Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 05-17-2018, 06:37
p4r4d0x p4r4d0x is offline
Friend
 
Join Date: Jul 2012
Location: https://www.youtube.com/watch?v=GoCOg8ZzUfg
Posts: 142
Rept. Given: 95
Rept. Rcvd 21 Times in 11 Posts
Thanks Given: 396
Thanks Rcvd at 146 Times in 64 Posts
p4r4d0x Reputation: 21
Lightbulb ASprotect Problem

Scanning -> C:\Documents and Settings\rea\Desktop\TunnelCAD.lnk
Link Resolved to -> C:\Program Files\IQSoft\TunnelCAD\1.7\TunnelCAD.exe
File Type : 32-Bit Exe (Subsystem : Win GUI / 2), Size : 785920 (0BFE00h) Byte(s)
[File Heuristics] -> Flag : 00000000000000001100000000100010 (0x0000C022)
[!] ASProtect SKE v2.3 - v2.5 detected !


And with Peid : ASProtect 1.33 - 2.1 Registered -> Alexey Solodovnikov *

and from vera2 : [TunnelCAD], [1.07.0006],
[2.3 build 06.26 Beta], [name].

I tried to unpack it with all scripts for Asprotect ... No Chance!
I tried with Winxp with Decomas 1.7 beta + ollydb Codedoctor
and is unpacked BUT the problem is that the application runs and sends an error 53 ( is writed on vb5!) and then kill it self!

Then i start back again scripting and i found that there is an issue at the IAT
you gone see that with the scripts it gona send you IAT = 401334 VA = 1000 and SIZE = 150 and when you go with the import fixer Dosent find it valid!!!


Any suggestions?

Last edited by p4r4d0x; 05-17-2018 at 06:56.
Reply With Quote
  #2  
Old 05-17-2018, 11:52
cybercoder cybercoder is offline
Friend
 
Join Date: Aug 2005
Posts: 114
Rept. Given: 2
Rept. Rcvd 11 Times in 8 Posts
Thanks Given: 22
Thanks Rcvd at 46 Times in 31 Posts
cybercoder Reputation: 11
google this ... run-time error:'53': file not found
Reply With Quote
  #3  
Old 05-17-2018, 18:18
p4r4d0x p4r4d0x is offline
Friend
 
Join Date: Jul 2012
Location: https://www.youtube.com/watch?v=GoCOg8ZzUfg
Posts: 142
Rept. Given: 95
Rept. Rcvd 21 Times in 11 Posts
Thanks Given: 396
Thanks Rcvd at 146 Times in 64 Posts
p4r4d0x Reputation: 21
thats not the solution cause you dont know what file is missing !!!
Reply With Quote
  #4  
Old 05-18-2018, 18:11
cybercoder cybercoder is offline
Friend
 
Join Date: Aug 2005
Posts: 114
Rept. Given: 2
Rept. Rcvd 11 Times in 8 Posts
Thanks Given: 22
Thanks Rcvd at 46 Times in 31 Posts
cybercoder Reputation: 11
Unable to even download so can't help really...
Reply With Quote
  #5  
Old 05-18-2018, 18:35
sendersu sendersu is offline
VIP
 
Join Date: Oct 2010
Posts: 1,067
Rept. Given: 332
Rept. Rcvd 223 Times in 115 Posts
Thanks Given: 235
Thanks Rcvd at 513 Times in 288 Posts
sendersu Reputation: 200-299 sendersu Reputation: 200-299 sendersu Reputation: 200-299
Quote:
Originally Posted by p4r4d0x View Post
thats not the solution cause you dont know what file is missing !!!
if the app looks for some file and its missed most easiest way would be to use procmon tool and figure it out (or any other FS monitoring utility)
Reply With Quote
The Following User Says Thank You to sendersu For This Useful Post:
p4r4d0x (05-18-2018)
  #6  
Old 05-18-2018, 19:01
dosprog dosprog is offline
Friend
 
Join Date: Feb 2018
Posts: 114
Rept. Given: 0
Rept. Rcvd 17 Times in 16 Posts
Thanks Given: 33
Thanks Rcvd at 146 Times in 74 Posts
dosprog Reputation: 17
Quote:
Originally Posted by p4r4d0x View Post
thats not the solution cause you dont know what file is missing !!!
1) How to I can switch language of proggy to english? (INI-faile string "Language=2" not gives effect).
2) Test this ->Loader<- and tell me what limitations [and errors occured] in proggy launched with it.


Last edited by dosprog; 05-18-2018 at 19:08.
Reply With Quote
  #7  
Old 05-18-2018, 20:14
p4r4d0x p4r4d0x is offline
Friend
 
Join Date: Jul 2012
Location: https://www.youtube.com/watch?v=GoCOg8ZzUfg
Posts: 142
Rept. Given: 95
Rept. Rcvd 21 Times in 11 Posts
Thanks Given: 396
Thanks Rcvd at 146 Times in 64 Posts
p4r4d0x Reputation: 21
Quote:
Originally Posted by sendersu View Post
if the app looks for some file and its missed most easiest way would be to use procmon tool and figure it out (or any other FS monitoring utility)
Event Class: File System
Operation: CreateFile
Result: NAME INVALID
Path: C:\Program Files\IQSoft\TunnelCAD\1.7\ÿÿÿÿ.DLL
TID: 3352
Duration: 0.0000120
Desired Access: Read Attributes
Disposition: Open
Options: Open Reparse Point
Attributes: n/a
ShareMode: Read, Write, Delete
AllocationSize: n/a

https://image.ibb.co/iCc7mJ/Screen_Shot_2018_05_18_at_8_18_06_AM.png

Last edited by p4r4d0x; 05-18-2018 at 20:21. Reason: image added
Reply With Quote
  #8  
Old 05-18-2018, 20:19
p4r4d0x p4r4d0x is offline
Friend
 
