Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


See API calls, file is packed with themida

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> General programming
View previous topic :: View next topic  
Author Message
NoMercy
Master Cheater
Reputation: 1

Joined: 09 Feb 2009
Posts: 289

PostPosted: Thu Jan 27, 2011 2:07 am    Post subject: See API calls, file is packed with themida Reply with quote

Hello,

I'm trying to read all API calls a .dll makes, seems like I've to make a dump of the file. Downloaded dark olly, tried one of the add ons, did not work out very well.

If someone could help me here?

Thanks.
Back to top
View user's profile Send private message
AhMunRa
Grandmaster Cheater Supreme
Reputation: 27

Joined: 06 Aug 2010
Posts: 1117

PostPosted: Thu Jan 27, 2011 1:23 pm    Post subject: Reply with quote

Have you tried Import Reconstructor?

You may have to search a bit to find it.

_________________
<Wiccaan> Bah that was supposed to say 'not saying its dead' lol. Fixing >.>
Back to top
View user's profile Send private message
NoMercy
Master Cheater
Reputation: 1

Joined: 09 Feb 2009
Posts: 289

PostPosted: Thu Jan 27, 2011 3:23 pm    Post subject: Reply with quote

Thanks,

but that's if the process is running, This process is hided so...

Anyone has other ideas?
Back to top
View user's profile Send private message
AhMunRa
Grandmaster Cheater Supreme
Reputation: 27

Joined: 06 Aug 2010
Posts: 1117

PostPosted: Thu Jan 27, 2011 4:52 pm    Post subject: Reply with quote

Are you trying to reverse engineer a virus?
_________________
<Wiccaan> Bah that was supposed to say 'not saying its dead' lol. Fixing >.>
Back to top
View user's profile Send private message
atom0s
Moderator
Reputation: 205

Joined: 25 Jan 2006
Posts: 8587
Location: 127.0.0.1

PostPosted: Fri Jan 28, 2011 1:25 am    Post subject: Reply with quote

Just dump the IAT from the file itself. (Binary not while loaded.)

If the file is packed either unpack it, or hook GetProcAddress and print out all the functions it looks up pointers for.

_________________
- Retired.
Back to top
View user's profile Send private message Visit poster's website
NoMercy
Master Cheater
Reputation: 1

Joined: 09 Feb 2009
Posts: 289

PostPosted: Sat Jan 29, 2011 4:08 am    Post subject: Reply with quote

I do not know how to unpack etc.

If I do hook GetProcAddress, do I see all API imports? So a program uses it always to determine what to call?
Back to top
View user's profile Send private message
atom0s
Moderator
Reputation: 205

Joined: 25 Jan 2006
Posts: 8587
Location: 127.0.0.1

PostPosted: Sat Jan 29, 2011 6:12 am    Post subject: Reply with quote

NoMercy wrote:
I do not know how to unpack etc.

If I do hook GetProcAddress, do I see all API imports? So a program uses it always to determine what to call?


If the program is told to load all API through LoadLibrary/GetProcAddress you should get most if not all of them, it mainly depends on how the packer is rebuilding the IAT and if it is fully altering it.

_________________
- Retired.
Back to top
View user's profile Send private message Visit poster's website
sloppy
Expert Cheater
Reputation: 0

Joined: 17 Aug 2008
Posts: 123

PostPosted: Sat Jan 29, 2011 12:45 pm    Post subject: Reply with quote

Play around with WinAPIOverride or the traceapi sample from Microsoft Detours to get a quick look at the windows api calls.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> General programming All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites