Jump to content
Tuts 4 You

[unpackme] 12311134


Teddy Rogers

Recommended Posts

When I download it and try to open with winrar and 7zip, i get a unexpected end to archive error. Downloaded multiple times. :unsure:

Edited by What
Link to comment
  • 4 weeks later...

Me, too. :) Just wondering about the compression ratio - how good is it?

Hehe, just love those code parts: :D

0046949C	FF15 D8B04600	   call	dword ptr [46B0D8]			; kernel32.IsDebuggerPresent
004694A2 83F8 01 cmp eax, 1
004694A5 75 08 jnz short 004694AF
004694A7 6A 00 push 0
004694A9 FF15 D0B04600 call dword ptr [46B0D0] ; kernel32.ExitProcess
Edited by metr0
Link to comment

From what PEiD says, it appears to be

bambam V0.04 -> bedrock * Sign.By.fly *

Short tutorial:

- bpm access on .text

- skip the REP instruction with F8

- run again - OEP; then dump

Attached unpacked target ;)

unpacked.zip

Edited by sunbeam
Link to comment

I think this is the one where you just put a breakpoint on the first Ret, Run, Press F7, Dump with rebuild imports checked, works fine. :P

Edited by What
Link to comment

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...