LCF-AT Posted August 13, 2010 Posted August 13, 2010 Hello, so today I have created & protected a new UnpackMe for you. I added also some detect stuff [easy level]. So it should run normal with [mouse double click] and also in a normal basic protected Olly. Have fun. greetz ENIGMA 2.05 UnpackMe.rar 1
Teddy Rogers Posted August 13, 2010 Posted August 13, 2010 The [unpackme] tag has been added to your topic title. Please remember to follow and adhere to the topic title format - thankyou! [This is an automated reply]
EvOlUtIoN Posted August 14, 2010 Posted August 14, 2010 Good! I will take a look on it for sure. I'm in holidays now, but i hope t have time for it.
Ronar22 Posted August 16, 2010 Posted August 16, 2010 (edited) Tested on Win xp Sp2 & Win 7 UnPacked.rar Edited August 16, 2010 by Ronar22
Ronar22 Posted August 16, 2010 Posted August 16, 2010 @hepL3r : can u post the rva where the exception happens ?@blackpirate : thnx for testing.
LCF-AT Posted August 16, 2010 Author Posted August 16, 2010 @ Ronar22 Ah ok I see it. But,you did not rebuild any real code so you have choosen the simplest way and you just added the VM. So the problem in this case is that you have NO real code.Lets say you need to patch something like a unregistered target to a registered target [patch xy etc] what then? So if you can then try to rebuild [translate] the VM back to real code. ---------------------00421997 JMP 007CA833 0042199C DEC DWORD PTR DS:[EDI]0042199E PUSHFD0042199F INC ESI004219A0 JG SHORT 00421A00 004219A2 OR AL,CH004219A4 MOV EBP,9BDF8655004219A9 CMP BYTE PTR DS:[EDI+18],AH004219AC JNS SHORT 00421945 004219AE MOV BL,27004219B0 MOV AH,0F2004219B2 AND DWORD PTR SS:[EBP+9533EAD6],E>004219B8 POP SS 004219B9 LOOPD SHORT 004219D1 004219BB ??? 004219BC IN AL,0E4 004219BE SUB AL,0EA004219C0 MOV FS,WORD PTR DS:[EDX] 004219C2 JS SHORT 004219BE 004219C4 PUSH EBP004219C5 OR BYTE PTR DS:[EDI+76],FFFFFFF6004219CA IN AL,DX 004219CB STD004219CC PREFIX REPNE: 004219CD CDQ004219CE ADC BYTE PTR DS:[CC71CC24],DL004219D4 PUSH ESI-------------------------00421997 XOR EAX,EAX00421999 PUSH 00042199B CMP DWORD PTR SS:[ESP+8],EAX0042199F PUSH 1000004219A4 SETE AL004219A7 PUSH EAX004219A8 CALL DWORD PTR DS:[4290BC] ; kernel32.HeapCreate004219AE TEST EAX,EAX004219B0 MOV DWORD PTR DS:[436580],EAX004219B5 JE SHORT 004219CC 004219B7 CALL 00421C40 004219BC TEST EAX,EAX004219BE JNZ SHORT 004219CF 004219C0 PUSH DWORD PTR DS:[436580]004219C6 CALL DWORD PTR DS:[4290C0] ; kernel32.HeapDestroy004219CC XOR EAX,EAX004219CE RETN004219CF PUSH 1004219D1 POP EAX 004219D2 RETN There are more than 18300 commands which you need to rebuild. greetz
LCF-AT Posted August 20, 2010 Author Posted August 20, 2010 @ Evoso what happend?If nothing happend [no message] then you can be detected without to get a message by the unpackme.So I added some custom names & driver checks.Maybe you can check what you have running on your system.Try to close / unload other stuff if loaded.So the unpackme should then start.greetz
EvOlUtIoN Posted August 21, 2010 Posted August 21, 2010 I changed my mahine and now i can run it... But there are tons of code to rebuild :S
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now