![]() |
|
#14
|
|||
|
|||
|
There is no any jump and call instruction at next code~
But when execute next code, other code execution happen. anyway I belived that file analyzer say it was packed by 1.08.04 But now I think It may not be 1.08.04. Also the DLL was not diasembled with W32dasm So I used IDA. But IDA can not diasemble too. The DLL file is d2maphack.dll of mousepad's diablo2 maphack program. Also Olly could not debug the dll because the DLL have the code to check registration key so if no key the DLL automaticly is unloaded. Olly can debug DLL loaded into memory ! -- summary -- 1. can not diasemble with any diasembler 2. can not debug with softice becuase code changing happen 3. can not debug with olly because the dll can not be loaded -- So I give up If we can know exact a packer/protector used, It may be possible to debug or diasemble. Thanks sorry for terrible english Last edited by jadesk99; 01-12-2004 at 21:12. |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| entry point to function in comobj/activex dlls | Mitchjs | General Discussion | 5 | 12-15-2005 05:45 |
| Can I move Entry Point to the middle of the codz ? | netxman | General Discussion | 11 | 11-23-2005 08:51 |
| how to get the address of the entry point in an API | Warren | General Discussion | 6 | 08-30-2005 16:18 |
| How to make sure this is really the Entry Point | merursinecury | General Discussion | 7 | 04-13-2003 08:20 |