Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #16  
Old 05-04-2004, 23:52
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
Quote:
Originally Posted by evaluator
Markus, that unpacked PEC on ftp are your?
unpacked PEC is not mine... i didn't upload anything to ftp. and the PEC i released is inline-patched

Quote:
Originally Posted by britedream
Hi
400000+3c---> offset to pe signature, add to whatever there 80H, then there is an RVA to IMPORTDirectory.

regards.
britedream, what can i do there? i think LordPE point me to the same... but can i fix there something?
Reply With Quote
  #17  
Old 05-05-2004, 19:06
evaluator
 
Posts: n/a
i had dld Pec2 & is sux to run on W98!
while on XP it runs well. What a shame, eh!?
Reply With Quote
  #18  
Old 05-05-2004, 21:38
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
that's the reason why i inline-patched it... it's one of the easiest because the OEP-jump is very easy to find (you can do it with a tutorial) but i found easier way...
use hex-editor, go to end of file and there you will find OEP-jump (FFF0) and there you can put your code
Reply With Quote
  #19  
Old 05-05-2004, 21:43
evaluator
 
Posts: n/a
well, redownloaded 04may release, now works on w9x.
Reply With Quote
  #20  
Old 05-05-2004, 21:53
evaluator
 
Posts: n/a
duh! Pec2Gui now starts, but "Browse for files" button not works again;
"Again" - because I fixed previous Pec2Gui(29apr release), which not started at all

what a buggy soft! shame to author
Reply With Quote
  #21  
Old 05-05-2004, 22:55
evaluator
 
Posts: n/a
yey, I found problem:)
btw, not bad exersize for newbies, try to find bug.
where is poor author, so we can help him.

But firstly, is he good boy!?
Reply With Quote
  #22  
Old 05-05-2004, 23:07
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
oh i thought it is maybe because of wrong unpacking *lol* but i don't know, i have no access to ftp, so it doesn't matter. seems programmer doesn't do his job very well
Reply With Quote
  #23  
Old 05-06-2004, 00:11
evaluator
 
Posts: n/a
what unpacking you are about??
i'm talking about bug in Pec2Gui.exe
Reply With Quote
  #24  
Old 05-06-2004, 01:33
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
i am too
Reply With Quote
  #25  
Old 05-06-2004, 02:01
evaluator
 
Posts: n/a
try to find this bug.

huh, another bug found when test-compressing big Exe..
Reply With Quote
  #26  
Old 05-06-2004, 02:21
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
does it not work for windows 98 or for other systems too?
Reply With Quote
  #27  
Old 05-06-2004, 02:49
evaluator
 
Posts: n/a
as above..on W9x you can't open File select dialog box.
on XP ok.
Reply With Quote
  #28  
Old 05-06-2004, 03:10
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
seems i have to find windows ME or 98 CD-ROM
Reply With Quote
  #29  
Old 05-06-2004, 09:07
britedream britedream is offline
Friend
 
Join Date: Jun 2002
Posts: 436
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 7 Times in 7 Posts
britedream Reputation: 0
Quote:
Originally Posted by MaRKuS-DJM
i'm not searching comfort, but i thought there would be a easier way to get OriginalFirstThunk.
Hi ,
I am only responding to your quotation above, I don't have the target.but after adding 80h, you will have VA, at this Va , there is Rva pointing to importDirectory, where you can find the OriginalFirstThunk you are looking for.
Reply With Quote
  #30  
Old 05-06-2004, 20:35
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
Quote:
Originally Posted by britedream
Hi ,
I am only responding to your quotation above, I don't have the target.but after adding 80h, you will have VA, at this Va , there is Rva pointing to importDirectory, where you can find the OriginalFirstThunk you are looking for.
oh thanks it looks interesting... i'll see what i can do with it
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Help to fixing API-Calls Nukacola General Discussion 6 05-11-2005 16:49
Import Rebuilding Without Import Table Kerlingen General Discussion 11 01-13-2005 10:24
Fixing an EXE to not call a DLL? Barry General Discussion 11 06-03-2004 00:37
Problem with fixing IAT K3nny General Discussion 5 01-04-2004 19:26


All times are GMT +8. The time now is 23:51.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )