View Full Version : Revirgin & CommView2.6
evaluator
September 18th, 2001, 16:52
Revirgin 1.1 can't handle CommView2.6(Tamos)
imports.
Appears, this file protected with
"Developers License" version for Tamos.
But CommView3.0 normally handled.
It's protected with maybe new version
of aspr, and Caspr v1.100 cannot unpack.
For Revirgins beta version.
Solomon
September 18th, 2001, 21:59
CommView 3.0 build 140 with latest RV beta.
After "IAT resolver" and "Resolve again", there are 13 functions unresolved:
(IATRva)
19125C
191260
191274
191318
191388
1913D0
191414
191434
19143C
191474
191478
191480
191AB0 (empty function name)
IAT Start RVA:00191208
IAT Len=000008E8
EP=00401000
tsehp
September 19th, 2001, 06:25
you should try :
api emulator
then enable trace on the still redirected ones and trace tjem
->getprocaddress
finally, look with sice on last entries :
579f00 & 579ecc = lame attempts to hide a ret4 = lockresource
and finally : 579e4c = sizeofresource , partially emulated
so only 3, not auto found, working on this actually
Solomon
September 19th, 2001, 06:44
yes, I tried it again, just got the same result. good
evaluator
September 19th, 2001, 16:31
tsehp but how about commview 2.6?
Powered by vBulletin® Version 4.2.2 Copyright © 2018 vBulletin Solutions, Inc. All rights reserved.