Jump to content
Tuts 4 You

[Unpackme] WinLicense v2.2 x64


Aguila

Recommended Posts

Restoring the imports was possible, because there were only two (and I unpacked the other file). I couldn't do it when there were more virtualized imports...

Bypassing the debug detections was easy :) I just used TitanHide (+ 'dbh' command, which does basic PEB hiding).

Greetings,

Mr. eXoDia

EDIT: attached file

WLUnpackmeStandard_dump_new_size_SCY.rar

Edited by Mr. eXoDia
  • Like 2
Link to comment
Share on other sites

Very nice! I didn't expect that.


 


And here is some max protection sample. Ultra anti-debug, will your TitanHide work? :showoff:


 


TIGER64 (Black)


WLUnpackmeMax.rar

Edited by Aguila
Link to comment
Share on other sites

Hi Aguila :


thanks for unpack test file ,but I think it is not a big deal :sorry:   For the first unpack me.


2 steps to unpack it just :sweat:


here a tut on how to unpack by IDA 6.1


https://drive.google.com/file/d/0B402C-bcZm3lNG01Q29VMXpWSzA/edit?usp=sharing


 


For me I solve the first one ,other file which need to work with hide debugger on x64 , I think I need more practice :smartass: .


 


I think Mr. eXoDia is rocker in x64 now :yes:


Edited by ahmadmansoor
  • Like 4
  • Thanks 1
Link to comment
Share on other sites

Thanks for the tutorial ahmadmansoor.


 


Most people will not be able to do this, because they don't have OllyDbg and Olly Script ;-)


Link to comment
Share on other sites

  • 3 weeks later...
  • 10 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...