Join Date: Jul 2012
Location: https://www.youtube.com/watch?v=GoCOg8ZzUfg
Posts: 142
Rept. Given: 95
Rept. Rcvd 21 Times in 11 Posts
Thanks Given: 396
Thanks Rcvd at 146 Times in 64 Posts
p4r4d0x Reputation: 21
Quote:
Originally Posted by dosprog View Post
1) How to I can switch language of proggy to english? (INI-faile string "Language=2" not gives effect).
2) Test this ->Loader<- and tell me what limitations [and errors occured] in proggy launched with it.

for the lang sorry my mistake at TunnelCad.cfg you can put 2
incorect version.. thats all
Reply With Quote
  #9  
Old 05-18-2018, 20:24
p4r4d0x p4r4d0x is offline
Friend
 
Join Date: Jul 2012
Location: https://www.youtube.com/watch?v=GoCOg8ZzUfg
Posts: 142
Rept. Given: 95
Rept. Rcvd 21 Times in 11 Posts
Thanks Given: 396
Thanks Rcvd at 146 Times in 64 Posts
p4r4d0x Reputation: 21
Quote:
Originally Posted by cybercoder View Post
Unable to even download so can't help really...
heres the main setup : http://dropmefiles.com/n1HUt File Size: 18.1mb
Reply With Quote
  #10  
Old 05-18-2018, 23:17
cybercoder cybercoder is offline
Friend
 
Join Date: Aug 2005
Posts: 114
Rept. Given: 2
Rept. Rcvd 11 Times in 8 Posts
Thanks Given: 22
Thanks Rcvd at 46 Times in 31 Posts
cybercoder Reputation: 11
on an xp virtual machine you could use wkt vb6 pcode debugger to find your problem... not going to tell you how what's the fun in that... But you can fix it with this..
Reply With Quote
The Following 2 Users Say Thank You to cybercoder For This Useful Post:
p4r4d0x (05-19-2018), tonyweb (05-20-2018)
  #11  
Old 05-19-2018, 02:10
dosprog dosprog is offline
Friend
 
Join Date: Feb 2018
Posts: 114
Rept. Given: 0
Rept. Rcvd 17 Times in 16 Posts
Thanks Given: 33
Thanks Rcvd at 146 Times in 74 Posts
dosprog Reputation: 17
Quote:
Originally Posted by p4r4d0x View Post
for the lang sorry my mistake at TunnelCad.cfg you can put 2
incorect version.. thats all
1) "Language=2" in INI-file give no effect.
2) Loader - run it where ORIGINAL PACKED file TunnelCAD.EXE v.1.7.6.1 placed. Where it is installed.

Last edited by dosprog; 05-19-2018 at 03:18.
Reply With Quote
The Following User Says Thank You to dosprog For This Useful Post:
p4r4d0x (05-19-2018)
  #12  
Old 05-19-2018, 09:38
p4r4d0x p4r4d0x is offline
Friend
 
Join Date: Jul 2012
Location: https://www.youtube.com/watch?v=GoCOg8ZzUfg
Posts: 142
Rept. Given: 95
Rept. Rcvd 21 Times in 11 Posts
Thanks Given: 396
Thanks Rcvd at 146 Times in 64 Posts
p4r4d0x Reputation: 21
Quote:
Originally Posted by dosprog View Post
1) "Language=2" in INI-file give no effect.
2) Loader - run it where ORIGINAL PACKED file TunnelCAD.EXE v.1.7.6.1 placed. Where it is installed.
Really it works..!!! Nice work ! My problem bro is what Im doing wrong with this protection.. can you help me just for Knowledge! what actions did you take and where i have to focus?

By the way thanks again!
Reply With Quote
  #13  
Old 05-19-2018, 16:17
dosprog dosprog is offline
Friend
 
Join Date: Feb 2018
Posts: 114
Rept. Given: 0
Rept. Rcvd 17 Times in 16 Posts
Thanks Given: 33
Thanks Rcvd at 146 Times in 74 Posts
dosprog Reputation: 17
Quote:
Originally Posted by p4r4d0x View Post
[..] what Im doing wrong with this protection.. [..]
Also don't know, I'll look later


--Add--

Use Q&D patch (File tc1761.CRK) :
Quote:
TunnelCAD 1.7.6.1
UnPacked

Skip starting nag (Error 53)
TunnelCAD.exe
.005612D8: 0B 14
.0055497F: 1C 1E
Can use CRACKER.EXE for apply this patch.



--Add2--
.. but program works strange. Fucked vbasic ..


Last edited by dosprog; 05-20-2018 at 16:03.
Reply With Quote
The Following User Says Thank You to dosprog For This Useful Post:
p4r4d0x (05-19-2018)
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
problem with asprotect 1.2x-1.3x el-kiwi General Discussion 6 12-03-2004 05:28
problem.................................... nikicraki General Discussion 3 12-13-2003 21:03
IDA 4.17 problem loman General Discussion 2 08-21-2002 18:35


All times are GMT +8. The time now is 15:47.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )