Exetools  

Go Back   Exetools > General > General Discussion

Notices

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #2  
Old 01-28-2006, 11:00
deroko's Avatar
deroko deroko is offline
cr4zyserb
 
Join Date: Nov 2005
Posts: 217
Rept. Given: 13
Rept. Rcvd 30 Times in 14 Posts
Thanks Given: 7
Thanks Rcvd at 33 Times in 16 Posts
deroko Reputation: 30
well I've made a little walkaround and forced CreateFileA at 420155 to read DebugApiSpy.exe instead of dumped file itself.

Code:
.00400510: E91A000000                   jmp        .00040052F  ---�� (1)
.00400515: B88D85FCFB                   mov         eax,0FBFC858D
.0040051A: AB                           stosd
.0040051B: 66B8FFFF                     mov         ax,-1
.0040051F: 66AB                         stosw
.00400521: B050                         mov         al,050 ;'P'
.00400523: AA                           stosb
.00400524: 5F                           pop         edi
.00400525: 6800054000                   push        000400500 ;'DebugApiSpy.exe
.0040052A: E926FC0100                   jmp        .000420155  ---�� (3)
.0040052F: 57                           push        edi
.00400530: BF4E014200                   mov         edi,00042014E  ---�� (4)
.00400535: E9DBFFFFFF                   jmp        .000400515  ---�� (5)
.0040053A: 0000                         add         [eax],al
sorry for too many jmps in patch but I've forgot to save edi and didn't wanna write everything from the beginning
you have to restore opcodes rewriten by jmp or progy will fail, or patch integrity check latter on

This is my fast solution probably someone will come up with better solution =)
Anyway you may use original exe and inject into last section with code that will dump file to disk and pass that fname to CreateFileA

cheers
__________________
http://accessroot.com
Reply With Quote
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Nice! ManSun General Discussion 2 04-22-2004 16:12


All times are GMT +8. The time now is 16:39.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )