Exetools

Exetools (https://forum.exetools.com/index.php)
-   General Discussion (https://forum.exetools.com/forumdisplay.php?f=2)
-   -   Newbie question ASPR 1.23 RC4 (long!) (https://forum.exetools.com/showthread.php?t=3397)

britedream 02-15-2004 17:27

I am runnig 2.1.0.0, I will download your version and see. (good thing you brought that up).

regards.

britedream 02-15-2004 19:40

Hi,
I didn't think it would make any difference, nevertheless I went and downloaded version 2.1.0.3, I did unpack
it , and without checking in the original, I went to address 578911 and change it to
mov eax, 62a43c as I suggested to you
and it runs as sweet as it can be. so the problem is at your end , may be from your dump.
btw ,I always think giving the program what it needs is better than nopping.

the protection in this version rendered all
my script worthless , it has layers after layers of asprotect protection. it was very usfull discussion , it made me discover this type of protection., which I am going to edit all my scripts to deal with it.

Regards!

Wurstgote 02-15-2004 19:55

Thanks, britedream :)
Quote:

so the problem is at your end , may be from your dump
I think you're right... your dump must somehow look different than SatyricOn's and mine. Could you please tell me where exactly you've dumped the app?

Regards
Wursgote

Satyric0n 02-15-2004 19:59

Wurstgote, please check your PM.

Regards

britedream 02-15-2004 20:05

I dumped at the oep, I will be happy to send you my dump along with my iat, for you to compare where you went wrong.

Satyric0n 02-15-2004 20:09

Please do. :) I woud appreciate it very much.

Regards

britedream 02-15-2004 20:13

just however interested should send me pm with his email or just post it.and I will send it.
regards.

Satyric0n 02-15-2004 20:26

I have PMed you with info to my FTP, to which you can upload your dump of the app, if you would please. :)

Regards,
Satyric0n

britedream 02-15-2004 20:34

I have the un edit dump, and one where I
edit the expiretion check, to prevent it from expiring which one you prefer.

Satyric0n 02-15-2004 20:39

The unedited dump will be sufficient, just so I can see what changes you made related to the problem going into Options.

Thanks

britedream 02-15-2004 21:01

I keep getting tcp error, but may be do to my slow dialup, I will be getting dsl today so I will try to send it to you , if it fails then I will upload to exetool ftp.

Satyric0n 02-15-2004 21:06

Also, make sure you have Passive Mode turned on in your FTP client.

JackD 02-15-2004 23:15

britedream,

I tried your patch at 578911 and it does run "sweet as it can be" until you select the "Options" function. At that point, it jumps to exception code that exits the program. This section of code is strictly a check to see if ASPR is still there and is otherwise not needed. At 57890c, replace 55 with C3 and everything will run "sweet as it can be".

I am having a problem with the 2 ASPR'd dlls. Unpacking them is not critical to overall funtionality of Resbldr but I was trying just for exercise. I have them both unpacked and the iat fixed, but neither of them will load. I get an "initialization error code" that normally indicates a bad PE but I don't think so. There must be a ASPR check or a chksum check that I can't find. I've seen this on other ASPR'd dlls and can't find the problem. Do you know where this check is?

JackD

britedream 02-15-2004 23:36

my dear JackD the patch at address 578911 is for option problem,and it works 100%. the progam doesn't need any fix other than this.
note: you are having the same problem as they are , this is why I am trying to upload my unpacked dump.

JackD 02-15-2004 23:55

britedream,

I think I'm getting the same problem that Wurstgote and Satyric0n are. Maybe your ASPR expiration patch is making the difference. Does you ASPR expiration patch involve an exception routine? Does your unedited dump and your patched dump behave the same way when you patch 578911?

I know you are real busy, but have you had a chance to look at either of the dll's?

JackD


All times are GMT +8. The time now is 03:16.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX