Jump to content
View in the app

A better way to browse. Learn more.

Tuts 4 You

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Featured Replies

Correct password a123-b567-2023!

OEP RVA :  55A4

MEP RVA  : 59CC

Module

IAT FIXED COMPLETELY

I suggest using a no-console application as an unpackme. 

DD.PNG.527ff9dff68d5ba6fe8085bf9fbf69df.PNG0ure.PNG.bdb152d11358e00f182d269dc4f36f56.PNG

Edit 2 : Added the FILE.

Keep Crying.exe

Edited by X0rby
added module entry point for the HATER, to make him keep crying

  • Replies 110
  • Views 57.4k
  • Created
  • Last Reply

Top Posters In This Topic

Most Popular Posts

  • @TRISTAN Pro: The point of the forums is to enable other people to learn about the protections and unpacking. When you post just an unpacked file, nobody learns anything. Would you please be so k

  • TRISTAN Pro
    TRISTAN Pro

    Tutorial for winlicence(This target): This tutorial work only for themida latest version,learn from @quosego and @LCF-AT . Load the target in ollydbg(I have made tutorial Here  for configura

  • lovejoy226
    lovejoy226

    I did it too. View this youtube video for the solution.   Regards. sean.

Posted Images

For those of you having a rant with each other, please take it up via PM.

Posts removed, please stay on topic.

Thank you...

Ted.

7 hours ago, Teddy Rogers said:

For those of you having a rant with each other, please take it up via PM.

Posts removed, please stay on topic.

Thank you...

Ted.

Ok thank yuo admin.👍

On 4/26/2023 at 1:13 AM, X0rby said:

Correct password a123-b567-2023!

OEP RVA :  55A4

MEP RVA  : 59CC

Module

IAT FIXED COMPLETELY

I suggest using a no-console application as an unpackme. 

DD.PNG.527ff9dff68d5ba6fe8085bf9fbf69df.PNG0ure.PNG.bdb152d11358e00f182d269dc4f36f56.PNG

Edit 2 : Added the FILE.

Keep Crying.exe 219 kB · 3 downloads

Can you please create a video guide on how you were able to unpack this using x64dbg? Thank you!

  • 3 weeks later...
On 4/26/2023 at 10:13 AM, X0rby said:

Correct password a123-b567-2023!

OEP RVA :  55A4

MEP RVA  : 59CC

Module

IAT FIXED COMPLETELY

I suggest using a no-console application as an unpackme. 

DD.PNG.527ff9dff68d5ba6fe8085bf9fbf69df.PNG0ure.PNG.bdb152d11358e00f182d269dc4f36f56.PNG

Edit 2 : Added the FILE.

Keep Crying.exe 219 kB · 11 downloads

How did u bypass themida anti debugger for x32dbg? i can't find a solution for x32dbg, i use OD wit StrongOD and Scylla. Can u share some info how to unpack this version? woud be really nice. Thanks.

  • 3 weeks later...

@boot Can yuo upload the real target please?without protection for learning something if yuo can thanks in advanced.

And source code for creating loader for TMD or VMP?

  • Author

This is the original EXE sample without any protections. To make a Loader86, you need to know about DLL Hook /API Hook... Of course, a faster way is to use the existing patch tool.

 

EXE_Original_x86.rar

Try this one.

Winlicense Test.zip

Untitled.png.fd595815855e343ab83ca4243f2e332f.png.0d6673e12998fc7828ddae2db43f9670.png

sean.

isn't it possible to just bypass hwid ?

your solution is whole unpack .

i just wanted to bypass hw license checking.

anyway good job.

how did you solve this? can you describe details for us ?

sean.

 

Edited by windowbase

When i try to do Tristan pro's way, I get the debugger found message.

though I set up plugin as like this.

 

  • Author
40 minutes ago, windowbase said:

When i try to do Tristan pro's way, I get the debugger found message.

though I set up plugin as like this.

For x64Dbg, Just try to remove ScyllaHide plugin and set SharpOD 0.6d  plugin likes this...

2023-06-16_173238.jpg.306c4cf01807c70a2ff11cd8b9c1ece2.jpg

okay, many thanks. and so many stopping at the compare commads, do I have to manipulate values manually?

Tristan Pro said to automate the process, inlining. how do I inline codes in the block?

sean.

Edited by windowbase

  • Author

You should find CMP_ADDRESS and modify it... This is similar to how x86 is handled, so you'll need to try it yourself.

EDIT:

You need to download and refer to Tristan Pro's tutorial, x64 is similar to x86, and you need to add the "Multiline Ultimate Assembler" plugin to x64dbg...

Your target does not HWID_Lock my computer, it can run directly, and unpack is possible, so I do unpack...

I remember there was a download link on this topic. Please contact the uploader for a backup of the tutorial...

Edited by boot
Add...

like this? mov edx,edi ?

sean.

11 minutes ago, boot said:

You need to download and refer to Tristan Pro's tutorial, x64 is similar to x86, and you need to add the "Multiline Ultimate Assembler" plugin to x64dbg...

can you link Tristan Pro's tut address?

I just wanna bypass other target's hwid lock. can you link the address ? any Tristan Pro's video tut or document tut are there ?

sean.

My 3rd challenge in this thread...😏

Unpacked.

Original Size restored. 107kb

Better_Size.exe

1 minute ago, X0rby said:

My 3rd challenge in this thread...😏

Unpacked.

Original Size restored. 107kb

 

Good job. @X0rby.

  • Author
4 minutes ago, windowbase said:

I just wanna bypass other target's hwid lock. can you link the address ? any Tristan Pro's video tut or document tut are there ?

sean.

The tutorial link has been removed, you need to re-contact the uploader to get the backup of the tutorial...

25 minutes ago, boot said:

I remember there was a download link on this topic. Please contact the uploader for a backup of the tutorial...

okay.thanks.

Sean, go PM I'll help you with somethings..

Edited by X0rby

I upload this locked to others version but i wonder why i can't run this in my machine either.

Winlicense test.zip

sean.

2 hours ago, boot said:

The tutorial link has been removed, you need to re-contact the uploader to get the backup of the tutorial...

As I said my laptop was broken,so I don't have any script and all my data was disappear so I don't have even one.

So may be someone send it to me and I will attach it or check my tutorial in text Here just ask to someone upload asm.txt and yuo will get it.

Create an account or sign in to comment

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.