![]() |
![]() |
![]() |
![]() |
![]() |
||||||||||
|
||||||||||||||
![]() |
#11
|
|||
|
|||
![]() Yes you are right my friend,
there are Armadillo DLL (SNCWS.DLL and MNDWS.DLL) so what can I do next to unpack this file??? thanks for your time, best wishes. Fargo Ps: I did it, and now I am looking for Tonemode_syncright function source code in SNCWS.DLL, can anyone help me??? still has problem in IDA. Last edited by Fargo4u : 02-09-2009 at 09:53 PM. |
#12
|
|||
|
|||
![]() Hi, i Have dumped the file with the posted method...
I have 2 questions: 1-)Is the dump file is ready to use? ( I beleive the import section is not full, etc..) I am trying to use some pe fixers but they all asaying it is not a valid pe... And i try to fix the file vie imprec tool but sadly i dont know the OEP.. With the posted method am i able to get the OEP??? 2-I am able to open the file via reflector but everything is encrypted do we have anything for xenocode deobfs? I am attaching the packed & unpacked file... http://rapidshare.com/files/217772831/bckup.zip.html any help is appreciated... thanks |
#13
|
|||
|
|||
![]() Quote:
|
#14
|
|||
|
|||
![]() |
#15
|
|||
|
|||
![]() |
#16
|
|||
|
|||
![]() how will i fix the imports and iat for this? since i dont know the oep???
Quote:
|
#17
|
|||
|
|||
![]() Read up on it in the help file. Very interesting way
![]() I am guessing that DumpDomain outputs a debug message for every .net assembly loaded. *looks through the rest of the SOS.dll exports* For people interested, SOS Debugging Extension (SOS.dll) Last edited by high6 : 04-06-2009 at 05:05 AM. |
#18
|
|||
|
|||
![]() masters, no hlep on this??
![]() Quote:
|