Log in

View Full Version : rebuilding last import


MeaCulpa
January 27th, 2003, 05:43
Hi All,

I am trying to rebuild the IT, of a dumped (asprotect 1.08.x) target.
I have done the following:
-dumped a OEP with /dump
-dumpfixed the header sections
-realigned and rebased

The problem is:
In RV, when fixing the imports, there are 2 that does not want to resolve. [BTW, what would cause the right-click / tracer command to be disabled?? ]
So i use the addresses, break into the programs main module, and use eg. 'u 401234' - at that address however i cant find any API calls. There is only a direct call, which i cant seem to get a bpx on....

I also noticed that RV gives an error when trying to save the reconstructed IT to a binary file??

Any help/comments please.
thanks
.mea

crUsAdEr
January 27th, 2003, 07:06
it has been sometimes since i see a post on aspr again ... long time havent played with it, what is the lastest version of aspr now ? the last time i remember it was 1.4 according to our guru SplAj :>... anything new or has Alexey started a new project?

Anyway, Mealcupa, search on the boards for plug-in, explanation on aspr IAT redirection... you dont need bpx on API to find IAT, just "d" and "u" will do :>...

cheers
crUsAdEr

hobferret
January 28th, 2003, 11:21
Bueno Dia meaculpa

Have you tried invalidating the function and then use trace level 3 (trap flag) sometimes this works

Utherwise do what crusader says:
dd the IAT then break on that address the dd gives you, sometimes you can't "see" the CORRECT call you may have to trace into it!!

Buena Noche - - dulce suenos!

/hobferret

MeaCulpa
February 10th, 2003, 04:34
@Crusader,
Hi man, hope you are well....i'm not on the channels much lately - work ;(

If my mind serves me correctly : AsPack 2.12 and AsProtect 1.2x

Thanks for the info, but that is exactly my problem. "Just d and u" does not work, i only see a call xxxx instruction, on which i cant sucessfully set a bpx/bpm.


@hobferret,
Esperanza usted es amigo bien?
Yes, i have tried to invalidate it and got no success.

I will try these suggestions. Thank you very much for the help.

Regards,
MeaCulpa

Manko
February 10th, 2003, 05:06
can you post code?
and maybe even the code it perhaps calls/jumps to?

/Manko

hobferret
February 10th, 2003, 07:24
MeaCulpa - Trabajando demasiado eh?
Soy bien gracias, pero haga lo que Manko dice poste su código o MP yo su IAT.
Cuando usted se acostumbra a él, es bastante fácil.
Permítame saber que cuando usted está enviando el MP, escriba algo en esta tabla!
/hobferret