Jump to content
Tuts 4 You

Scylla TheMida v2.1.8.0 IAT problem


Recommended Posts

Posted

Hi again.


:)


 


Today i have one problem following a LCF-AT tutorial in unpacking a Themida target.


 


One API even is ok in the unpackme (TlsSetValue) in Kernel32 when the IAT is rebuilded via Scylla the API is put in oleaut32.


 


the dump in consequence will not start.


 


I put in attach all the things needed and a video of the problem.


 


I did not do something alright or?


 


See ya!


TheMida v2.1.8.0 UnpackMe.7z

Posted

Hi GIV,


 


so if you read the IAT in Scylla then you can already see it has read the IAT not right so in your case your oleaut32 module holds 72 entrys (oleout 3 + kernel 4 + Advapi 3 + kernel 62 = 72 entrys which you can see in my video in Scylla).In your case these modules was read as one with oleout and they will now fixed to oleout = wrong.So what you can do is to enable the fix to original first thunk in Scylla settings and try again.


 


greetz


  • Like 1
Posted

Yes, LCF-AT is probably right. Maybe I will remove the choice for that option, because using Original First Thunk is always a good behaviour, so it should be always enabled.


Posted (edited)

Checked that option.


The same problem.


 


Edit.


With version 0.8 is working fine though.


Video2.7z

Edited by GIV
Posted

Hi,


 


i have the same issue with a asprotect (DIE0.84: ASProtect(1.23-2.56)[EXE32]) protected file.


Scylla Version x86 v0.9.6b.


 


--- only for Information ---


  • Like 1
Posted

Can the problem be solved?


Posted

Thanks for the bug report. I was a little bit busy with ScyllaHide. This should fix the problem I hope, please see the attachment.


Scylla097.rar

  • Like 3
Posted

I was a little bit busy with ScyllaHide. 

I guessed the same.

No problem.

I just thought you forgot.

:)

  • 4 months later...
Posted (edited)

Thanks for the bug report. I was a little bit busy with ScyllaHide. This should fix the problem I hope, please see the attachment.

 

Scylla is a MASTER PIECE like the very famous "ImPrec"

Keep working bro.

 

BTW :

sorry out of the topic.

Just a question may be you or someone know.

I often to test dumped files with Import Fixer (SuperCracker), but often put bugs on dumped file.

Why ??? Anyone to explain ??

Is there any update version of ImportFixer from the author ??

Thanks for advances.

Edited by Hasby

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...