Posted August 21, 201213 yr this is a small easy unpackme good luck on unpacking it and tell me your opinion on it unpackme.rar Edited August 21, 201213 yr by mm10121991
August 24, 201213 yr Here ya go: Clean dump everything returned to the original code and encryption removed as well as the macro. http://www.2shared.c...TA7j2/dump.html No keygen I'm not that kind of guy. Though one could easily rip the algo. Was quite fun, not hard but it has everything for someone that wants to get introduced into unpacking. Simple redirected API's, a macro, obfuscated oep. Not so much for the hardcore unpacker though. Found it over @ arteam.. but seems raham beat me to it doing a clean unpack. regards, q dump.rar Edited August 24, 201213 yr by Teddy Rogers Attached file...
August 25, 201213 yr hey Raham\quosego i just unpack but how you fully remove the crypt by hand or there away to auto do it?
August 25, 201213 yr Well the oep obfuscation is only like 10 instructions interlaced with jumps. So that shouldn't be hard, simple manual copy paste. The other macro is a question of filtering out the useless functions and only retaining the original code which are only two/three instructions. It's obvious the PE header checking can be removed and then just dump the decrypted code to the exe.
January 13, 201312 yr 1. For me the serial was: 4848302. About the stolen OEP instructions was about 10 as mr. Q say : PUSH EBPMOV EBP,ESPPUSH -0x1PUSH 0x4050C0PUSH 0x402678MOV EAX,DWORD PTR FS:[0]PUSH EAXMOV DWORD PTR FS:[0],ESPSUB ESP,0x58PUSH 0x401242 Then i have 2 invalid imports:GetDlgItemTextAMessageBoxA Short video attached.The story.....rar Edited January 14, 201312 yr by GIV
January 14, 201312 yr At last i could unpacked. Tutorial added.Many thanks to GIV for his help. Tutorial.rar
January 24, 201312 yr Dumped, Size Reduced and Keygenned (well, really, I've ripped the algo ). This was funny to solve Solved.7z
Create an account or sign in to comment