Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 08-23-2014, 03:56
0x22 0x22 is offline
Family
 
Join Date: Aug 2014
Posts: 66
Rept. Given: 14
Rept. Rcvd 47 Times in 18 Posts
Thanks Given: 12
Thanks Rcvd at 64 Times in 21 Posts
0x22 Reputation: 47
Question regarding .NET dumping

Hello guys, usually i only reverse native applications but I've started to get some interest in .NET as well, so i have a question

My target is packed with themida.
The problem is that, when i load the program it will say "invalid email" or yeah you know.. Then it will auto close the dos window so i dont have time to press dump process.

So i tried a different approach, i started the file with MegaDumper and used the option to break on load, but after i did that it will break on laod on the first dos window but there are actually two that opens, the first one loads a second one who stated the invalid text. So yeah it will break on the first one and if i dump it at that point the program will get an exception and non-functional.

Could anyone help me out on this or tell me some tools i might use instead to get me on the right track ?

This is not a request because i want to do this myself to learn different obsticles. I will attach the file so that you might be able to understand it better as im bad at explaining

Thank you four time, have a good day

https://www.sendspace.com/file/lhgpkj
Reply With Quote
  #2  
Old 08-23-2014, 04:54
0x22 0x22 is offline
Family
 
Join Date: Aug 2014
Posts: 66
Rept. Given: 14
Rept. Rcvd 47 Times in 18 Posts
Thanks Given: 12
Thanks Rcvd at 64 Times in 21 Posts
0x22 Reputation: 47
I actually fixed the issue, the issue was as simple as the name on the file after it was dumped was not correct, funny
Reply With Quote
  #3  
Old 08-23-2014, 04:58
mr.exodia mr.exodia is offline
Retired Moderator
 
Join Date: Nov 2011
Posts: 784
Rept. Given: 492
Rept. Rcvd 1,122 Times in 305 Posts
Thanks Given: 90
Thanks Rcvd at 711 Times in 333 Posts
mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299
I think GIV has a themida.net tutorial somewhere.

greetings
Reply With Quote
The Following User Gave Reputation+1 to mr.exodia For This Useful Post:
0x22 (08-28-2014)
  #4  
Old 08-23-2014, 16:37
wilson bibe wilson bibe is offline
VIP
 
Join Date: Nov 2012
Posts: 492
Rept. Given: 489
Rept. Rcvd 439 Times in 180 Posts
Thanks Given: 859
Thanks Rcvd at 176 Times in 112 Posts
wilson bibe Reputation: 400-499 wilson bibe Reputation: 400-499 wilson bibe Reputation: 400-499 wilson bibe Reputation: 400-499 wilson bibe Reputation: 400-499
Maybe this tutorial by GIV can help you
Regards
http://rghost.net/57624131
Attached Files
File Type: rar Themida unpacking.part1.rar (1.76 MB, 18 views)
File Type: rar Themida unpacking.part2.rar (1.76 MB, 15 views)
File Type: rar Themida unpacking.part3.rar (889.4 KB, 13 views)
Reply With Quote
The Following User Gave Reputation+1 to wilson bibe For This Useful Post:
0x22 (08-28-2014)
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Dumping protected memory? tr1stan General Discussion 6 08-24-2004 14:37
svkp dumping problem SvensK General Discussion 30 05-10-2004 07:09
Dumping sfld General Discussion 2 03-20-2004 23:56
Dumping a dll with ollydump ceK52z General Discussion 6 02-08-2004 19:39


All times are GMT +8. The time now is 19:12.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )