Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 08-07-2011, 21:01
copyleft copyleft is offline
VIP
 
Join Date: Apr 2010
Posts: 174
Rept. Given: 181
Rept. Rcvd 43 Times in 39 Posts
Thanks Given: 156
Thanks Rcvd at 60 Times in 36 Posts
copyleft Reputation: 43
Why not unpacking manually,...
missing code means not unpacked code section correctly.
As Kerlingen noted you might also encounter wrong OEP address or might misplaced IAT with generic unpackers.
Reply With Quote
  #2  
Old 08-07-2011, 22:31
yogi_saw yogi_saw is offline
Family
 
Join Date: Jul 2010
Posts: 173
Rept. Given: 57
Rept. Rcvd 52 Times in 32 Posts
Thanks Given: 3
Thanks Rcvd at 13 Times in 13 Posts
yogi_saw Reputation: 52
The target was too hard to unpack manually btw there is no doubt tat unpacking was succesful. Everything is working as expected other than this two functions. And as everything is working as expected there is no chance of wrong oep. It could be possible after dumping the section size may have not included required address....
Btw is there any way to know the address which get called when i click show toolbar if i found tat it wll be easy to include code in right section

Last edited by yogi_saw; 08-07-2011 at 22:42.
Reply With Quote
  #3  
Old 08-07-2011, 22:54
yogi_saw yogi_saw is offline
Family
 
Join Date: Jul 2010
Posts: 173
Rept. Given: 57
Rept. Rcvd 52 Times in 32 Posts
Thanks Given: 3
Thanks Rcvd at 13 Times in 13 Posts
yogi_saw Reputation: 52
Btw is there any way to know the address which get called when i click show toolbar if i found tat it wll be easy to include code in right section
Reply With Quote
  #4  
Old 08-08-2011, 01:10
Kerlingen Kerlingen is offline
VIP
 
Join Date: Feb 2011
Posts: 338
Rept. Given: 0
Rept. Rcvd 278 Times in 100 Posts
Thanks Given: 0
Thanks Rcvd at 358 Times in 110 Posts
Kerlingen Reputation: 200-299 Kerlingen Reputation: 200-299 Kerlingen Reputation: 200-299
The default window/dialog proc is called. You just need to follow the control's ID from there.
Reply With Quote
  #5  
Old 08-08-2011, 02:09
yogi_saw yogi_saw is offline
Family
 
Join Date: Jul 2010
Posts: 173
Rept. Given: 57
Rept. Rcvd 52 Times in 32 Posts
Thanks Given: 3
Thanks Rcvd at 13 Times in 13 Posts
yogi_saw Reputation: 52
As i know the id gets pushed on stack for dialogbox. And same applies to menu but what do i need to see in case of submenu item
any hint on api or any docs to read is welcomed
thanks all
Reply With Quote
  #6  
Old 08-08-2011, 15:49
Kerlingen Kerlingen is offline
VIP
 
Join Date: Feb 2011
Posts: 338
Rept. Given: 0
Rept. Rcvd 278 Times in 100 Posts
Thanks Given: 0
Thanks Rcvd at 358 Times in 110 Posts
Kerlingen Reputation: 200-299 Kerlingen Reputation: 200-299 Kerlingen Reputation: 200-299
It doesn't matter if the ID comes from a menu or a sub-menu, as long as it all belongs to the same window.
Quote:
Originally Posted by Kerlingen View Post
The default window/dialog proc is called. You just need to follow the control's ID from there.
Reply With Quote
Reply

Tags
menu, procedure, resource

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to log all procedure calls? morgot General Discussion 2 10-01-2024 03:30
Olly & .NET peleon General Discussion 8 06-21-2007 09:13
Ollydebug plugin crashes.. how do i locate problem? redbull General Discussion 3 11-24-2005 15:42
Olly BPM apex General Discussion 1 02-25-2005 15:02


All times are GMT +8. The time now is 20:02.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )