Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 10-16-2004, 07:58
Peter[Pan]
 
Posts: n/a
DLL Hell (Help!)

Thanks.

My problem is i try to unpack this dll, i can find the oep very easy, i break at the JMP EAX, and step once, them iam in the oep.

for me the base was:

->> Module selected: c:\pb\pbcl.dll
Image Base:00370000 Size:0004C000

OEP in olly was: 00390108

00390108h - 00370000h = 20108h;

I enter 20108 as the oep, click IAT autosearch, and i get "Cant find anything good blah blah", now i can unpack neolite exe's fine, but i always have this problem in unpacking dll's no matter what protector

Anybody show me my problem ? thanks.
Attached Files
File Type: zip pbcl.zip (116.1 KB, 16 views)
Reply With Quote
  #2  
Old 10-16-2004, 11:40
bukkake's Avatar
bukkake bukkake is offline
VIP
 
Join Date: Aug 2004
Location: /usr/home
Posts: 127
Rept. Given: 2
Rept. Rcvd 14 Times in 3 Posts
Thanks Given: 0
Thanks Rcvd at 3 Times in 2 Posts
bukkake Reputation: 14
If you are unpacking this with ollydbg, and used loaddll.exe, when you dump the file, open ImpRec, attach to loaddll.exe, then click pick dll, and select the dll from that list you gonna get, then you can put the OEP.
Attached Files
File Type: rar dumped.rar (101.2 KB, 9 views)

Last edited by bukkake; 10-16-2004 at 11:46.
Reply With Quote
  #3  
Old 10-16-2004, 12:53
Peter[Pan]
 
Posts: n/a
Yes, i did do that, attached to loaddll.exe, and went to Pick DLL, after i chose pbcl.dll, and then i clicked ok, i enter in the oep, then i get that msg. Iam thinking it must be some other problem, which os are u using and which version of imprec please ?

See the attached Picture, i did it correct but still no go.
Attached Images
File Type: jpg error.JPG (62.4 KB, 24 views)

Last edited by Peter[Pan]; 10-16-2004 at 14:17.
Reply With Quote
  #4  
Old 10-17-2004, 19:15
LaptoniC LaptoniC is offline
Family
 
Join Date: Jan 2002
Posts: 31
Rept. Given: 1
Rept. Rcvd 38 Times in 4 Posts
Thanks Given: 1
Thanks Rcvd at 7 Times in 5 Posts
LaptoniC Reputation: 38
You know that dlls are relocated. So first check at the bottom of imprec for image base of DLL. Imprec has an option that loads PE header from disc. So lets say that your orginal dll image base is 10000 in the PE header, if that locations is reserverd by another dll, windows will load your dll to another address, ie 12000. Of course when Imprec look for 10000 it wont find anything. So in order to fix this, change corresponding option of Imprec. Your work wont be finished here because you have o fix reloc section too. Good luck
Reply With Quote
  #5  
Old 12-23-2004, 11:13
fly [CUG]'s Avatar
fly [CUG] fly [CUG] is offline
UpK
 
Join Date: Jul 2004
Location: һ������
Posts: 153
Rept. Given: 3
Rept. Rcvd 3 Times in 1 Post
Thanks Given: 5
Thanks Rcvd at 3 Times in 2 Posts
fly [CUG] Reputation: 3
Arrow UnPacked-pbcl.DLL

Game
Attached Files
File Type: rar UnPacked-pbcl.rar (96.8 KB, 6 views)
__________________

UpK

һ�����ꡭ����ƽ��!
http://www.unpack.cn
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 20:11.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )