LaBBa
October 6th, 2002, 02:15
i alredy once asked about :
Examine32 v4.00
that both imprec and revirgin couldn't find the AIT and fix it..
i saw the two replays of nikolatesla20 and h8er and i thoght
that "ok they done it again they can unpack all"
but after a while i had some spare time and wanted to do it
by my self ...
h8er posted this :
"dump the file oep is 1000
load examine with symbol loader
bpr 442000 442000+948 rw
0187:0045017D C1F902 SAR ECX,02
0187:00450180 F3A5 REPZ MOVSD <- you pop here
0187:00450182 8BC8 MOV ECX,EAX
0187:00450184 83E103 AND ECX,03
at 450182 d 442000 this is your it an down there's the complete iat so here dump 442000 948
IT Rva 42000 size f0
IAT Rva 420f0 size 948
fix the dump " end of h8er words
i done all of that step by step .. but still some things are not the same ,like :
1) if i do a : 'bpr 442000 442000+948 rw'
i will NOT pop here:
> 0187:00450180 F3A5 REPZ MOVSD <- you pop here
2) after the dumping and pasting it back still doesn't work...
if can some1 plz help me with that with better explnations i will
be very thankful
Examine32 v4.00
that both imprec and revirgin couldn't find the AIT and fix it..
i saw the two replays of nikolatesla20 and h8er and i thoght
that "ok they done it again they can unpack all"
but after a while i had some spare time and wanted to do it
by my self ...
h8er posted this :
"dump the file oep is 1000
load examine with symbol loader
bpr 442000 442000+948 rw
0187:0045017D C1F902 SAR ECX,02
0187:00450180 F3A5 REPZ MOVSD <- you pop here
0187:00450182 8BC8 MOV ECX,EAX
0187:00450184 83E103 AND ECX,03
at 450182 d 442000 this is your it an down there's the complete iat so here dump 442000 948
IT Rva 42000 size f0
IAT Rva 420f0 size 948
fix the dump " end of h8er words
i done all of that step by step .. but still some things are not the same ,like :
1) if i do a : 'bpr 442000 442000+948 rw'
i will NOT pop here:
> 0187:00450180 F3A5 REPZ MOVSD <- you pop here
2) after the dumping and pasting it back still doesn't work...
if can some1 plz help me with that with better explnations i will
be very thankful