Zool@nder Posted October 16, 2009 Posted October 16, 2009 PEspin 1.32use script to unpack then Spinano to fix nanomites
thisistest Posted October 18, 2009 Author Posted October 18, 2009 0041A18A 8907 MOV DWORD PTR DS:[EDI],EAX0041A18C EB 02 JMP SHORT LCGUnPac.0041A1900041A18E 02F5 ADD DH,CH0041A190 F9 STC0041A191 72 08 JB SHORT LCGUnPac.0041A19B0041C8FC 0000 ADD BYTE PTR DS:[EAX],AL0041C8FE 0000 ADD BYTE PTR DS:[EAX],AL0041C900 0000 ADD BYTE PTR DS:[EAX],AL0041C902 0000 ADD BYTE PTR DS:[EAX],AL0041C904 0000 ADD BYTE PTR DS:[EAX],AL0041C906 0000 ADD BYTE PTR DS:[EAX],AL0041C908 0000 ADD BYTE PTR DS:[EAX],AL0041C90A 0000 ADD BYTE PTR DS:[EAX],AL0041C90C 0000 ADD BYTE PTR DS:[EAX],AL0041C90E 0000 ADD BYTE PTR DS:[EAX],AL0041C910 0000 ADD BYTE PTR DS:[EAX],AL0041C912 0000 ADD BYTE PTR DS:[EAX],AL0041C914 0000 ADD BYTE PTR DS:[EAX],AL0041C916 0000 ADD BYTE PTR DS:[EAX],AL3E 8B 44 24 C4 3E 2B 44 24 C8 89 07 E9 3E D8 FF FF0041C8FC 3E:8B4424 C4 MOV EAX,DWORD PTR DS:[ESP-3C] ; ntdll.7C9300410041C901 3E:2B4424 C8 SUB EAX,DWORD PTR DS:[ESP-38]0041C906 8907 MOV DWORD PTR DS:[EDI],EAX0041C908 ^ E9 83D8FFFF JMP LCGUnPac.0041A1900041C90D 90 NOP0041ACF7 55 PUSH EBP 10041ACF8 EB 01 JMP SHORT LCGUnPac.0041ACFB0041ACFA 288B ECEB01E1 SUB BYTE PTR DS:[EBX+E101EBEC],CL0041ACFB 8BEC MOV EBP,ESP 20041ACFD EB 01 JMP SHORT LCGUnPac.0041AD000041ACFF E1 6A LOOPDE SHORT LCGUnPac.0041AD6B0041AD00 6A FF PUSH -1 30041AD02 EB 01 JMP SHORT LCGUnPac.0041AD050041AD04 1D 680C9F19 SBB EAX,199F0C680041AD05 68 0C9F1948 PUSH 48199F0C0041AD0A 812C24 FC4DD947 SUB DWORD PTR SS:[ESP],47D94DFC0041AD11 68 9166D60A PUSH 0AD666910041AD16 812C24 2941960A SUB DWORD PTR SS:[ESP],0A9641290012FFD4 00402568 LCGUnPac.004025680012FFD8 00405110 LCGUnPac.004051100012FFDC FFFFFFFF0041AD1D 64:A1 00000000 MOV EAX,DWORD PTR FS:[0] 60041AD23 EB 01 JMP SHORT LCGUnPac.0041AD260041AD26 50 PUSH EAX 70041AD27 EB 01 JMP SHORT LCGUnPac.0041AD2A0041AD29 216489 25 AND DWORD PTR DS:[ECX+ECX*4+25],ESP0041AD2A 64:8925 00000000 MOV DWORD PTR FS:[0],ESP 80041AD31 EB 01 JMP SHORT LCGUnPac.0041AD340041AD33 67:83EC 58 SUB ESP,58 ; Superfluous prefix0041AD34 83EC 58 SUB ESP,58 90041AD37 EB 01 JMP SHORT LCGUnPac.0041AD3A0041AD3A 53 PUSH EBX 100041AD3B EB 01 JMP SHORT LCGUnPac.0041AD3E0041AD3E 56 PUSH ESI 11 ; ntdll.7C9302280041AD3F EB 01 JMP SHORT LCGUnPac.0041AD420041AD42 57 PUSH EDI 12 ; KERNEL32.7C816FE70041AD43 EB 01 JMP SHORT LCGUnPac.0041AD460041AD46 8965 E8 MOV DWORD PTR