Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 06-09-2006, 19:57
squareD's Avatar
squareD squareD is offline
VIP
 
Join Date: Aug 2005
Location: Banana Republic
Posts: 301
Rept. Given: 31
Rept. Rcvd 35 Times in 27 Posts
Thanks Given: 37
Thanks Rcvd at 110 Times in 72 Posts
squareD Reputation: 36
Don't get Olly to work properly

Hi,

I have problems to get Olly working with ExeCryptor.

Using AntiDetectOlly v2.2.4 works fine, if I don't rename patched Olly and work with original Olly in same directory.
But in this case lots of error messages appear and the real problem is, that most of plugins are not visible anymore.

So I decided to make a manually patch published by Shub-Niggurath in woodman forum using Re-Pair v0.6.

Quote:
Copy of ollydbg.exe to ollydbg_execrypt.exe

Open LordPE with ollydbg.exe (yes, it's the original file): click on PE Editor and select ollydbg.exe, then directories and then Export Table. Now place RVA and SIZE of the Export Table to 0000. Save everything and exit from LordPE.

Open Re-Pair and click fix on ollydbg.exe and wait till the process finishes.

Now you should have two files as below:
o ollydbg.exe patched with LordPE and Re-Pair
o ollydbg_execrypt.exe still original

Invert these two files renaming them: ollydbg.exe should become the not patched program, and ollydbg_execrypt.exe should become the patched program.

Now launch ollydbg_execrypt.exe (that is now the patched Olly), and exit immediately.

Now look into the directory, there should be a new .ini file, with a name like asbd.ini or something similar (the name is casual, determined by the patch re-pair did on Ollydbg). Well, copy your ollydbg.ini file over this ini file to keep your old olly settings for the patched version too.

Now to debug execrypt use ollydbg_execrypt.exe and you should also see all the plugins.
This also does not work for me...
There's no new .ini file in directory and Olly always terminates with ExeCryptor.

Really don't know what to do else?

PS: There is a file named IDP.VXD in Re-Pair folder...
Don't know what to do with this driver, because there's no explanation about it.

Regards,
squareD

Last edited by squareD; 06-09-2006 at 20:03.
Reply With Quote
  #2  
Old 06-10-2006, 23:49
_veDc
 
Posts: n/a
you tried to use the "olly advanced" plugin by markus for debugging execryptor protected apps? it works fine for me ...

http://forum.exetools.com/showthread.php?t=8479&page=6&pp=15&highlight=olly+advanced

There is maybe a newer version anywhere don't know...
Reply With Quote
  #3  
Old 06-11-2006, 10:47
kittmaster kittmaster is offline
Friend
 
Join Date: Feb 2005
Location: USA
Posts: 30
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
kittmaster Reputation: 0
Most developers are onto the tools that are used and programming exceptions when their apps are being debugged.

I think the olly advanced as mentioned would be a good try.
Reply With Quote
  #4  
Old 06-12-2006, 01:31
squareD's Avatar
squareD squareD is offline
VIP
 
Join Date: Aug 2005
Location: Banana Republic
Posts: 301
Rept. Given: 31
Rept. Rcvd 35 Times in 27 Posts
Thanks Given: 37
Thanks Rcvd at 110 Times in 72 Posts
squareD Reputation: 36
Tried out with enabled all anti-debug features...

Breaking on OEP...

Then after running into program this error appears:

Quote:
[226] Debugger detected - please disable it and restart the application.
Pressing OK-Button terminates program...
So this also seems not to work with my execryptor program.
May be I have to spend lot of time, to find out, what is going wrong.

Regards,
squareD
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
IDA can't properly deal with RUST strings WhoCares General Discussion 3 07-08-2021 10:46
My work so far CodeCracker General Discussion 6 04-28-2018 21:54
Can this work? (RAD Studio XE5) Wannabe General Discussion 0 11-10-2013 08:26
IDA IDC-script: cannot shift right properly amitophia General Discussion 2 03-28-2004 18:26


All times are GMT +8. The time now is 16:39.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )