thisistest Posted September 20, 2009 Posted September 20, 2009 NoobyProtect 1.6.401 http://filebeam.com/989eb33f8cb65fb2c3acd1b13944a2152 http://www.plunder.com/NoobyProtect-1-6-40-rar-download-54fdc10191.htm3: NoobyProtect 1.6.40.rar />http://www.filefactory.com/file/a0a02e1/n/NoobyProtect_1_6_40_rar 611180cb07516f3e0e95d87b1772ae99 NoobyProtect 1.6.40.exe md5 delphiNoobyProtect 1.6.40.rar 1
Teddy Rogers Posted September 20, 2009 Posted September 20, 2009 Demo version or full and what features were enabled?Ted.
Teddy Rogers Posted September 20, 2009 Posted September 20, 2009 The [unpackme] tag has been added to your topic title. Please remember to follow and adhere to the topic title format - thankyou! [This is an automated reply]
thisistest Posted September 20, 2009 Author Posted September 20, 2009 NoobyProtect SE 1.6.4.0 Demo All protection !0061496B > $ E8 1D000000 call NoobyPro.0061498D ; PUSH ASCII "NoobyProtect SE 1.6.4.0 Demo"00614970 . 4E 6F 6F 62 7>ascii "NoobyProtect SE "00614980 . 31 2E 36 2E 3>ascii "1.6.4.0 Demo",00061498D >^ EB 8B jmp short NoobyPro.0061491A0061498F 75 db 75 ; CHAR 'u'00614990 F0 db F000614991 66 db 66 ; CHAR 'f'00614DE7 >^\0F84 40FCFFFF je NoobyPro.00614A2D00614DED > 81E8 00000100 sub eax,10000 ; UNICODE "ALLUSERSPROFILE=C:\Documents and Settings\All Users"00614DF3 .^ E9 13FCFFFF jmp NoobyPro.00614A0B00614DF8 C5 db C500614DF9 51 db 51 ; CHAR 'Q'00614DFA C1 db C100614DFB A0 db A000405BB0=<jmp.&kernel32.GetModuleHandleA>
AnTiCDLoCK Posted September 20, 2009 Posted September 20, 2009 (edited) OEP : 00613602Stolen OEP shoud be Same:PUSH EBPMOV EBP,ESPADD ESP,-10MOV EAX,00463710CALL 00405C74MOV EAX,DWORD PTR DS:[4658EC]MOV EAX,DWORD PTR DS:[EAX]CALL 0044D3D8MOV ECX,DWORD PTR DS:[4659D0]MOV EAX,DWORD PTR DS:[4658EC] MOV EAX,DWORD PTR DS:[EAX]MOV EDX,DWORD PTR DS:[463528]CALL 0044D3F0MOV EAX,DWORD PTR DS:[4658EC]MOV EAX,DWORD PTR DS:[EAX]CALL 0044D470CAll 00403D9C--------------try to fix Imports ... . Edited September 20, 2009 by AnTiCDLoCK
thisistest Posted September 20, 2009 Author Posted September 20, 2009 So easily Gaoding it?Wait unpackingSource oep 00463910 00463910 > $ 55 push ebp00463911 . 8BEC mov ebp,esp00463913 . 83C4 F0 add esp,-1000463916 . B8 10374600 mov eax,004637100046391B . E8 5423FAFF call 00405C7400463920 . A1 EC584600 mov eax,dword ptr ds:[4658EC]00463925 . 8B00 mov eax,dword ptr ds:[eax]00463927 . E8 AC9AFEFF call 0044D3D80046392C . 8B0D D0594600 mov ecx,dword ptr ds:[4659D0] 00463932 . A1 EC584600 mov eax,dword ptr ds:[4658EC]00463937 . 8B00 mov eax,dword ptr ds:[eax]00463939 . 8B15 28354600 mov edx,dword ptr ds:[463528] 0046393F . E8 AC9AFEFF call 0044D3F000463944 . A1 EC584600 mov eax,dword ptr ds:[4658EC]00463949 . 8B00 mov eax,dword ptr ds:[eax]0046394B . E8 209BFEFF call 0044D47000463950 . E8 4704FAFF call 00403D9C00463955 . 8D40 00 lea eax,dword ptr ds:[eax]
EvOlUtIoN Posted September 21, 2009 Posted September 21, 2009 are u sure OEP was like this? Anyway, this is one of the best protector i ever seen, waiting to try in an faster pc, since here it is hard for me to load it.
