Teddy Rogers Posted October 11, 2007 Posted October 11, 2007 ExeCryptor 2.4.1 UnPackMeExeCryptor_2.4.1.rarTed.
LCF-AT Posted October 11, 2007 Posted October 11, 2007 Nothing changes.Here the unpacked file.Unpacked.rar
What Posted October 11, 2007 Posted October 11, 2007 Yeah still same stuff, same IAT repair. Unpacked pretty fast, IAT script took longer You think that when they saw that an unpacker, RSI's, was being worked on they thought man we need to get back to work because its been like a year since the last release.
Ox87k Posted October 12, 2007 Posted October 12, 2007 Someone can post an unpackme made in Delphi and packed with this version of ExeCryptor? Thanks! This one is too easy with the Evolution's tutorial!
pablov300 Posted May 27, 2008 Posted May 27, 2008 hello i from argentina somebody can help whit this fu...k excryptor 2.4.1.0 thanks ... my mails are pgusmaker@hotmail.com , control_acer@hotmail.com , the_eternalchampion@hotmail.com... thanksssss to much!!!!
SunBeam Posted May 28, 2008 Posted May 28, 2008 Read the tutorials lying around the web That should help enough..
anhduccec Posted June 6, 2008 Posted June 6, 2008 (edited) CrackmeLoki Edit : Attachment removed. User warned. Edited June 6, 2008 by Loki
Loki Posted June 6, 2008 Posted June 6, 2008 (edited) Looks like one to me Thanks for the heads up LCF-AT - if he tries to get in contact with you to get you to pass him the unpacked file then let me know. Edited June 6, 2008 by Loki
Apuromafo Posted July 14, 2008 Posted July 14, 2008 Is this a crack request?Packed Unpacked greetz thats is the option 1 click trial..maybe can write some tut for defeat if not have days :S the procedure is the same, but how fix the key of bypass the checking ? or that have some days trials..because 1 days , dump and done. nice work lcf . is the first time thats see that :S
thisistest Posted October 3, 2009 Posted October 3, 2009 0100739D - E9 2FB80100 JMP UnPackMe.01022BD1010073A2 - 0F84 2C520200 JE UnPackMe.0102C5D4010073A8 - E9 70780200 JMP UnPackMe.0102EC1D010073AD - E9 4ECC0000 JMP UnPackMe.01014000010073B2 1E PUSH DS010073B3 27 DAA010073B4 FE ??? ; Unknown command010073B5 9F LAHF010073B6 3C A9 CMP AL,0A9010073B8 16 PUSH SS010073B9 91 XCHG EAX,ECX010073BA 3F AAS010073BB 8B48 3C MOV ECX,DWORD PTR DS:[EAX+3C]010073BE 03C8 ADD ECX,EAX010073C0 8139 50450000 CMP DWORD PTR DS:[ECX],4550010073C6 75 12 JNZ SHORT UnPackMe.010073DA hr010073C8 0FB741 18 MOVZX EAX,WORD PTR DS:[ECX+18]010073CC 3D 0B010000 CMP EAX,10B010073D1 74 1F JE SHORT UnPackMe.010073F2010073D3 3D 0B020000 CMP EAX,20B010073D8 74 05 JE SHORT UnPackMe.010073DF010073DA 895D E4 MOV DWORD PTR SS:[EBP-1C],EBX010073DD EB 27 JMP SHORT UnPackMe.01007406010073DF 83B9 84000000 0E CMP DWORD PTR DS:[ECX+84],0E010073E6 ^ 76 F2 JBE SHORT UnPackMe.010073DA010073E8 33C0 XOR EAX,EAX010073EA 3999 F8000000 CMP DWORD PTR DS:[ECX+F8],EBX010073F0 EB 0E JMP SHORT UnPackMe.01007400010073F2 8379 74 0E CMP DWORD PTR DS:[ECX+74],0E010073F6 ^ 76 E2 JBE SHORT UnPackMe.010073DA010073F8 33C0 XOR EAX,EAX010073FA 3999 E8000000 CMP DWORD PTR DS:[ECX+E8],EBX01007400 0F95C0 SETNE AL01007403 8945 E4 MOV DWORD PTR SS:[EBP-1C],EAX01007406 895D FC MOV DWORD PTR SS:[EBP-4],EBX01007409 6A 02 PUSH 20100740B FF15 38130001 CALL DWORD PTR DS:[1001338] ; msvcrt.__set_app_type01007411 59 POP ECX ; ntdll.7C957C3901007412 830D 9CAB0001 FF OR DWORD PTR DS:[100AB9C],FFFFFFFF0006FFB0 0006FFE0 Pointer to next SEH record0006FFB4 010075BA SE handler push0006FFB8 01001898 UnPackMe.01001898 push0006FFBC FFFFFFFF0100739D > 6A 70 push 70 oep0100739F 68 98180001 push Unpacked.01001898010073A4 E8 BF010000 call Unpacked.01007568010073A9 33DB xor ebx,ebx010073AB 53 push ebx010073AC 8B3D CC100001 mov edi,dword ptr ds:[<&kernel32.GetModu>; kernel32.GetModuleHandleA010073B2 FFD7 call edi010073B4 66:8138 4D5A cmp word ptr ds:[eax],5A4Diat fix Difficult
SunBeam Posted October 3, 2009 Posted October 3, 2009 ^ Not quite. I've unpacked it before, same goes for main EXECryptor. Problem is the VM-ed code that would probably need cleaning/rebuilding for looks to understand anything out of it :-)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now