Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 02-15-2005, 10:13
grimm
 
Posts: n/a
Question Dumping protected DLL 'perplex' data section

Been out of the reverse engineering picture for a while and decided to get back into it as there is an app which I use that is missing some functions ;) I'm working the apps DLL which is packed using an Unknown packer (at least to me) It has a data section called 'perplex' which I seem to remember indicates that this has been packed with ACProtect/UltraProtect. Can anyone confirm this?

Also I'm using ollydbg as I couldn't get softice to install on XP sp2 grrr and didn't feel like going back to 98. I was wondering if there was anything I should be looking out for when unpacking ACprotect/UltraProtect - I have Hide Debugger v1.2 and Ollydump installed... anything else?

TIA

grimm
Reply With Quote
  #2  
Old 02-15-2005, 14:21
fly [CUG]'s Avatar
fly [CUG] fly [CUG] is offline
UpK
 
Join Date: Jul 2004
Location: һ������
Posts: 153
Rept. Given: 3
Rept. Rcvd 3 Times in 1 Post
Thanks Given: 5
Thanks Rcvd at 3 Times in 2 Posts
fly [CUG] Reputation: 3
http://www.exetools.com/forum/showthread.php?t=6148
__________________

UpK

һ�����ꡭ����ƽ��!
http://www.unpack.cn
Reply With Quote
  #3  
Old 02-15-2005, 16:39
Michel Michel is offline
Friend
 
Join Date: Sep 2004
Location: France
Posts: 66
Rept. Given: 2
Rept. Rcvd 6 Times in 1 Post
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Michel Reputation: 6
http://www.exetools.com/forum/showthread.php?t=6774
Reply With Quote
  #4  
Old 02-15-2005, 23:31
JMI JMI is offline
Leader
 
Join Date: Jan 2002
Posts: 1,627
Rept. Given: 5
Rept. Rcvd 199 Times in 99 Posts
Thanks Given: 0
Thanks Rcvd at 98 Times in 96 Posts
JMI Reputation: 100-199 JMI Reputation: 100-199
And watch out for that JMI fellow, he'll tell you to stop being so darn lazy and to use the SEARCH function both here and on the net before you ask a question that may have been already answered. There is also information here and on the net about getting Softice to function on SP2.

Regards,
__________________
JMI
Reply With Quote
  #5  
Old 02-28-2005, 08:19
grimm
 
Posts: n/a
Sorry have been away from my machine so haven't been able to respond.

The search function? I can't see one on the exetools boards... not in Quick Links or Thread Tools. I'm using Firefox if that makes a difference?

I wasn't being toooo lazy... I tried searching google with different combinations of 'perplex', 'rdata', 'data' etc and only found one relevant page: http://www.pediy.com/bbshtml/BBS6/pediy6922.htm but as I don't understand the language it was pretty tough to decipher

Thanks for the links. I shall get on and unpack this thing!

grimm
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Dumping Armadillo protected DLL? FEARHQ General Discussion 10 02-09-2005 11:08
Dumping protected memory? tr1stan General Discussion 6 08-24-2004 14:37
Dumping sfld General Discussion 2 03-20-2004 23:56


All times are GMT +8. The time now is 18:35.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )