![]() |
|
|
|
#1
|
|||
|
|||
|
Ok, I'll check it out and thanks for the nice scripts for OllyScript btw. Saves alot of time
|
|
#2
|
|||
|
|||
|
my pleasure!,
Some time it is usefull to use my script "asprsto", it will stop where we should be looking in the stack, that is 12ffc4:77e814c7(for this program), F9 few times till you are at mov ebp,esp; then follow the execution of your stolen with F8. Last edited by britedream; 03-24-2004 at 22:38. |
|
#3
|
|||
|
|||
|
Nice stuff, I followed the stolen bytes during execution with your method.
Still having problems with my dumped exe though. After the trace I end up at: 0041F013 FF15 68274200 CALL DWORD PTR DS:[422768] ; MSVCRT.__set_app_type I insert the stolen bytes and change the origin to PUSH EBP at 41EFE6 and then dump the exe with OllyDump, unchecking Rebuild Import. I load your tree in ImpRec and press Fix Dump. I load the exe in LordPE and change OEP to 1EFE6. Problem is the exe still wont run. ![]() It crashes at: 0041F115 |. E8 F6020000 CALL dumpLord.0041F410 |
|
#4
|
|||
|
|||
|
I don't remeber what the addresses for the two exceptios are, but if u run xp I will be glad to send you the running target.
Last edited by britedream; 03-24-2004 at 23:08. |
|
#5
|
|||
|
|||
|
Yes, please do that. Maybe I can compare the two and figure it out.
|
|
#6
|
|||
|
|||
|
please pm with your email
target has been sent, please check your e-mail. thanks Last edited by britedream; 03-24-2004 at 23:21. |
|
#7
|
|||
|
|||
|
BriteDream,
I have the same problem as Svensk (I'm running Xp Pro). I thought to use Imprec (using Raider's tutorial on Tag&Rename 3.06), to increase the IAT SIZE to 1000? Imprec v1.6f defaults to 918 when I load my patched DVDIdlePro 3.39 (stolen bytes entered and new oep set). Then I've dumped using OllyDump and unchecking: Rebuild Import. If I load your tree file, then select fix dump, the exe is not executable. It comes up with an exception. I know that with Tag & rename there was one section you ran across that had ??? and you had to NOP it. How is it that you got yours to execute and we can't get ours? Is there more patching required? -Malt |
|
#8
|
|||
|
|||
|
TO Svensk
"[insert the stolen bytes and change the origin to PUSH EBP at 41EFE6 and then dump the exe with OllyDump, unchecking Rebuild Import. I load your tree in ImpRec and press Fix Dump. I load the exe in LordPE and change OEP to 1EFE6. Problem is the exe still wont run. ![]() It crashes at: 0041F115 |. E8 F6020000 CALL dumpLord.0041F410]" Please Note: 1- if you have changed origin to push ebp, there is no need to use lordpe. 2- please don't load my iat, fix yours according to mine. Last edited by britedream; 03-25-2004 at 13:55. |
|
#9
|
|||
|
|||
|
Arrrgghh....
Britedream, thank you for the tutorials and I can confirm your version is working... at least the greet screen comes up. Mine always has an exception error. Looking at your tree file your size is 918..mine turns out to be 91C either way no luck. I confirmed the bytes you entered as stolen are entered in right where the trace dumps at. (just above 45 bytes). I noticed that Olly reports at least one different register upon initial load (no stepping) between our versions. The first time I compared the ESI turned out to be different. In you tutorial you mention the stolen bytes.... thanks to you and lownoise we have that. I am starting to think that I am doing something wrong with Imprec. When I compared our startup code..it looked dead on. Are there any different settings on Olly or Imprec that you think would make a difference? Is it the way I am dumping it with ollydump? I used your script of asprbp. to help eliminate any possible errors by me. Here is a pic of the stolen bytes entered.... the EIP (which is now the origin) and the dump window as I prepare to dump the DVDidle Code. -Malt |
|
#10
|
|||
|
|||
|
Well for me it's a little bit early, and it seems i'm missing the link in the thread that the app crashes.
I dumped the app the same way as Malt. The iat has been fixed with asprdbg from manko. It's a little tool which dumps asprotect targets from previous versions. When the asprdbg paused after he cleans the iat open imprec enther the values given by asprdbg en press fix dump. After that open your dumped exe in olly and fix the check in dvdidle pro for the present of asprotect. my quick and dirty fix is online 4043AA Mov eax, dword ptr ds:[eax] if you change this to xor eax,eax your app will run fine. lownoise |
|
#11
|
|||
|
|||
|
To maltese:
default options for importrec work fine. now when you select the first line of your stolen , you should right click on it and choose origin here then dump. |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| ASProtect SKE unpacking | TempoMat | General Discussion | 10 | 08-24-2016 17:48 |
| need help unpacking ASProtect | Fade | General Discussion | 8 | 05-25-2011 22:12 |
| Unpacking asprotect | britedream | General Discussion | 7 | 09-01-2004 01:46 |