Sign in to follow this  
Followers 0
GIV

Scylla TheMida v2.1.8.0 IAT problem

10 posts in this topic

Hi again.


:)


 


Today i have one problem following a LCF-AT tutorial in unpacking a Themida target.


 


One API even is ok in the unpackme (TlsSetValue) in Kernel32 when the IAT is rebuilded via Scylla the API is put in oleaut32.


 


the dump in consequence will not start.


 


I put in attach all the things needed and a video of the problem.


 


I did not do something alright or?


 


See ya!


TheMida v2.1.8.0 UnpackMe.7z

Share this post


Link to post
Share on other sites

Hi GIV,


 


so if you read the IAT in Scylla then you can already see it has read the IAT not right so in your case your oleaut32 module holds 72 entrys (oleout 3 + kernel 4 + Advapi 3 + kernel 62 = 72 entrys which you can see in my video in Scylla).In your case these modules was read as one with oleout and they will now fixed to oleout = wrong.So what you can do is to enable the fix to original first thunk in Scylla settings and try again.


 


greetz


1 person likes this

Share this post


Link to post
Share on other sites

Yes, LCF-AT is probably right. Maybe I will remove the choice for that option, because using Original First Thunk is always a good behaviour, so it should be always enabled.


Share this post


Link to post
Share on other sites

Checked that option.


The same problem.


 


Edit.


With version 0.8 is working fine though.


Video2.7z

Edited by GIV

Share this post


Link to post
Share on other sites

Hi,


 


i have the same issue with a asprotect (DIE0.84: ASProtect(1.23-2.56)[EXE32]) protected file.


Scylla Version x86 v0.9.6b.


 


--- only for Information ---


1 person likes this

Share this post


Link to post
Share on other sites

Can the problem be solved?


Share this post


Link to post
Share on other sites

Thanks for the bug report. I was a little bit busy with ScyllaHide. This should fix the problem I hope, please see the attachment.


Scylla097.rar

3 people like this

Share this post


Link to post
Share on other sites

I was a little bit busy with ScyllaHide. 

I guessed the same.

No problem.

I just thought you forgot.

:)

Share this post


Link to post
Share on other sites

Thanks for the bug report. I was a little bit busy with ScyllaHide. This should fix the problem I hope, please see the attachment.

 

Scylla is a MASTER PIECE like the very famous "ImPrec"

Keep working bro.

 

BTW :

sorry out of the topic.

Just a question may be you or someone know.

I often to test dumped files with Import Fixer (SuperCracker), but often put bugs on dumped file.

Why ??? Anyone to explain ??

Is there any update version of ImportFixer from the author ??

Thanks for advances.

Edited by Hasby

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!


Register a new account

Sign in

Already have an account? Sign in here.


Sign In Now
Sign in to follow this  
Followers 0