![]() |
SVKP 1.3x unpacking
Hi,
I'm trying to unpack the Speed Optimizer from Speedbit. http://speedoptimizer.com/ It's packed with SVKP 1.3x & i managed to find oep as 4604b2. What about it and the stolen bytes. Pls help. The UC2004's SVKP explorer don't works. |
i-speed optimizers are trush, forget tham;
is other any good program protected with svkp.. about stolen bytes many times explaned, use search; |
Formik maybe (dunno what is for you "good program")
_http://www.formik.rksoft.sk/ _http://www.rksoft.sk/Download/formik.exe |
speedoptimizer
Looks like 89 stolen bytes , oep == 00460459 |
sorry, forgot about this thread..
so i dld-ed Formik. That was Delphi-app, so at OEP are ripped just few Delphi-standart instructions.. also there are 2 SVKP_Imported calls; (1st= mov eax,1; ret4; 2nd = ret) some decryptor calls, from where last 2 decrypted code conteins PE-header check. |
Formik
Code:
....stolen bytes |
If someone has "Formik v2.16a" please PM me. Can't find that version anywhere (stolen bytes above are for this version)
|
hosiminh,
you want learn unpacking, or only unpack that program? look at any Delphi567 program & you will able discover OEP bytes without any tracing-debugging.. (i can upload unpacked.ace 466kb, but is it correct for forum?) |
2.16b stolen
I did check the stolen for the last version; 2.16b, and the correct stolen are:
004F9B9C 55 PUSH EBP 004F9B9D 8BEC MOV EBP,ESP 004F9B9F 83C4 F0 ADD ESP,-10 004F9BA2 53 PUSH EBX 004F9BA3 B8 64974F00 MOV EAX,Formik.004F9764 the two versions are right after each other , so I assume there is no difference between the two as far as the stolen is concerned. |
Thanks you both for replying.
I saw at the fake oep (004F9BA8 CALL Formik.00407320) (just where stolen bytes ends) that EAX == 004F9764 (and in stack window: 0012FFC4 7C816D4F RETURN to kernel32.7C816D4F , at 7C816D4F is EAX PUSH-ed into stack ) but i was unsure if i have the right one. |
the last push in the stack is the ebx register = 7ffdf000
regards. |
| All times are GMT +8. The time now is 09:01. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX