![]() |
|
|
|
#1
|
|||
|
|||
|
ahmadmansoor had a nice idea for a new IAT search algorithm. It seems that it is very accurate after some tweaks, but takes a little bit longer depending on your computer.
Use the option "advanced iat search" and test it. If you like to support this project, BTC Address: 1GmVrhWwUhwLohaCLP4SKV5kkz8rd16N8h Code:
Version 0.9.2 - Pick DLL -> Set DLL Entrypoint - Advanced IAT Search Algorithm (Enable/Disable it in Options), thanks to ahmadmansoor - Fixed bug in Options - Added donate information, please feel free to donate some BTC to support this project |
| The Following 7 Users Gave Reputation+1 to Carbon For This Useful Post: | ||
ahmadmansoor (09-27-2013), alekine322 (09-29-2013), DMichael (09-27-2013), nikkapedd (09-30-2013), sendersu (09-27-2013), the_beginner (09-28-2013), wilson bibe (09-27-2013) | ||
|
#2
|
|||
|
|||
|
new options added
Quote:
Last edited by Carbon; 03-20-2014 at 19:23. |
| The Following 8 Users Gave Reputation+1 to Carbon For This Useful Post: | ||
ahmadmansoor (02-03-2014), alekine322 (02-03-2014), DMichael (02-03-2014), h8er (02-05-2014), niculaita (02-03-2014), nikkapedd (02-03-2014), winndy (02-03-2014), ZeNiX (02-03-2014) | ||
|
#3
|
|||
|
|||
|
Quote:
Direct import scanner fix methods: - Normal: Patch memory with jmp/call only - Universal: Works with everything, creates a jump table in the scylla section, watch for relocation information in the log file I also found some weird thing in Windows 7 x64. I don't know yet why this happens: Quote:
|
| The Following 5 Users Gave Reputation+1 to Carbon For This Useful Post: | ||
ahmadmansoor (02-06-2014), copyleft (02-08-2014), giv (02-05-2014), h8er (02-05-2014), Kla$ (02-05-2014) | ||
|
#4
|
||||
|
||||
|
Quote:
but it is limited with some Protector ,in other it is Difficult to handle it . Let take the Themida/Winlicense : through the unpacked rutine ,it pass through IAT Table rebuild which write the API to the file .here it decide to write the Quote:
Quote:
pls check this Image : http://postimg.org/image/6fzu4kr8v/ and u will see what I was talking about .I have write a lot of tut on rebuild IAT for Themedi I can send it to u and through this tut u will see when and where the nop is written . and so on for other Protector ,which each one his privacy . Quote:
Thanks for ur great work ,pls keep up.
__________________
Ur Best Friend Ahmadmansoor Always My Best Friend: Aaron & JMI & ZeNiX |
|
#5
|
|||
|
|||
|
@giv
feel free to report bugs. @ahmadmansoor Try the "universal" direct import fixer (enable in options). It will work with Themida and any other protector. I don't think I can give an example. It is still weird. It has probably something to do with this https://forum.tuts4you.com/topic/34548-scylla-version-announcements/#entry159332 |
|
#6
|
||||
|
||||
|
Quote:
I will upload the files when back to home .Quote:
__________________
Ur Best Friend Ahmadmansoor Always My Best Friend: Aaron & JMI & ZeNiX |
|
#7
|
|||
|
|||
|
Now I see there is a bug. You must disable the "normal" fixer otherwise the "universal" will not work. And it is fixed only in the dumped and fixed file. Not in memory.
|
|
#8
|
||||
|
||||
|
Quote:
About scylla crash, I had found that the function ApiReader: arseExportTable is parsing export not correct in some case, the way of calculating functionName = (char*)(addressOfNamesArray[i] + deltaAddress) is not right if the address of names in the differ memory than the exportbuffer cover.
__________________
Welcome to my place http://www.reaonline.net |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Scylla IAT finder and Dumper | Storm Shadow | Source Code | 6 | 05-05-2015 02:22 |
| More Armadillo - import reconstruction | FEARHQ | General Discussion | 8 | 09-19-2005 16:46 |