Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 08-13-2005, 03:35
optimus_prime
 
Posts: n/a
olly & app crash

just got one app to look at, and it crashes before loading in my olly.
(it's renamed version with no olly strings with hidedbg.)

so, can somebody give me a hint is there a new dillo or something, or is this something custom-made.

thanks.
Reply With Quote
  #2  
Old 08-13-2005, 15:03
codeX codeX is offline
{RES} Cracker
 
Join Date: Dec 2004
Location: C:\WINDOWS\SYSTEM32
Posts: 163
Rept. Given: 1
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 3
Thanks Rcvd at 1 Time in 1 Post
codeX Reputation: 0
What's the packer? Consult PEiD.. or is it says 'nothing found'..
__________________
{RES}
Reply With Quote
  #3  
Old 08-13-2005, 15:50
dj-siba's Avatar
dj-siba dj-siba is offline
Musician Member
 
Join Date: Jun 2003
Location: Outside the dot
Posts: 324
Rept. Given: 34
Rept. Rcvd 43 Times in 21 Posts
Thanks Given: 56
Thanks Rcvd at 159 Times in 43 Posts
dj-siba Reputation: 42
maybe it use the TLS trick
Reply With Quote
  #4  
Old 08-13-2005, 23:55
taos's Avatar
taos taos is offline
The Art Of Silence
 
Join Date: Aug 2004
Location: In front of my screen
Posts: 580
Rept. Given: 65
Rept. Rcvd 54 Times in 19 Posts
Thanks Given: 69
Thanks Rcvd at 134 Times in 36 Posts
taos Reputation: 54
there's other way to crash olly without TLS, I call it "SYSTEM_KERNEL_DEBUGGER_INFORMATION"
using ZwQuerySystemInformation.
Regards
Reply With Quote
  #5  
Old 08-14-2005, 15:49
optimus_prime
 
Posts: n/a
thanks guys, just wanted to know if these symptoms point to some commercial protection since i'm lagging behind alot.

anyway, i've got a hint it's an execryptor, so i'll take look since it will probably become very trendy thanks again.
Reply With Quote
  #6  
Old 08-14-2005, 23:29
WerEsT
 
Posts: n/a
optimus_prime
then install patch for olly(olly invisible),this must help under execryptor
Reply With Quote
  #7  
Old 08-20-2005, 20:11
optimus_prime
 
Posts: n/a
yeah, thanks, just had some spare time, so i fired up softice.

it's not an execryptor it's dna 3 from
http://www.softworkz.com/DNA3/
if anyone cares
Reply With Quote
  #8  
Old 08-21-2005, 06:41
NeOXOeN NeOXOeN is offline
Friend
 
Join Date: Jan 2005
Posts: 273
Rept. Given: 2
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 2
Thanks Rcvd at 18 Times in 18 Posts
NeOXOeN Reputation: 3
where can i read more about this trick you are all reffering too??
it "SYSTEM_KERNEL_DEBUGGER_INFORMATION"
or what TLS tricky??


bye NeO
Reply With Quote
  #9  
Old 08-21-2005, 06:50
optimus_prime
 
Posts: n/a
well in my case it's tls, don't know if it is well papered trick tho.

anyway there's nice plug on reversing.be NtGlobalFlag by stingduk/jm, that can help you catch it.

read what junemouse has to say:
http://www.exetools.com/forum/showthread.php?t=7363


Last edited by optimus_prime; 08-22-2005 at 01:38.
Reply With Quote
  #10  
Old 08-22-2005, 02:49
codeX codeX is offline
{RES} Cracker
 
Join Date: Dec 2004
Location: C:\WINDOWS\SYSTEM32
Posts: 163
Rept. Given: 1
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 3
Thanks Rcvd at 1 Time in 1 Post
codeX Reputation: 0
DNA? Haven't heard of it yet... Anyway seems a smart baby. Softworkz Pricing seems interesting..

@ taos : Any more info about the "SYSTEM_KERNEL_DEBUGGER_INFORMATION".

The NtGlobalFlag v 1.1 OllyDbg Plugin Attached.

Quote:
This Ollydbg plugin logs all debugstrings that are emitted by the windows loader and logs it in ollydbg log window. Functionality to break on TLS CALLBACKS as well as on Dll Init Routines has been added.
Attached Files
File Type: zip ntglobalflag.zip (42.0 KB, 21 views)
__________________
{RES}

Last edited by codeX; 08-22-2005 at 02:54.
Reply With Quote
  #11  
Old 08-22-2005, 04:03
al-kaiser
 
Posts: n/a
I had the some problem on a app the reasen it crashed was that it was a .net file but I could´t see that cause it was protected.
Reply With Quote
  #12  
Old 06-10-2006, 00:03
conan981 conan981 is offline
VIP
 
Join Date: Feb 2006
Posts: 197
Rept. Given: 81
Rept. Rcvd 8 Times in 6 Posts
Thanks Given: 66
Thanks Rcvd at 45 Times in 23 Posts
conan981 Reputation: 8
i found another protection protected with DNA 3... AID4MAIL 1.86.
anyone has info about it? i heard it's really strong!
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Olly Crash when this simple app loaded... kunam General Discussion 6 10-10-2023 21:00
Installation of DriverStudio 3.2 causes System Crash rcer General Discussion 7 09-20-2009 09:25
Strange Crash in Armadilled Program TmC General Discussion 4 06-03-2006 21:08
Program crash MAHMUT General Discussion 22 03-03-2005 18:50


All times are GMT +8. The time now is 19:18.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )