![]() |
Unpackme
1 Attachment(s)
just an unpackme from me,read the rules in zip...U may post the solution here,or just tell us the link to find it...
difficulty:2/10 |
and something more...
I packed it in XP SP1 English and not tested in any other...But normally would run fine...
|
1 Attachment(s)
ok done...but i never post a solution because it packed with telock...u can find a lot of tutorials on this packer and u can even find an unpacker for it...
|
well done
thankz for the time man...
but didin't really got it when saying packed with telock so no quide...anyway,easilly made easilly Dumped ;) |
...
and cause i'm never sure if u solved it right using your mind,would u tell us a small quide to follow and make our dump?if u would of course...
|
Quote:
But what is wrong with a guide 'bout telock . Anyway Quote:
|
Its not packed with teLock .. i guess its UPolyX ...
Looks like UPX and UPolyX scrambles the stub a bit ... KaGra correct me if i am wrong ... _veDc |
it is tElock. KaGra, you should have deleted the real OEP-bytes, else you just need to set correct EP and fix one call ;)
|
You start here:
Code:
01007D80 > 9C PUSHFD- Dump with your favorite dumper (lord pe / dump full) - Use OEP 01006AE0 sub ImageBase (1000000) and fill your ImpRec with it - Fix the dump with it Fix the not starting dump: Remember the Address which was MOV onto Stack at the beginning? This is the reason why our dump is not working .. find this in your dump: Code:
01006C45 > \6A 0A PUSH 0ACode:
01007FF0 $ 36:FF25 FCFF0>JMP DWORD PTR SS:[6FFFC]What we have to do now? We fix the CALL to the real Destination and have a working dump... Change Code:
01006C4F . E8 9C130000 CALL dumped_.01007FF0Code:
01006C4F E8 ADBBFFFF CALL dumped_.01002801thx to KaGra for this .. i hope this is the solution you wanted to hear .. and its the same unpackme you send me .. have a nice day |
| All times are GMT +8. The time now is 16:26. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX