Jump to content
Tuts 4 You

[unpackme] VMProtect


xuhw

Recommended Posts

Hello xuhw,

there are not much to explain.There is also no redirection.

Just set BP on GetModuleHandleA and trace over ret 4 and now you can rebuild the OEP bytes.

PUSH EBP
MOV EBP,ESP
ADD ESP,-10
MOV EAX,4B66A4 // <--Look EBX
CALL 00406E80
JMP 005348D4

Set BP on ret and run.

00406E80   PUSH EBX  // <-- Call 00406E80
00406E81 MOV EBX,EAX
00406E83 XOR EAX,EAX
00406E85 MOV DWORD PTR DS:[4B70C4],EAX
00406E8A PUSH 0
00406E8C CALL 00406DBC // GMHA
00406E91 MOV DWORD PTR DS:[4BB668],EAX // <--EBX holds value of EAX before.Here you are.
00406E96 MOV EAX,DWORD PTR DS:[4BB668]
00406E9B MOV DWORD PTR DS:[4B70D0],EAX
00406EA0 XOR EAX,EAX
00406EA2 MOV DWORD PTR DS:[4B70D4],EAX
00406EA7 XOR EAX,EAX
00406EA9 MOV DWORD PTR DS:[4B70D8],EAX
00406EAE CALL 00406E74
00406EB3 MOV EDX,4B70CC
00406EB8 MOV EAX,EBX
00406EBA CALL 004049D4
00406EBF POP EBX
00406EC0 RETN <------ here

Trace over and now you have the back jump address for the JMP above to rebuild your OEP.

Thats all here.

greetz

Link to comment

The [unpackme] tag has been added to your topic title.

Please remember to follow and adhere to the topic title format - thankyou!

[This is an automated reply]

Link to comment

Hi,

the same here.No redirection.Just break on "ThunRTMain" and rebuild....

004011A9   PUSH 4012C0			   ; VB5!
004011AE CALL 00401122 ; JMP to MSVBVM60.ThunRTMain

Thats all.

greetz

Link to comment

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...