View Single Post
  #11  
Old 25-09-2002, 02:16
crispy crispy is offline
Registered User
 
Join Date: Oct 2000
Location: Quavers test laboratory
Posts: 455
Thanks: 0
Thanked 0 Times in 0 Posts
crispy
Revirgin (and less so imprec) are more designed to rebuild mangled/screwed IAT of packed/compressed PE files which have been infected with things like ASProtect etc. Earler SD2 versions could be rebuilt but like it's been said above, the redirected calls (like Securom's latest versions) call for a lot more debuggging and code replacement.
In the end it will always be possible to rebuild these protection mechs as it MUST be decrpyted in memory to run. Even SMC routines can be rebuilt. It's just a matter of time to step thru all the crap (and obfuscation used by macrovision to slow debugging down) and do a little cut and pasting.
Apps like revirgin will help, but developers are gettting wise to these rebuilders and add fake API calls (just look at the multiple "double-dipping" of the latest ASProtect) to mess up automation.

My patience these days ain't what it used to be so maybe Macrovision has beaten me!
__________________
Munch......munch.....munch
Reply With Quote