Jump to content
Tuts 4 You

Enigma Protector 5.2


Go to solution Solved by icarusdc,

Recommended Posts

Posted
On 4/21/2016 at 10:11 AM, icarusdc said:

Hi,

The steps I take for unpack this:

1. Change HWID. I used LCF-AT's script from here

2. VM Fixing and OEP Rebuilding. I used LCF-AT's script from here.

3. File Optimizing. I used SHADOW_UA's method from here.

Unpacked files: here

 

Salam.

im new ...

video tutorial plz...

  • 1 month later...
Posted

How to do that please? I'm newbie , can someone explain for me ? ( I can fast learn )

  • 3 months later...
Posted

has any one devirtualize the VM CODE

  • 7 months later...
Posted (edited)
On 7/19/2016 at 9:15 AM, GIV said:

Here are 2 more unpackmes with Enigma 5.4.

OEP is not virtualized so for you it must be easy to get the point.

 

Original.rar

Can you or someone help to teach that how to extract files from enigma protector protected files realy intrested but I don't have a lot if knowledge about scripts if possible please will help me to much... thanks PM me please...or faizan453@gmail.com

Edited by faizan453
Info
Posted
On 5/12/2016 at 6:15 PM, GautamGreat said:

Yes it is working like PRE_CHECKER_PATCH 

I updated the script now

Now script can Fix VM Api very fast

http://wikisend.com/download/212166/

Can you please update download link for script... 

  • 4 years later...
Posted

Hello Everyone, can anyone here teach me how to unpack Enigma 5.X ? I need help

  • 8 months later...
Sean the hard worker
Posted

Is this still possible to bypass the HWID?

I can't do it, it shows the integrity failure message.

Please check it.

I'm using

Edition    Windows 10 Enterprise
Version    22H2
Installed on    ‎31/‎05/‎2023
OS build    19045.3693
Experience    Windows Feature Experience Pack 1000.19053.1000.0
 

 Enigma Protector v5.2 unpackme by giv.zip

Regards.

sean.

  • Like 1
Sean the hard worker
Posted (edited)
On 1/11/2024 at 11:05 PM, windowbase said:

Is this still possible to bypass the HWID?

I can't do it, it shows the integrity failure message.

Please check it.

I'm using

Edition    Windows 10 Enterprise
Version    22H2
Installed on    ‎31/‎05/‎2023
OS build    19045.3693
Experience    Windows Feature Experience Pack 1000.19053.1000.0
 

  Enigma Protector v5.2 unpackme by giv.zip 2.25 MB · 5 downloads

I just want to bypass HWID checking. so I used the LCF-AT's script. but no luck.

I need your attentions. please guide me to bypass it.

I used below script.

Quote

//////////////////////////////////////////////////////////////

//

//  HWID Patch & Password Bypass Script

//

//  Example Script for only this UnpackMe....

// 

//  The Enigma Protector-4.3-X32 [patch HWID and unpackme]

//

//  LCF-AT

//////////////////////////////////////////////////////////////

bphwc

bc

alloc 500

mov SECTION, $RESULT

var ID_HOOK


add ID_HOOK, 00A076F5


bphws ID_HOOK

esto

bphwc

mov [SECTION], #3135444445314245334346444144363842423736#

mov [SECTION+29], #608BF850E8AE06A27483F817750B61688050263DE9B876EDFDB9170000008BFABE0000B302F3A4EBE590#

gpa "lstrlenA", "kernel32.dll"

mov TEMP, $RESULT

eval "call {TEMP}"

asm SECTION+2D, $RESULT

gci ID_HOOK, DESTINATION

add SECTION, 29

eval "jmp {SECTION}"

asm ID_HOOK, $RESULT

sub SECTION, 29

////////////////////////////////

RUN:

esto

pause
////////////////////////////////

After executing the script, the HWID isn't changed in my case.

2024-01-14_183212.png.20d2402ba0b48bb36d66170f309e6d38.png

giv gave us this information.

Quote

HWID: 15DDE-1BE3C-FDAD6-8BB76
NAME: giv
SERIAL: CP4Q7-7J6PV-R8XLS-T3CNX-7AE9H-RKBA3-A2NWD-DU2KR-RBSXY-XAKNE-UX3NV-FUTVN-943K2-2JZ5B-LTFSS-KMNK5-R63AK-4ZLFS-L3T4Q

If I run the script in the ollydbg, it is not bypassed but just terminated.

Regards.

sean.

 

Edited by windowbase
adding words.
  • Like 1
Posted
On 1/11/2024 at 10:05 PM, windowbase said:

Is this still possible to bypass the HWID?

I can't do it, it shows the integrity failure message.

Please check it.

I'm using

Edition    Windows 10 Enterprise
Version    22H2
Installed on    ‎31/‎05/‎2023
OS build    19045.3693
Experience    Windows Feature Experience Pack 1000.19053.1000.0
 

  Enigma Protector v5.2 unpackme by giv.zip 2.25 MB · 7 downloads

Regards.

sean.

shfolder - Unpackme.zip

  • Sad 1
Sean the hard worker
Posted (edited)

I finally did it. I want a fine script. can anyone help me?

2024-01-15_061345.png.b6b58687fd94b2279c2176edcae85dca.png

I repeatedly changed my HWID into giv's HWID over 20 times.

I really need a script. show me the way.

-------------------------------------------------------------

Use @CodeExplorer's tool for the x86 target.

the EnigmaHWID Changer. It works well for this target.

https://forum.tuts4you.com/topic/44556-enigmahardwareid/

Regards.

sean.

Edited by windowbase
adding words.
  • Like 1
  • 2 months later...
Posted
On 1/15/2024 at 12:26 AM, windowbase said:

I finally did it. I want a fine script. can anyone help me?

2024-01-15_061345.png.b6b58687fd94b2279c2176edcae85dca.png

I repeatedly changed my HWID into giv's HWID over 20 times.

I really need a script. show me the way.

-------------------------------------------------------------

Use @CodeExplorer's tool for the x86 target.

the EnigmaHWID Changer. It works well for this target.

https://forum.tuts4you.com/topic/44556-enigmahardwareid/

Regards.

sean.

hi! can you share video/text manual? Im study that theme, my homework with version 6.5

thanks

Posted (edited)
2 hours ago, zhhh said:

hi! can you share video/text manual? Im study that theme, my homework with version 6.5

thanks

Your homework is cracking a commercial protection?$

and if it's ur hw as you said, you need to do it by yourself.

no cheating!

Edited by X0rby
  • Like 1
Posted
52 minutes ago, X0rby said:

Your homework is cracking a commercial protection?$

and if it's ur hw as you said, you need to do it by yourself.

no 

My homework is an unofficial crack

jackyjask
Posted

what the hell is unofficial crack?

  • Haha 2
Posted
22 hours ago, jackyjask said:

what the hell is unofficial crack?

enigma on a PE that installs an unsigned data cable driver 😁 I don't know how to explain it anymore 😇

  • 2 months later...
bmwcrux
Posted

8AC7D-F830C-69B66-FC54B

  • Like 1
  • 3 months later...
MaiquelPeters
Posted
On 21/04/2016 at 01:11, icarusdc said:

Oi,

Os passos que sigo para descompactar isto:

1. Altere o HWID. Usei o script do LCF-AT daqui

2. Conserto de VM e reconstrução de OEP. Usei o script do LCF-AT daqui .

3. Otimização de arquivo. Usei o método SHADOW_UA daqui .

Arquivos descompactados: aqui

 

Olá.

E se fosse um arquivo de 64 bits?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...