Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 02-29-2004, 15:48
kuli
 
Posts: n/a
Unhappy What's wrong with w32Dasm_2002828_pll621

WIN2000 with sp3 and use w32Dasm_2002828_pll621.exe
I saved unASM file to disk, when I open it again,some codes were changed:

-------------------------------------------------------------------------------
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:0079FF1B(C)
|
:0079FF22 8D4C2408 lea ecx, dword ptr [esp+08]
:0079FF26 8BD7 mov edx, edi
:0079FF28 8BC6 mov eax, esi
:0079FF2A E80DF7C6FF call 0040F63C
:0079FF2F FF74240C push [esp+0C]
:0079FF33 FF74240C push [esp+0C]
:0079FF37 8B433C mov eax, dword ptr [ebx+3C]
:0079FF3A 50 push eax
:0079FF3B 8D44241C lea eax, dword ptr [esp+1C]
:0079FF3F 50 push eax
:0079FF40 8B4B38 mov ecx, dword ptr [ebx+38]
:0079FF43 33D2 xor edx, edx
:0079FF45 33C0 xor eax, eax
:0079FF47 E808F7C6FF call 0040F654
:0079FF4C 8D442418 lea eax, dword ptr [esp+18]
:0079FF50 50 push eax

-------------------------------Saved then Opened--------
U)nconditional or (C)onditional Jump at Address:
|:0079FF1B(

|
:0079FF22 8D4C2408 lea ecx
dword ptr [esp+08]
:0079FF26 8BD7
mov edx, edi
:0079FF28 8BC6
mov eax, esi
:0079FF2A E80DF7C6FF
call 0040F63C
:0079FF2F FF74240C
push [esp+0C]
:0079FF33 FF74240C push [es
0C]
:0079FF37 8B433C mov
ax, dword ptr [ebx+3C]
:0079FF3A 50 pus
eax
:0079FF3B 8D44241C lea
ax, dword ptr [esp+1C]
:0079FF3F 50 pus
eax
:0079FF40 8B4B38 mov ecx
dword ptr [ebx+38]
:0079FF43 33D2
xor edx, edx
:0079FF45 33C0
xor eax, eax
:0079FF47 E808F7C6FF call 004
654
:0079FF4C 8D442418 lea

, dword ptr [esp+18]
:0079FF50 50
push eax
Reply With Quote
  #2  
Old 02-29-2004, 16:28
tom324 tom324 is offline
Friend
 
Join Date: Jan 2002
Posts: 233
Rept. Given: 5
Rept. Rcvd 7 Times in 6 Posts
Thanks Given: 26
Thanks Rcvd at 28 Times in 17 Posts
tom324 Reputation: 7
w32Dasm is out of date, its development has stopped years ago. If you want propper disassembler use IDA Pro.

Tom
Reply With Quote
  #3  
Old 02-29-2004, 19:55
kuli
 
Posts: n/a
For large file IDA too slow ,
unasm a 5MB-size file needs 5hours,@@@
Reply With Quote
  #4  
Old 02-29-2004, 22:09
Squidge's Avatar
Squidge Squidge is offline
Drunken Squirrel
 
Join Date: Oct 2002
Posts: 412
Rept. Given: 4
Rept. Rcvd 9 Times in 4 Posts
Thanks Given: 0
Thanks Rcvd at 6 Times in 6 Posts
Squidge Reputation: 9
Longest I've seen here is about 5 minutes for a 10mb file. Are you using a 486 or something?
Reply With Quote
  #5  
Old 02-29-2004, 22:51
Polaris's Avatar
Polaris Polaris is offline
Friend
 
Join Date: Feb 2002
Location: Invincible Cyclones Of FrostWinds
Posts: 97
Rept. Given: 3
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 2 Times in 2 Posts
Polaris Reputation: 0
Quote:
Originally posted by kuli
For large file IDA too slow ,
unasm a 5MB-size file needs 5hours,@@@
IDA is too superior.... However, you can try PVDasm... It is supported and free.

Byyeyeyzz

Polaris
Reply With Quote
  #6  
Old 02-29-2004, 23:03
kuli
 
Posts: n/a
Quote:
Originally posted by Squidge
Longest I've seen here is about 5 minutes for a 10mb file. Are you using a 486 or something?
MEM=256MB,CPU=PIII 800 , HD=40Gb/7000 SYS=WIN2000 SP3 ,

test.exe (DELPHI) 5.70 MB (5,987,328 BYTE)
use IDA4.5.1.770
time used :almost 5 hours.
My God !
Reply With Quote
  #7  
Old 03-01-2004, 01:24
sgdt
 
Posts: n/a
For Delphi generated apps, I use PE Explore.

It has a lot of the same key sequences as IDA, and it seems to understand Delphis qwirks better than anything else.

It's REALLY fast, and it's available here, so I'd give it a look. It even has a built in resource editor.

