![]() |
|
#4
|
|||
|
|||
|
Quote:
Steps i did are: 1) Load in Olly PIMOne.exe 2) Run CopyMEM II Detach script by hipu - ricardo - benina 3) ArmDetach -> grab pid 4) Load son in Olly and NOW run the script. It seems it works for a while and then it pops up with Error: No Find. The assembly looks like this: 63002951 85C0 TEST EAX,EAX ; kernel32.7C800000 63002953 74 1A JE SHORT SynTPFcs.6300296F 63002955 68 58A00063 PUSH SynTPFcs.6300A058 ; ASCII "IsTNT" 6300295A 50 PUSH EAX 6300295B FF15 14F20063 CALL DWORD PTR DS:[<&KERNEL32.GetProcAdd>; kernel32.GetProcAddress 63002961 85C0 TEST EAX,EAX 63002963 74 0A JE SHORT SynTPFcs.6300296F If i try arm_getmodule, I am able to fix magic jump, but after i set bp on CreateThread the program crashes. Any Ideas?
|
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Armadilled Programs with Custom Implementation | TmC | General Discussion | 3 | 05-15-2006 08:58 |
| Setup Factory 7.0.2.0 De-Armadilled Problem | TmC | General Discussion | 3 | 05-07-2005 23:02 |
| Program crash | MAHMUT | General Discussion | 22 | 03-03-2005 18:50 |
| Armadilled apps | Annibal | General Discussion | 12 | 02-10-2005 23:29 |