Jump to content
Tuts 4 You

[unpackme] Larp V2.0 Pro Ed.


Recommended Posts

Posted

After lARP v2.0 Lite and lARP v2.0 Standard editions, here is an unpackme protected by lARP v2.0 Pro Ed.

It is supposed to be challenging :o

Have fun

lena151.

lARP_v2.0_Pro_UnpackMe.rar

Posted (edited)

yay ;)

edit : forgot to fix the data section :P

should be okay now :)

done.rar

Edited by syk071c
Posted (edited)
yay ;)

Can one of you guys throw me a bone and tell me why I can't even get it to run through my Olly? Iam guessing it's part of the protection. If it is the protection can someone give me a few pointers please? There must be a way without just attaching it

Edited by vinnie
Posted

@vinnie: Not the purpose of this thread ;) Either try to figure it out on your own or take it in PMs =]

Posted (edited)

@vinnie: what sunbeam said ;) you need to study up on anti-debug techniques.. ;) it's what i did.. :)

Edited by syk071c
Posted
@vinnie: what sunbeam said ;) you need to study up on anti-debug techniques.. ;) it's what i did.. :)

I'm sure if he gets really stuck you will help point him in the right direction... :D

Ted.

Posted (edited)
@vinnie: what sunbeam said ;) you need to study up on anti-debug techniques.. ;) it's what i did.. :)

I'm sure if he gets really stuck you will help point him in the right direction... :D

Ted.

Oh well :confused: I guess but all I really wanted was a bone not the steak. Anyhow I think I am getting there in any case but Iam cheating by studying a script I think Pavka wrote. This however doesn't and won't explain the protection I think so I may well need a little guidance afterall later. So you see what you guys have done... you have made me resort to cheating...for now.

Oh syk071c, is there a anti deugging paper you are referencing to?? Yes I googled and there is a huge list to go through.

Edited by vinnie
Posted (edited)

I'm sure if he gets really stuck you will help point him in the right direction... :D

Oh well :confused: I guess but all I really wanted was a bone not the steak.

vinnie, I've sent you a bone and a steak by pm ;)

See there.

lena151.

Edited by lena151
Posted

Хм.. My bad English Is a pity ;( do not understand sense of discussion

Posted (edited)
Хм.. My bad English Is a pity ;( do not understand sense of discussion

@ Pavka

What I mean is I want only a clue (bone) and I don't want the someone to show me everything ( steak )

bone=clue steak=show me how to do please

Do you understand now?? :biggrin:

Edited by vinnie
Posted

@pavka: Он хотел бы знать, как запускать его в Оlly ;)

  • 2 months later...
ahmadmansoor
Posted

I'm sure if he gets really stuck you will help point him in the right direction... :D

Oh well :confused: I guess but all I really wanted was a bone not the steak.

vinnie, I've sent you a bone and a steak by pm ;)

See there.

lena151.

FIRST SORRY lena151 ...i think u know :confused: ...........

but is there any way to send to me some hints like vinnie .

and Thanks in adv

Posted

Can one of you throw me a bone with this too... gettin no where.

just like eXpressor throwing me bsod everytime :D

Posted (edited)

Well I had a bypass script, but I do not know where the hell it went, so I will just describe what you need to do, vaguely. Try putting a breakpoint on the following, ZwContinue (exceptions) and GetProcAddress, I think that one is obvious. Watch the GetProcAddress for what anti debug is used. Once you find the trick, look it up. I really dont want to give away to much. When I did it I made a script and added to it as I went along so when I restarted the app I didnt have to redo any work, or remember. I think you should be able to bypass it with this info.

P.S. @ Lena, Maybe work with the dll export tables so you dont have to use GetProcAddress, it will keep from easily identifying tricks. :wink:

Edited by What
Posted

hmm what a giveaway ;)

Posted (edited)
hmm what a giveaway ;)

Well, I was going to make a tutorial on unpacking it the right way, but I am not sure if I should or if I am too lazy to.

Edited by What
Posted

Figured out my bsod... firewall was causing it.

Now, I still can't get anywhere... I figured to bp GetProcAddress before , but I can't get it to go even that far. It just runs around in the loops/obfuscation forever and never starts to load any API's or anything.

:/

Posted (edited)
Figured out my bsod... firewall was causing it.

Now, I still can't get anywhere... I figured to bp GetProcAddress before , but I can't get it to go even that far. It just runs around in the loops/obfuscation forever and never starts to load any API's or anything.

:/

Just when I have deleted this pain in the arse unpackme you guys suddenly become interested in it again. :kick:

Thanks What for that info. I had given up on getting it to run in Olly as Lena told me that everyone that had unpacked was using loader, except for one person and that is our resident memeber syk071c whom has of yet to divulge any further info.

Pavka also said to me that Softice is the way to go but now I just might download again and see if I get anywhere with Whats' info.

Edited by vinnie
Posted
I had given up on getting it to run in Olly as Lena told me that everyone that had unpacked was using loader, except for one person and that is our resident memeber syk071c whom has of yet to divulge any further info.

Pavka also said to me that Softice is the way to go...

I dont have a problem running under olly, if you had to use softice, noone with a newer computer could unpack it. No real plugin setup is needed.

Posted (edited)
I had given up on getting it to run in Olly as Lena told me that everyone that had unpacked was using loader, except for one person and that is our resident memeber syk071c whom has of yet to divulge any further info.

Pavka also said to me that Softice is the way to go...

I dont have a problem running under olly, if you had to use softice, noone with a newer computer could unpack it. No real plugin setup is needed.

Agreed.

i don't use Softice and I haven't unpack it yet. I was just sharing the info I had gathered for the sake of the members who had asked about the clues that Lena gave me. Your method is much appreciated as I have really wanted to unpack this but was just not good enough.

Let me also put both my hands up HIGH for any tutorial you may or may not write.

Edited by vinnie
Posted

Here's my contribution

I thought it was the same version as the first

nice tricks lena. thanks

dumped_.zip

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...