It's not PERFECT, but if it had three bug fixes and a MAP exporter to Olly, I'd probably buy the thing. (It's amazing how many Borland targets there are out there).

I should mention that OllyDbg also understands Borland stuff OK. It's not PE Explore, but then again, it can debug while PE Explore can't.
Reply With Quote
  #8  
Old 03-01-2004, 03:08
Polaris's Avatar
Polaris Polaris is offline
Friend
 
Join Date: Feb 2002
Location: Invincible Cyclones Of FrostWinds
Posts: 97
Rept. Given: 3
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 2 Times in 2 Posts
Polaris Reputation: 0
Quote:
Originally posted by sgdt
For Delphi generated apps, I use PE Explore.

It has a lot of the same key sequences as IDA, and it seems to understand Delphis qwirks better than anything else.

It's REALLY fast, and it's available here, so I'd give it a look. It even has a built in resource editor.

It's not PERFECT, but if it had three bug fixes and a MAP exporter to Olly, I'd probably buy the thing. (It's amazing how many Borland targets there are out there).

I should mention that OllyDbg also understands Borland stuff OK. It's not PE Explore, but then again, it can debug while PE Explore can't.
Although I would NEVER use anything than my IDA, for delphi written apps I would use old good Dede from Dafixer... Really better than PE Explorer
Reply With Quote
  #9  
Old 03-01-2004, 04:51
floorpie
 
Posts: n/a
Quote:
Originally posted by kuli
MEM=256MB,CPU=PIII 800 , HD=40Gb/7000 SYS=WIN2000 SP3 ,

test.exe (DELPHI) 5.70 MB (5,987,328 BYTE)
use IDA4.5.1.770
time used :almost 5 hours.
My God !
HA HA. Good old IDA Pro! It uses inefficient algorithms so some programs take hours to analyze. I once disassembled a VB app that took more than 24 hours to analyze and I have a VERY fast computer. Things that will make IDA slow is having lots of obfuscated code with jumps or lots of variables in a function.
Reply With Quote
  #10  
Old 03-01-2004, 05:40
tom324 tom324 is offline
Friend
 
Join Date: Jan 2002
Posts: 233
Rept. Given: 5
Rept. Rcvd 7 Times in 6 Posts
Thanks Given: 26
Thanks Rcvd at 28 Times in 17 Posts
tom324 Reputation: 7
I prefer good to fast. IDA Pro is not a tool I would use for VB and AFAIK it was not designed for VB.

Tom
Reply With Quote
  #11  
Old 03-01-2004, 06:41
floorpie
 
Posts: n/a
Quote:
Originally posted by tom324
I prefer good to fast. IDA Pro is not a tool I would use for VB and AFAIK it was not designed for VB.

Tom
IDA was designed to disassemble programs. Doesn't matter what language the program was written in.
Reply With Quote
  #12  
Old 03-01-2004, 08:11
kuli
 
Posts: n/a
w32Dasm can't instead, I like its speed and references of CALLs /Jumps ,so conveniency.
Reply With Quote
  #13  
Old 03-01-2004, 17:25
tom324 tom324 is offline
Friend
 
Join Date: Jan 2002
Posts: 233
Rept. Given: 5
Rept. Rcvd 7 Times in 6 Posts
Thanks Given: 26
Thanks Rcvd at 28 Times in 17 Posts
tom324 Reputation: 7
Quote:
Originally posted by floorpie
IDA was designed to disassemble programs. Doesn't matter what language the program was written in.
Wrong. There is a difference between compiler and interpreter. FLIRT signatures in IDA are mostly for C libraryes of various compilers.

Tom
Reply With Quote
  #14  
Old 03-01-2004, 22:35
floorpie
 
Posts: n/a
Quote:
Originally posted by tom324
Wrong. There is a difference between compiler and interpreter. FLIRT signatures in IDA are mostly for C libraryes of various compilers.

Tom
1. VB can be compiled into native code.
2. You can make your own FLIRT sigs.
3. You can program your own p-code disassembler for IDA

So you're wrong.
Reply With Quote
  #15  
Old 03-01-2004, 22:59
tom324 tom324 is offline
Friend
 
Join Date: Jan 2002
Posts: 233
Rept. Given: 5
Rept. Rcvd 7 Times in 6 Posts
Thanks Given: 26
Thanks Rcvd at 28 Times in 17 Posts
tom324 Reputation: 7
Thumbs down

> 2. You can make your own FLIRT sigs.

h**p://www.datarescue.com/ubb/ultimatebb.php?ubb=get_topic;f=1;t=000296

> 3. You can program your own p-code disassembler for IDA

h**p://www.datarescue.com/ubb/ultimatebb.php?ubb=get_topic;f=1;t=000406

> So you're wrong.

Not likely.

Tom
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
What is wrong? Asus General Discussion 2 11-14-2006 18:41
what's wrong? droptionno_1 General Discussion 2 08-27-2002 04:41


All times are GMT +8. The time now is 15:05.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )