himanshu
08-19-2002, 03:22 PM
hi there,
i was trying to dump wisdec.exe which is packed with shrinker 3.4 . well i changed the shrinker0 segments charactristics to e0000020 and loaded the exe with symbol loader and traced the OEP(call [ebp-20],the shrinker way of jumping to OEP) .but the problem is that when i dump the program, the dumped exe still contained the shrinker segments,only the size of the exe increased from 250 to 608k.
well i tried using icedump's /DUMP 400000 98000, /BHRAMA and plain ProcDump to dump the exe, but no luck.can somebody plz tell me what i am doing wrong.
----
exe=wisdec.exe,packed with shrinker 3.4
OEP=004560ec
base=400000
size of image=00098000
----
BTW, while dumping i found that really strange things were happening. when i ran wisdec.exe , i found that its shrinker segments automatically disappeared and instead there were CODE and DATA segments.really strange...
it was only later that i found it was due to SirCam ;) but now that i have got rid of it, i am still not able to cleanly dump it.
neone ... ????
i was trying to dump wisdec.exe which is packed with shrinker 3.4 . well i changed the shrinker0 segments charactristics to e0000020 and loaded the exe with symbol loader and traced the OEP(call [ebp-20],the shrinker way of jumping to OEP) .but the problem is that when i dump the program, the dumped exe still contained the shrinker segments,only the size of the exe increased from 250 to 608k.
well i tried using icedump's /DUMP 400000 98000, /BHRAMA and plain ProcDump to dump the exe, but no luck.can somebody plz tell me what i am doing wrong.
----
exe=wisdec.exe,packed with shrinker 3.4
OEP=004560ec
base=400000
size of image=00098000
----
BTW, while dumping i found that really strange things were happening. when i ran wisdec.exe , i found that its shrinker segments automatically disappeared and instead there were CODE and DATA segments.really strange...
it was only later that i found it was due to SirCam ;) but now that i have got rid of it, i am still not able to cleanly dump it.
neone ... ????