waw... its long way to get here
waw... its long way to get here
damn thx man
now i can lear how to about unpack
inside the main aadp4olly folder, there are 2 more folders named 'bin' and 'third-party'..
make a copy of 'aadp4olly.dll' inside the 'bin' folder and paste it inside your main 'odbg110' folder..
make a copy of 'TitanEngine.dll' inside the 'third-party' folder and paste it inside your main 'odbg110' folder..
when you run OllyDbg and if everything are done right, there should be a aadp4olly plugin menu in OllyDbg..
Last edited by S4R4H; 2012-01-11 at 04:21 PM.
I like to make stupid theories and asssumptions..
when i tried pressing shift + f9 nothing happens and didnt encounter this one either
-click 'No' to skip analyzing compressed code
check your:
'Debugging options' > 'Exceptions'
same as mine ?
'Debugging options' > 'Analysis 1' > 'Auto start analysis of main module'
yours is turned off, but it won't be a problem though, just press [Ctrl]+[A] when you reach the part
where you need to analyze the compressed codes..
I like to make stupid theories and asssumptions..
Progress :
- Get OEP [Check]
- Recover Stolen Byte [Check]
- Set New Origin and Dump [Check]
- IAT rebuild ImpRec [Check]
- Entering Stolen Byte [Check]
- Rebuild PE [Check]
But Got Error When Run My Dump_.exe.
Where Is My Mistake Or Missing Step?.
Tx
Already Rename To AIKAIN.exe But Still Error...
1. Error When Running The EXE
2. My Dump Exe Run In Olly
3. The Original Exe OEP in Olly
4. Tracing Stolen Byte
My Stollen Byte :
PUSH EBP
MOV EBP,ESP
PUSH -1
PUSH 623730
PUSH 5EF620
MOV EAX,DWORD PTR FS:[0]
PUSH EAX
MOV DWORD PTR FS:[0], ESP
SUB ESP, 58
PUSH EBX
PUSH ESI
PUSH EDI
MOV DWORD PTR SS:[EBP-18], ESP
Tx
Last edited by fennes; 2012-01-11 at 06:27 PM. Reason: reupload image