blowfrank
April 17th, 2012, 15:02
Hi all,
I'm trying to reverse an executable, once the debugger (immunity debugger) is attached and set the first breakpoint( in my case is ws2_32 ) after 30 second i get each time process terminated exit code 7f(127), below registers. Someone can help me to bypass it? Is it some antidebugging techniques? i tried to use !hidedebug script but nothing changes.
Thanks a lot
Luc
EAX 77E668F1 kernel32.ExitProcess
ECX 00000000
EDX 00000000
EBX 0051F2D4
ESP 03CAFD18
EBP 00000000
ESI 00000000
EDI 00000000
EIP 7C8284A0 ntdll.KiUserApcDispatcher
C 0 ES 0023 32bit 0(FFFFFFFF)
P 0 CS 001B 32bit 0(FFFFFFFF)
A 0 SS 0023 32bit 0(FFFFFFFF)
Z 0 DS 0023 32bit 0(FFFFFFFF)
S 0 FS 003B 32bit 7FFA7000(FFF)
T 0 GS 0000 NULL
D 0
O 0 LastErr ERROR_SUCCESS (00000000)
EFL 00000200 (NO,NB,NE,A,NS,PO,GE,G)
ST0 empty 0.00000000000000000000
ST1 empty 0.00000000000000000000
ST2 empty 0.00000000000000000000
ST3 empty 0.00000000000000000000
ST4 empty 0.00000000000000000000
ST5 empty 0.00000000000000000000
ST6 empty 0.00000000000000000000
ST7 empty 1.2519775166695107000e-312
3 2 1 0 E S P U O Z D I
FST 0000 Cond 0 0 0 0 Err 0 0 0 0 0 0 0 0 (GT)
FCW 027F Prec NEAR,53 Mask 1 1 1 1 1 1
I'm trying to reverse an executable, once the debugger (immunity debugger) is attached and set the first breakpoint( in my case is ws2_32 ) after 30 second i get each time process terminated exit code 7f(127), below registers. Someone can help me to bypass it? Is it some antidebugging techniques? i tried to use !hidedebug script but nothing changes.
Thanks a lot
Luc
EAX 77E668F1 kernel32.ExitProcess
ECX 00000000
EDX 00000000
EBX 0051F2D4
ESP 03CAFD18
EBP 00000000
ESI 00000000
EDI 00000000
EIP 7C8284A0 ntdll.KiUserApcDispatcher
C 0 ES 0023 32bit 0(FFFFFFFF)
P 0 CS 001B 32bit 0(FFFFFFFF)
A 0 SS 0023 32bit 0(FFFFFFFF)
Z 0 DS 0023 32bit 0(FFFFFFFF)
S 0 FS 003B 32bit 7FFA7000(FFF)
T 0 GS 0000 NULL
D 0
O 0 LastErr ERROR_SUCCESS (00000000)
EFL 00000200 (NO,NB,NE,A,NS,PO,GE,G)
ST0 empty 0.00000000000000000000
ST1 empty 0.00000000000000000000
ST2 empty 0.00000000000000000000
ST3 empty 0.00000000000000000000
ST4 empty 0.00000000000000000000
ST5 empty 0.00000000000000000000
ST6 empty 0.00000000000000000000
ST7 empty 1.2519775166695107000e-312
3 2 1 0 E S P U O Z D I
FST 0000 Cond 0 0 0 0 Err 0 0 0 0 0 0 0 0 (GT)
FCW 027F Prec NEAR,53 Mask 1 1 1 1 1 1