View Full Version : OllyDump v2.11.108 release
Gigapede
March 26th, 2003, 20:16
what's new in OllyDump v2.11.108
-- new import rebuild engine can rebuild asprotect,petite (not perfect)
-- tElock's imported API search(cannot rebuild but logging)
Please try various packers or protectors and report it.
download
http://dd.x-eye.net/file/ollydump211.zip ("http://dd.x-eye.net/file/ollydump211.zip")
Ricardo Narvaja
March 27th, 2003, 01:47
There is a bug yesterday i make a tut dumping a simple exe32pack archive with OLLYDMP old version and works fine, and with the new y reach the same OEP dump, and not RUN, this message appear
NO SE ENCUENTRA EL PUNTO DE ENTRADA DEL PROCEDIMIENTO RtlDeleteCriticalSection en la bibioteca de vinculos dinamicos Kernel32.dll
Don't found de entry point of procedure RtlDeleteCriticalSection in Kernel32.dll
And dont RUN and with the old OLLYDMP runs very well maybe OLLYDMP if you try more complex for hard packers maybe a option for simple rebuild for old packers
can be useful,if not i switc in old ollydmp and new ollydmp for every packer
Ricardo Narvaja
Ricardo Narvaja
March 27th, 2003, 01:58
UPX 1.24 the same error, yesterday i dump a upx 1.24 in old version and go weel, in the new ollydmp the message of error say
NO SE ENCUENTRA EL PUNTO DE ENTRADA DEL PROCEDIMIENTO RtlDeleteCriticalSection en la bibioteca de vinculos dinamicos Kernel32.dll
Don't found de entry point of procedure RtlDeleteCriticalSection in Kernel32.dll
And dont RUN
Ricardo Narvaja
Anonymous
March 27th, 2003, 06:00
try to rename this function in something what exists in kernel32
Ricardo Narvaja
March 27th, 2003, 09:50
If in old ollydmp function well in the new has a bug, then i report for correct the bug in the next release.
Ricardo
Gigapede
March 29th, 2003, 06:56
Thanks Ricardo.
I know it but I have no idea to solve it.
It may be relative with SEH and ntdll.dll's function get into kernel32.dll's thunk block.
Could you give me the both bad and good dumped files?
Ricardo Narvaja
March 29th, 2003, 08:57
i dont know your mail my mail is ricnar22@millic.com.ar if you mail i send to you the files with the old OLLYDMP and with the new OLLYDMP.
Ricardo
Gigapede
March 29th, 2003, 10:30
Sorry.
My mail is gigapede@btmo.cjb.net
I may solve this problem.
Please try new one.
http://dd.x-eye.net/file/ollydump212.zip ("http://dd.x-eye.net/file/ollydump212.zip")
Tacman
March 29th, 2003, 11:25
It seems to be working good now. I've only tested on Upx and Fsg, both succesful
Ricardo Narvaja
March 29th, 2003, 14:28
Now is the same error but with RtlGetLastWinError not found entry point in other API.
Ricardo Narvaja
Gigapede
March 29th, 2003, 21:31
I can't guess the reason any more.
Please send the files.
Ricardo Narvaja
March 30th, 2003, 04:04
I send the files yesterday to your mail.
Ricardo
Ricrado Narvaja
March 30th, 2003, 12:31
The version 2.13 RUNS WELL thanks GIGAPEDE you are great.
Ricardo Narvaja
Anonymous
March 31st, 2003, 23:57
a newbie question please???
how can i make the dumped exe run-able? Do i need to fix anything?
Ricrado Narvaja
April 1st, 2003, 01:32
Now i discover a Bug again in version 2.13, in other api, this bug i guess only in W98 and XP spanish versions, in english go well.
Ricardo Narvaja
Anonymous
April 1st, 2003, 05:31
I got an error in the unpacked file:
the procedure entry point timeGetTime could not be located in the dynamic link library comctl32.dll
Ricardo Narvaja
April 1st, 2003, 06:14
Well is the same error i have, in different api.
Ricardo Narvaja
Anonymous
April 1st, 2003, 17:49
aspack 212
windows xp
Don't found de entry point of procedure RtlGetLastWin23Error in Kernel32.dll
Ricardo Narvaja
April 2nd, 2003, 03:43
well in 2.13 version any of this bugs are repared, and others not, i think in the next release will be all repared.
Ricardo
marley
March 23rd, 2004, 15:55
odbg109d
ollydump212
Aspack 2.12
windows XP PRO
Error:
"NO SE ENCUENTRA EL PUNTO DE ENTRADA DEL PROCEDIMIENTO en la bibioteca de vinculos dinamicos WS2_32.dll"
Ricardo Narvaja
March 24th, 2004, 02:11
The last ollydmps are not full compatible with windows spanish versions, try change the mark tu the METHOD 2 of unpacking in the window of ollydmp and try again.
Si tenes el ollydmp en espaņol calculo que lo hablaras, los vijos ollydmps funcionaban en XP en espaņol, pero los ultimos los cambios de el engine determinaron que no reconstruya bien la tabla, y de siempre errores como esos sobre todo si usas en la ventana del ollydmp el metodo 1.
Proba con el metodo 2 si no bajate de mi FTP las versiones viejas de ollydmp con lo cual por lo menos podras dumpear sin error los packers mas sencillos (aspack, upx, petite, etc)
Ricardo
marley
March 24th, 2004, 14:21
Hy Ricardo, I speak Portugues(Brasil), you could send me an old version of ollydmp?
which the address of its ftp?
Thanks
Ricardo Narvaja
March 25th, 2004, 02:10
The portuguese version of XP has the same problems of the spanish version.
mi ftp es
ftp://curso:curso@ricnar456.no-ip.org/
("ftp://curso:curso@ricnar456.no-ip.org/
")
user:curso
pass:curso
en HERRAMIENTAS-PLUGINS PARA OLLY esta el ollydmp y los viejos ollydmp
en ellos puedes desempacar muchos packers sencillos (no piensen en armadillo, asprotect, etc)
Cuando llegas a oep desempacas directo y si te da un error C0000005 vas al LORDPE DELUXE y le haces un REBUILD y queda funcional.
Ricardo
marley
March 25th, 2004, 06:11
Hy Ricardo,
I Have a problem, I analyzed an archive with the PEiD, the result was EXEStealth 2,5/2,6 - > WebToolMaster.
I analyzed the sections of it and appears the UPX.
How I must proceed first? With ExeStealth or UPX?
Thanks
Ricardo Narvaja
March 25th, 2004, 13:08
Well i think if peid say exestealth i think is more possible, the names of sections can be changed.
The unpacking of the two packers are very similar (manually found OEP, DUMP, REBUILD IAT) , the diferences are few.
Ricardo
Powered by vBulletin® Version 4.2.2 Copyright © 2019 vBulletin Solutions, Inc. All rights reserved.