Jump to content
Tuts 4 You

[UnpackMe] - iChallengeYou UnpackMe #1


iChallengeYou

Recommended Posts

iChallengeYou

Hello all, Are you alone too with Christmas like me? And don't know what to do, then i will challenge you all for a new competition. I created a unpackme with selfmade code, so none protector is used, all coded by me. The goal is to find the original entrypoint, or make a running dump.


 


Goodluck and merry xmas  :rudolph: 


 


 


1. Gold: SHADOW785


2. Silver: SmilingWolf


3. Bronze: GIV


 


 


Note: The unpackme doesn't run in winXP for a unkown reason.


 


 


iChallengeYou UnpackMe #1.rar


Edited by iChallengeYou
  • Like 1
Link to comment
Share on other sites

iChallengeYou

Nice work shadow, although it wasn't that hard. You won the gold medal ;)


And yes the first layer is aspack to reduce the filesize.

Link to comment
Share on other sites

iChallengeYou

Very easy.

Some stolen imports ... (i'm in a quick rush) ....

 

Probably you had a very quick rush because there are no stolen imports. Also the file is not unpacked correctly, you just unpacked the first layer which is Aspack for filesize reducing :P

Link to comment
Share on other sites

Sure.


The OEP is:



 


005F74C0



But strange... under XP SP3 your file does not run ( i have unpacked the first layer under 7 X64 and used the ESP stuff).


Was my mistake that i have not double checked if is the final OEP not the second protector OEP.


Take a look in attach. I have made a video for you.


 


Desktop.7z

Link to comment
Share on other sites

iChallengeYou

Yes as I told in the first post for a unkown reason the packed file won't run in winxp, the unpacked does.


But thanks for spending time to my challenge :)


Link to comment
Share on other sites

iChallengeYou

This time you got the rigth oep, congrats for that :) , but you modified (or destroyed) the import-table which is not needed, so your dump still not running here.


Link to comment
Share on other sites

iChallengeYou

Nice job SmilingWolf!


 


Giv, the dump is finally running, so good job :)


But i still do not understand why you touch the imports, i didn't modified/protected the import-table at all.


 


I will edit the first post to rank you, and be ready for the next challenge soon ;)


Edited by iChallengeYou
Link to comment
Share on other sites

Or i'm stupid or Win 7 does something strange to imports.


If i did not patch that address the imports are going crazy to other locations as it should be.


Noticed that to a PEP 5 unpackme also.


XP is way better to unpack than 7.


Link to comment
Share on other sites

Nice job SmilingWolf!

Giv, the dump is finally running, so good job :)

But i still do not understand why you touch the imports, i didn't modified/protected the import-table at all.

I will edit the first post to rank you, and be ready for the next challenge soon ;)

Next time do a unpackme that runs on XP.
Link to comment
Share on other sites

iChallengeYou

Next time do a unpackme that runs on XP.

 

Don't blame me, i can't help that you can't handle =>win7 :)

 

But for the next challenge i hope the xp issue is solved for then.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...