AnTiCDLoCK Posted September 21, 2009 Posted September 21, 2009 you can test it :set a hwbp on 00613602write that opcodes and press F9regards.
baguette Posted September 21, 2009 Posted September 21, 2009 one of the best protector..faster pc..hard for me to load it.wait, what?
EvOlUtIoN Posted September 22, 2009 Posted September 22, 2009 Sorry?Of course i was talking about medium protectors, not the high level ones.
EvOlUtIoN Posted September 23, 2009 Posted September 23, 2009 Ok i figured all on it...but rebuild all code can take days, not only hours. Very good import portection, and it is nice to see how good you protected oep and near procedures.I hope to have time to complete this.
thisistest Posted September 24, 2009 Author Posted September 24, 2009 set a hwbp on 00613602write that opcodes and press F9Not Breakpoint 00613602
thisistest Posted October 2, 2009 Author Posted October 2, 2009 00613602 > /55 push ebp00613603 . |EB 72 jmp short NoobyPro.0061367700613605 |E0 db E000613606 |6B db 6B ; CHAR 'k'00613607 |FB db FB00613608 |9E db 9E00613609 |6D db 6D ; CHAR 'm'0061360A |83 db 830061360B |FF db FF0061360C |7B db 7B ; CHAR '{'0061360D |EB db EB0061360E |8E db 8E0061360F |7D db 7D ; CHAR '}'00613610 |88 db 8800613611 |A6 db A600613612 |33 db 33 ; CHAR '3'00613613 |A3 db A300613614 |C6 db C600613615 |35 db 35 ; CHAR '5'00613616 |D1 db D100613617 |CB db CB00613618 |41 db 41 ; CHAR 'A'00613619 |D1 db D10061361A |B0 db B00061361B |43 db 43 ; CHAR 'C'0061361C |A5 db A50061361D |0C db 0C0061361E |18 db 180061361F $ |8D6424 04 lea esp,dword ptr ss:[esp+4]00613623 . |E9 DD020000 jmp NoobyPro.0061390500613628 |D5 db D500613629 |5C db 5C ; CHAR '\'0061362A |F2 db F20061362B |95 db 950061362C |64 db 64 ; CHAR 'd'0061362D |97 db 970061362E |B3 db B30061362F |43 db 43 ; CHAR 'C'00613630 |D3 db D300613631 . |B6 45 mov dh,4500613633 . |E4 B8 in al,0B800613635 . |35 A5CC3FE9 xor eax,E93FCCA50061363A . |73 02 jnb short NoobyPro.0061363E0061363C . |EC in al,dx0061363D . |9D popfd0061363E > |AD lods dword ptr ds:[esi]0061363F > |E8 E8E7E4FF call NoobyPro.00461E2C00613644 . |8BE5 mov esp,ebp00613646 . |5D pop ebp00613647 . |C2 0800 retn 80061364A .-|E9 1AFEE4FF jmp NoobyPro.004634690061364F |C2 db C200613650 > |8B00 mov eax,dword ptr ds:[eax]00613652 . |EB 59 jmp short NoobyPro.006136AD00613654 |A9 db A900613655 |B1 db B100613656 > |8B0D D0594600 mov ecx,dword ptr ds:[4659D0] ; NoobyPro.00466BE00061365C . |EB 31 jmp short NoobyPro.0061368F0061365E |C5 db C50061365F |4F db 4F ; CHAR 'O'00613660 |DF db DF00613661 |BA db BA00613662 |49 db 49 ; CHAR 'I'00613663 |95 db 9500613664 |98 db 9800613665 |1B db 1B00613666 |8B db 8B00613667 |EE db EE00613668 |1D db 1D00613669 |BC db BC0061366A |C5 db C50061366B |55 db 55 ; CHAR 'U'0061366C |C5 db C50061366D |AC db AC0061366E |5F db 5F ; CHAR '_'0061366F |EB db EB00613670 |76 db 76 ; CHAR 'v'00613671 |EB db EB00613672 |7B db 7B ; CHAR '{'00613673 |1E db 1E00613674 |ED db ED00613675 |42 db 42 ; CHAR 'B'00613676 |3D db 3D ; CHAR '='00613677 > |8BEC mov ebp,esp00613679 . |83C4 F0 add esp,-100061367C . |C7C0 10374600 mov eax,NoobyPro.0046371000613682 . |E8 ED25DFFF call NoobyPro.00405C7400613687 . |8B05 EC584600 mov eax,dword ptr ds:[4658EC] ; NoobyPro.00466BB00061368D .