SS:[EBP-18],ESP 130041AD49 EB 01 JMP SHORT LCGUnPac.0041AD4C0041AD4C FF15 BDDE4100 CALL DWORD PTR DS:[41DEBD] 14 ; KERNEL32.GetVersion0041AD52 EB 01 JMP SHORT LCGUnPac.0041AD550041AD55 33D2 XOR EDX,EDX 150041AD57 EB 01 JMP SHORT LCGUnPac.0041AD5A0041AD5A 8AD4 MOV DL,AH 160041AD5C EB 01 JMP SHORT LCGUnPac.0041AD5F0041AD5F 8915 90854000 MOV DWORD PTR DS:[408590],EDX0041AD65 EB 01 JMP SHORT LCGUnPac.0041AD680041AD68 8BC8 MOV ECX,EAX0041AD6A EB 01 JMP SHORT LCGUnPac.0041AD6D0041AD6D 81E1 FF000000 AND ECX,0FF0041AD73 EB 01 JMP SHORT LCGUnPac.0041AD760041AD76 890D 8C854000 MOV DWORD PTR DS:[40858C],ECX0041AD7C EB 01 JMP SHORT LCGUnPac.0041AD7F0041AD7F C1E1 08 SHL ECX,80041AD82 EB 01 JMP SHORT LCGUnPac.0041AD850041AD85 - E9 5A6BFEFF JMP LCGUnPac.004018E40041AD8A DF ??? ; Unknown command0041AD8B 0FA7 ??? ; Unknown command0041AD8D 3D 8E5A1FFC CMP EAX,FC1F5A8E004018E4 8DC0 LEA EAX,EAX oep near ; Illegal use of register004018E6 890D 88854000 MOV DWORD PTR DS:[408588],ECX004018EC C1E8 10 SHR EAX,10004018EF A3 84854000 MOV DWORD PTR DS:[408584],EAX004018F4 33F6 XOR ESI,ESI ; ntdll.7C930228004018F6 56 PUSH ESI ; ntdll.7C930228004018F7 E8 E4E8FFFF CALL LCGUnPac.004001E0004018FC 59 POP ECX ; KERNEL32.7C816FE70040189D 0000 ADD BYTE PTR DS:[EAX],AL oep0040189F 0000 ADD BYTE PTR DS:[EAX],AL004018A1 0000 ADD BYTE PTR DS:[EAX],AL004018A3 0000 ADD BYTE PTR DS:[EAX],AL004018A5 0000 ADD BYTE PTR DS:[EAX],AL55 8B EC 6A FF 68 10 51 40 00 68 68 25 40 00 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 83 EC 5853 56 57 89 65 E8 FF 15 BD DE 41 00 33 D2 8A D4 89 15 90 85 40 00 8B C8 81 E1 FF 00 00 00 89 0D8C 85 40 00 C1 E1 08 90oep GROUPBOX "考核要求", -1, 2, 43, 185, 63 LTEXT "一:必须要亲自手动脱壳!", -1, 8, 53, 137, 9 LTEXT "二:不准使用他人的脱壳机和脚本!", -1, 8, 64, 133, 8 LTEXT "三:不准与他人讨论或泄漏考题!", -1, 8, 77, 137, 8 LTEXT "四:需要提交详细的脱壳分析文档!", -1, 8, 90, 138, 10 ICON 102, 1000, 15, 110, 20, 20 PUSHBUTTON "吾爱破解技术论坛", 1001, 108, 111, 79, 19 CONTROL 105, 1002, "STATIC", SS_BITMAP | WS_BORDER, 0, 1, 189, 40iat.txt
frozenrain Posted October 26, 2009 Posted October 26, 2009 hi thisistest Do you want to join LCG,How did you get this program? thx
thisistest Posted October 27, 2009 Author Posted October 27, 2009 你很聪明!我们是一家人!You are very clever! We are family!
thisistest Posted October 27, 2009 Author Posted October 27, 2009 I believe that the snd very strong! No matter where as long as it learned something!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now