thread Tools | |
Display Modes | |
|
|
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
How to pass the large data in kernel mode to user mode? | benina | General Discussion | 3 | 03-06-2010 04:50 |
How to unpack DOS program working in protected mode? | rootra | General Discussion | 7 | 05-24-2004 17:28 |