^|EB C1 jmp short NoobyPro.006136500061368F > |8B05 EC584600 mov eax,dword ptr ds:[4658EC] ; NoobyPro.00466BB000613695 . |EB 22 jmp short NoobyPro.006136B900613697 |DB db DB00613698 |49 db 49 ; CHAR 'I'00613699 |D9 db D90061369A |B8 db B80061369B |4B db 4B ; CHAR 'K'0061369C |F8 db F80061369D |FC db FC0061369E |73 db 73 ; CHAR 's'0061369F >^|E3 86 jecxz short NoobyPro.00613627006136A1 .^|75 DA jnz short NoobyPro.0061367D006136A3 . |45 inc ebp006136A4 . |D141 20 rol dword ptr ds:[ecx+20],1006136A7 . |D362 1B shl dword ptr ds:[edx+1B],cl006136AA |9A db 9A006136AB . |7A F2 jpe short NoobyPro.0061369F006136AD > |E8 269DE3FF call NoobyPro.0044D3D8006136B2 .^|EB A2 jmp short NoobyPro.00613656006136B4 |AE db AE006136B5 |C0 db C0006136B6 . |A6 cmps byte ptr ds:[esi],byte ptr es:[edi]006136B7 . |D032 sal byte ptr ds:[edx],1006136B9 > |8B00 mov eax,dword ptr ds:[eax]006136BB . |E9 F2010000 jmp NoobyPro.006138B2006136C0 |19 db 19006136C1 |2C db 2C ; CHAR ','006136C2 > |E8 D506DFFF call NoobyPro.00403D9C006136C7 . |E9 20010000 jmp NoobyPro.006137EC006136CC |DF db DF006136CD |48 db 48 ; CHAR 'H'006136CE |DE db DE006136CF |B9 db B9006136D0 |48 db 48 ; CHAR 'H'006136D1 |E1 db E1006136D2 |CC int3006136D3 |58 db 58 ; CHAR 'X'006136D4 |CE db CE006136D5 |A9 db A9006136D6 |58 db 58 ; CHAR 'X'006136D7 |EF db EF006136D8 |8C db 8C006136D9 |1F db 1F006136DA |8F db 8F006136DB |EA db EA006136DC |19 db 19006136DD . |807A AC 15 cmp byte ptr ds:[edx-54],15006136E1 . |8A10 mov dl,byte ptr ds:[eax]006136E3 > |8B45 FC mov eax,dword ptr ss:[ebp-4]006136E6 . |8B50 48 mov edx,dword ptr ds:[eax+48]006136E9 . |8B45 FC mov eax,dword ptr ss:[ebp-4]006136EC . |8B80 78010000 mov eax,dword ptr ds:[eax+178]006136F2 . |E8 6DEEE4FF call NoobyPro.00462564006136F7 .^|E9 49FEFFFF jmp NoobyPro.00613545
thisistest Posted October 2, 2009 Author Posted October 2, 2009 (edited) 0052AD7D . 9D popfd0052AD7E . C3 retn0052AD7F 24 db 24 ; CHAR '$'7C824750 (kernel32.GetModuleHandleA) 0012FEF8 002002460012FEFC 7C824750 kernel32.GetModuleHandleA0012FF00 005928D9 NoobyPro.005928D9 来自 NoobyPro.0052AC170012FF04 000000000012FEFC 7C824750 kernel32.GetModuleHandleA0012FF00 005928D9 NoobyPro.005928D9 来自 NoobyPro.0052AC170012FF04 000000000012FF08 00000000 Edited October 2, 2009 by thisistest
LCF-AT Posted October 10, 2009 Posted October 10, 2009 Hello,here the first version of my unpacked file.So for me it runs and I hope it will run also on other systems.Just start the unpacked file and tell me plaese whether the file is working for you or not.Thanks.NoobyProtect 1.6.40_Unpacked.rar
