Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 04-27-2005, 04:42
AdamD
 
Posts: n/a
While we have an active topic within reason, I'll pop my question in here.

I too have been trying to unpack an application that shows Armadillo 3.78 as the packer. I have found what I believe is the Entry point and used ollydump to dump the file. I'm stuck trying to use Imprec to rebuild the IAT, and seem to be getting no where fast. I've tried my best to use imprec with this packer, though I don't think I fully understand what to do. I can't run the dumped exe because of this, so I just opened it in olly to use imprec on the dumped file. Is this the correct way about going at this? Perhaps someone can help me with this subject.

Thank you.
Reply With Quote
  #2  
Old 04-27-2005, 05:46
_veDc
 
Posts: n/a
Hi,

maybe this thread:
_http://forum.exetools.com/showthread.php?t=6664 -> Armadillo 4.xx standard unpacking by DappA
will help you .. covers IAT stuff ... i hope it works for you ...

_veDc

EDIT: Just deleted the not working URL Tag .. sorry ..

Last edited by _veDc; 04-27-2005 at 19:02.
Reply With Quote
  #3  
Old 04-28-2005, 13:09
AdamD
 
Posts: n/a
Quote:
Originally Posted by _veDc
Hi,

maybe this thread:
_http://forum.exetools.com/showthread.php?t=6664 -> Armadillo 4.xx standard unpacking by DappA
will help you .. covers IAT stuff ... i hope it works for you ...

_veDc

EDIT: Just deleted the not working URL Tag .. sorry ..
Though the IAT rebuild is completely different it seems, I'm not finding anything that is stated. I'll post an attachment for all to look at, maybe someone will enlighten me.

EDIT: Added required dll to the attachment.
Attached Files
File Type: zip zclient.zip (683.2 KB, 135 views)

Last edited by AdamD; 04-29-2005 at 04:46.
Reply With Quote
  #4  
Old 04-28-2005, 14:17
lownoise
 
Posts: n/a
Talking Try This..

hxxp://ollydbg.win32asmcommunity.net/index.php?action=vthread&forum=6&topic=1105
Reply With Quote
  #5  
Old 04-28-2005, 22:35
AdamD
 
Posts: n/a
Finding the OEP isn't what I'm looking for. I can't figure out how to rebuild the IAT with the tutorial posted. The OEP for my attached file is 00029B73
Reply With Quote
  #6  
Old 04-29-2005, 03:58
lownoise
 
Posts: n/a
Quote:
Originally Posted by AdamD
Finding the OEP isn't what I'm looking for. I can't figure out how to rebuild the IAT with the tutorial posted. The OEP for my attached file is 00029B73
Sorry AdamD i was Referring to the original post from codeX
btw yor attachment doesn't work
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Conditional BPs made easy (wizard style) Rhodium General Discussion 5 01-04-2006 00:17


All times are GMT +8. The time now is 16:54.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )