thisistest Posted December 29, 2009 Posted December 29, 2009 WinLicense again updated! Welcome Test @!Running a special card, in particular, slow, be patient!testMacros Information------------------VM Macros: 0CodeReplace Macros: 0ENCRYPT Macros: 0CLEAR Macros: 0CHECK_PROTECTION Macros: 0CHECK_CODE_INTEGRITY Macros: 0CHECK_REGISTRATION Macros: 0CHECK_VIRTUAL_PC Macros: 0Protection Options------------------Anti-Debugger: AdvancedAnti-Dumpers: ENABLEDEntry Point Obfuscation: ENABLEDResource Encryption: ENABLEDVMWare compatible: ENABLEDAPI-Wrapping Level: Level 2Anti-Patching: File PatchingMetamorph Security: ENABLEDMemory Guard: ENABLEDWhen Debugger Found: Display MessageApplication compression: ENABLEDResources compression: ENABLEDSecureEngine compression: ENABLEDAnti-File Monitor: ENABLEDAnti-Registry Monitor: ENABLEDDelphi/BCB form protection: ENABLEDRing-0 Protection: ENABLEDVirtual Machine Settings------------------------Number of Virtual APIs wrapped: 6API Virtualization Level: 3Entry Point Virtualization: 15 instructionsMulti Branch Technology: DISABLEDVirtual Machine Processor: Mutable CISC-2 processorNumber of CPUs: 1Opcode Type: Metamorphic - Level 2Dynamic Opcode: 20% DynamicAdvanced Protection Options---------------------------Encrypt Application: ENABLEDDLL plugin: DISABLEDExport Generators: ENABLEDKeep Trial Running: DISABLEDHide from PE scanners: Type 1.NET assemblies: ENABLEDActive Context: DISABLEDCustom Event: Add Manifest: Don't add manifestLaunch Application: 5 All protection options!test7.rartest8.rar
thisistest Posted December 29, 2009 Author Posted December 29, 2009 test5 All protection options/>http://www.multiupload.com/ZHYMC9DABM726d083eb1e09255bd74b54697eb62b8 test5.exe md5
LCF-AT Posted December 29, 2009 Posted December 29, 2009 Hi,here my unpacked files.The test5 file was a little bit to big so in this case have split it into 2 parts.I upload part 2 in the next post and also a free join tool.The test5 file also used PE AntiDump / check.greetztest7_Unpacked.rartest5_Unpacked_part01.exe.rar 1
LCF-AT Posted December 29, 2009 Posted December 29, 2009 Here comes part 2 of the unpacked test5 file and the join tool.@ thisistestMaybe you should use the next times some other targets so its not the best to use always the same you know.Thanks.PS: test8 does not run for me so its a .net target so no .net targets run on my system.greetztest5_Unpacked_part02.exe.rarJoin it with me.rar
quosego Posted December 29, 2009 Posted December 29, 2009 (edited) nice work..What is interesting however is that it virtualizes small API calls in delphi init and puts an antidump block in it, not something I've seen before.Not very useful, antidumps are public knowledge, however it is new. 00405C80 .-E9 CA572900 JMP test5_Un.0069B44F00405C85 7B DB 7B ; CHAR '{'00405C86 16 DB 1600405C87 BB DB BB00405C88 F8 DB F800405C89 17 DB 1700405C8A . 03 DB 0300405C8B . 30 51 49 ASCII "0QI"00405C8E CD DB CD00405C8F . A3 AC404600 MOV DWORD PTR DS:[4640AC],EAX ; test5_Un.00400000Which is actually a simple getmodulhandlea call and 2 movs. Edited December 29, 2009 by quosego
thisistest Posted December 30, 2009 Author Posted December 30, 2009 00468353 >- E9 A8330100 jmp test5_Un.0047B70000468358 F0:B8 10374600 lock mov eax,test5_Un.00463710 ; LOCK prefix is not allowed0046835E E8 11D9F9FF call test5_Un.00405C7400468363 - E9 16011C00 jmp test5_Un.0062847E0047B700 60 pushad0047B701 9C pushfd0047B702 50 push eax0047B703 54 push esp0047B704 6A 04 push 40047B706 68 00100000 push 10000047B70B 68 00004000 push test5_Un.00400000 ; ASCII "MZP"0047B710 FF15 78B74700 call dword ptr ds:[<&kernel32.VirtualPro>; kernel32.VirtualProtect0047B716 58 pop eax0047B717 C7C6 00B24700 mov esi,test5_Un.0047B200 ; ASCII "MZP"0047B71D C7C7 00004000 mov edi,test5_Un.00400000 ; ASCII "MZP"0047B723 C7C1 00050000 mov ecx,5000047B729 F3:A4 rep movs byte ptr es:[edi],byte ptr ds:[>0047B72B C705 53834600 5>mov dword ptr ds:[<ModuleEntryPoint>],83>0047B735 C705 57834600 C>mov dword ptr ds:[468357],10B8F0C40047B73F 9D popfd0047B740 61 popad00468353 > 55 push ebp00468354 8BEC mov ebp,esp00468356 83C4 F0 add esp,-1000468359 B8 10374600 mov eax,test5_Un.004637100046835E E8 11D9F9FF call test5_Un.00405C7400468363 - E9 16011C00 jmp test5_Un.0062847Etest7 and test5 can run my system!strong!You further progress, but it is difficult for me!
thisistest Posted December 31, 2009 Author Posted December 31, 2009 test8 Microsoft Visual C# / Basic .NET Source hereWindowsFormsApplicat99.rar
thisistest Posted January 1, 2010 Author Posted January 1, 2010 test5_Unpacked Backup/>http://www.multiupload.com/VCABPHNBSJ/>http://www.multiupload.com/XQ19U24NP0 Themida 2.08 all Protection Options test!@LCF-ATI think you can make a tutorial WinLicense all protected, or update your script! Make more friends, to get to learn, thank you!
LCF-AT Posted January 1, 2010 Posted January 1, 2010 Hello, here my unpacked Themida 2.08 all Protection file. So this time the original file runs very slow on my system!Some kind of slow motion.This is real bad. Maybe someone can also DL this UnpackMe and test it to see whether you get the same slow motion result or not. So I have test it with win XP and win 2000 and I get the same slow result with the original and unpacked file. No-one will protect a file / target on this way like in this UnpackMe case. Anyway.So here my split files so its again a bit large + VM section. Rename the Themida all Unpacked_A.rar file to Themida all Unpacked_A.001 Update your script!Hhmmm,good idea! But it would be better if someone creates a new Unpacker tool like quosego alraedy said. I have no idea about coding tools etc but someone else could do this so the knowledge is available and public. greetz Themida all Unpacked_A.rar
LCF-AT Posted January 1, 2010 Posted January 1, 2010 Here the second part and the join tool.Rename the Themida all Unpacked_B.rar to Themida all Unpacked_A.002Join this 2 files then you have the full rar file which you then can unpack.greetzThemida all Unpacked_B.rarJoin it with me.rar
thisistest Posted January 2, 2010 Author Posted January 2, 2010 Themida 2.08 Unpacked run my system(xp), strong!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now