Zool@nder Posted October 10, 2009 Posted October 10, 2009 Good work LCF-ATStill you're missing some thing, it runs but crashes after a very short timeanyway, good work as usual
quosego Posted October 10, 2009 Posted October 10, 2009 (edited) I really suggest fixing all the imports LCF-AT. Also one dll is not in the descriptor table.. As well as the 00525E0D FF90 AD075AFD CALL DWORD PTR DS:[EAX+FD5A07AD] ; GDI32.77E59F93 calls are not fixed. Also the obfu is not that impressive it seems.. Nice but not special. Should be easily removable. Very nice work, q. Edited October 10, 2009 by quosego
thisistest Posted October 10, 2009 Author Posted October 10, 2009 Update, Increased protection strengthNoobyProtect SE 1.6.6.0 (unpackme)00632257 > $ E8 1D000000 call 8_npse.00632279 ; PUSH ASCII "NoobyProtect SE 1.6.6.0 Demo"0063225C . 4E 6F 6F 62 7>ascii "NoobyProtect SE "0063226C . 31 2E 36 2E 3>ascii "1.6.6.0 Demo",000632279 >^ E9 DAFEFFFF jmp 8_npse.006321580063227E 50 db 50 ; CHAR 'P'0063227F DD db DD00632280 4D db 4D ; CHAR 'M'00632281 14 db 14Protection of the completion of: Protection of code size:1771520 Dealing with input reference:1819 Dealing with the implementation of the branch:2387 Treatment Function api :1412 file:------http://filebeam.com/7c1f2e494f99b02f0eb53091506d95d63bb72bdf846c706408154c8214db80b5 NoobyProtect SE 1.6.6.0 Demo.exe md5NoobyProtect SE 1.6.6.0 Demo.rar
thisistest Posted October 10, 2009 Author Posted October 10, 2009 Can not run my computer LCF-AT my friend!
LCF-AT Posted October 10, 2009 Posted October 10, 2009 Hi,ah ok and thanks for the feedback.So here my second try maybe this will run now for you.So for me it runs without to make trouble.Maybe someone can trace a little bit if the new unpacked file will not run for you to find whats wrong.So I have just XP to test it.@ quosegoHmm, so I think I have all what will used fixed.00525E0D | CALL DWORD PTR DS:[EAX+FD5A07AD] will also not used for me.ThanksNoobyProtect 1.6.40_Unpacked_2.rar
quosego Posted October 11, 2009 Posted October 11, 2009 (edited) If you got the dll's on the same imagebase it does.. However I don't..VM imports really need to be fixed. Both the call I mentioned;00527C0A FF90 7DFA3A9A CALL DWORD PTR DS:[EAX+9A3AFA7D] ; GDI32.77E59F93Which is getmodulehandla btw.. And VM exits at;00491F2F 9D POPFD00491F30 61 POPAD00491F31 C3 RETStack;0012F4A4 77F416F8 advapi32.77F416F8Both are good api's addresses at your place however they are not here.. regards,q. Edited October 11, 2009 by quosego
thisistest Posted October 11, 2009 Author Posted October 11, 2009 Can not runWindows Server 2003 !my friend!
Apakekdah Posted October 12, 2009 Posted October 12, 2009 Btw, what can make my olly crash every time i loaded this protector to my olly...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now