Contribute  :  Web Resources  :  Past Polls  :  Site Statistics  :  Downloads  :  Forum  
    BiW ReversingThe challenge is yours    
 Welcome to BiW Reversing
 Sunday, April 02 2023 @ 10:08 AM CEST
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

removing Armadillos residual sections

 
Post new topic   Reply to topic    www.reversing.be Forum Index -> Unpacking
View previous topic :: View next topic  
Author Message
mustanger
Frequent poster
Frequent poster


Joined: 13 Sep 2005
Posts: 64

PostPosted: Fri Jul 07, 2006 2:31 pm    Post subject: removing Armadillos residual sections Reply with quote

Just when I was getting cocky about my armadillo abilities, I'm suddenly thrust back to my status as a dumb questioner!

I'm unpacking a program with nanomites and when I try to repair the dump in the very last step, Arminline tells me it can't do it and to "try removing armadillo's residual section" I know exactly what it means, but alas, I only know how to NOP or fill with zeros. I know this is an easy one step procedure. Can any of you mavens of cracking tell me what it is?


BTW As I was lookin for a way to remove sections, I right clicked in the Memory window and there was a coomand to "actualize" . It doesn't remove armadillo sections, but as long as I've got your attention, does anybody know what this does?
Back to top
View user's profile Send private message
moniker
Regular
Regular


Joined: 05 Sep 2005
Posts: 123
Location: lage lande

PostPosted: Fri Jul 07, 2006 7:11 pm    Post subject: Reply with quote

removing sections is one of the things i don't do through olly. There are several PE editors, like LordPE, that allow you to fiddel with sections, and other PE-format specific things.

actualize isn't a function i use commonly either, i figure that when you change for example the access permissions on a section you need to actualize the settings.
Back to top
View user's profile Send private message
bengunn
Regular
Regular


Joined: 15 Apr 2005
Posts: 118

PostPosted: Sat Jul 08, 2006 6:22 pm    Post subject: Reply with quote

Hi moniker,
It would be interesting if you would show in some detail how you do it with lpe, I've never ended up with a working dump after removing sections and rebuilding dumped arma targets using lpe alone. My method is, using ollypedumper dump twice, first a full dump all sections included, second one with all sections from the second .text to end removed, extract the resource section from first dump, use resource rebuilder to rebuild resources then add it to the second dump, that always works but a easier/simpler method would be preferred.
cheers.
Back to top
View user's profile Send private message
haggar
Regular
Regular


Joined: 19 Mar 2005
Posts: 246

PostPosted: Sat Jul 08, 2006 8:09 pm    Post subject: Reply with quote

I think that I wrote in couple mines tutorials how to do it. You erase all sections of armadillo that are unused. But if you redirect spliced code to one of them, then ofcourse that you must not delete it. Sometimes is not good to delete that .pdata one.

When you delete sections the easiest way is to rebuild it with LordPE. But in options select only "Validate PE file" and "Show Progress Window". If you want to do it manually, then you must set number of sections and image size. Also you can check file alignment, sections , etc...
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    www.reversing.be Forum Index -> Unpacking All times are GMT + 1 Hour
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group
 Copyright © 2023 BiW Reversing
 All trademarks and copyrights on this page are owned by their respective owners.
Powered By Geeklog 
Created this page in 0.84 seconds