![]() |
IT Elimination
Hi, i can't unpack armadilled when IT Elimination is used. It's new feature since v3.60 beta1.
Like, Strategic Code Splicing (i can deal with it), i've added a new section from dumped region. This target only using standard protection + IT Elimination. i've changed the long JNE to long Jmp in IT rebuilding, but there's still problem in Indirect Jump. The Indirect Call is OK (of my dumped file). Code:
004E8140 PUSH EBXBut there's problem in Indirect Jump (my dumped file) Code:
00548F50 JMP DWORD PTR DS:[D88904]And i could not go there. But in protected file, the code is like this: Code:
00548F50 JMP DWORD PTR DS:[D88904] ; VERSION.VerQueryValueA================================================================================== Weird, There's no module VERSION.dll in my dumped file. Anyone know how to deal with this new feature? Sorry for poor english Hypersnap-DX 5.50.01 Kyrios |
| All times are GMT +8. The time now is 14:38. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX