Exetools

Exetools (https://forum.exetools.com/index.php)
-   General Discussion (https://forum.exetools.com/forumdisplay.php?f=2)
-   -   dvr studio99d yoda cryptet after unpack not run :-( (https://forum.exetools.com/showthread.php?t=4207)

the_beginner 05-06-2004 21:21

dvr studio99d yoda cryptet after unpack not run :-(
 
1 Attachment(s)
Hi

I have here a proggie its packet with yoda modified ,I can unpack this file but its will not run (the 99c version no probs)
can anybody help me with this file

thanks

Btw I have a loader written it work fine but patching it better

the_beginner I'm still lean :-)

MaRKuS-DJM 05-06-2004 23:21

OEP: 44B6E9

IAT attached

please compare... is your OEP wrong or your IAT? ImportRec can resolve every import of y0das cryptor through trace level 1

Regards

the_beginner 05-07-2004 02:40

hmmm ???

my oep is the same but my iat is not the same ,I cant understand why

may i have some wrong options on my olly ?? I dont know what the right options for debugging ,because I have use ever sice on win 98 now I use olly since 2 weeks ,can someone help or tell me how make I the right option

thanks

MaRKuS-DJM 05-07-2004 03:17

if OEP is right, you have done everything right with olly.
then use imprec, insert OEP (the one without image-base from ollydump), click IAT auto search, get imports... then click show invalid, right click and Trace Level One (Disasm), and all is valid. then fix dump. good luck.

the_beginner 05-07-2004 04:51

1 Attachment(s)
shit wont not work ,I THINK I make anything with imprec wrong ,maybe wrong options

TQN 05-07-2004 11:23

2 Attachment(s)
Nothing wrong with me. What are your Windows version ? ImpRect settings for 9x/Me have some differences with WinNT/2000. This is my settings for ImpRec on my Win2000 Server and the unpacked file.
Regards

the_beginner 05-07-2004 15:35

thanks for unpacking,but I have testet unpack and fix on my Notebook with xp ,want work here on my pc w2k work only unpack but I cant fix the *.exe :confused: I dont Know why
I'ts can be soo hard ????

TQN 05-07-2004 16:22

Do not check "Import all by Ordinal" on ImpRec options.
Good luck

the_beginner 05-07-2004 20:01

3 Attachment(s)
F*ck it wont be work ,under w2k the proggi start but crash,under XP pro many Faults ,can this some one explain why ,olly 10,steb3 ollydump 221.108 or 220.108 hidedebugger isdebug ,Maybe shit on my system :confused:

thanks if someone explain

edit

my dumped file and my iat (but not work :confused: ) and the fixed file ,who can explain what wrong ? I'm sure here someone can this


All times are GMT +8. The time now is 23:14.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX