Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 05-19-2026, 15:15
deepzero's Avatar
deepzero deepzero is offline
VIP
 
Join Date: Mar 2010
Location: Germany
Posts: 310
Rept. Given: 115
Rept. Rcvd 64 Times in 42 Posts
Thanks Given: 195
Thanks Rcvd at 224 Times in 95 Posts
deepzero Reputation: 64
The E8 imports should be doable with a script (attaching a pe section and putting the jump-thunk there then point the E8s at that). There is also a tool for this, but I dont have it anymore, ImportFixer 1.2 I think it was called.

But the real problem is obviously the VM. There is no public way to defeat it.
Reply With Quote
The Following 2 Users Say Thank You to deepzero For This Useful Post:
1ST (05-19-2026), niculaita (05-22-2026)
  #2  
Old 05-19-2026, 15:51
1ST 1ST is offline
Family
 
Join Date: Apr 2010
Location: Jordan
Posts: 99
Rept. Given: 47
Rept. Rcvd 225 Times in 24 Posts
Thanks Given: 6
Thanks Rcvd at 4 Times in 4 Posts
1ST Reputation: 200-299 1ST Reputation: 200-299 1ST Reputation: 200-299
Quote:
Originally Posted by deepzero View Post
The E8 imports should be doable with a script (attaching a pe section and putting the jump-thunk there then point the E8s at that). There is also a tool for this, but I dont have it anymore, ImportFixer 1.2 I think it was called.

But the real problem is obviously the VM. There is no public way to defeat it.
This is UIF (Universal Import Fixer) v1.2 by Magic_h2001 — it fixes Themida's E8-style "Directly Imports" in memory. But it's 32-bit only — won't work on our x64 target.
Reply With Quote
The Following User Says Thank You to 1ST For This Useful Post:
niculaita (05-20-2026)
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 16:09.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )