Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 02-03-2005, 14:39
Crk
 
Posts: n/a
Unknown Multiple layer Encryption ?

well... haven't been able to make a decent dump and came here to see if someone knows a good method to get a dump or unpack for: _ttp://www.dvdxcopy-international.com/setup/DVDXPv4.0.3.8.exe

anyone knows what protector or cryptor was used on this one?

Peid says nothing.. i've been tracing for hours and can'r reach OEP ...maybe due many encryption layer it has and anti-debug tricks.. got tired ..but there most be an easy way.. i tried Lordpe/Full dump and all it gives is an invalid image without nothing decrypted ...
Reply With Quote
  #2  
Old 02-04-2005, 13:20
Lunar_Dust
 
Posts: n/a
can you give us more info about the PE, like how many sections, what are their names, etc.

Also, look in the file with hex editor and see if you find any strings that might clue towards the protector.

Run the app in a debugger and see if it gives an error message. If so, what does it say and what does the message look like?

These are all indicators that can show the protector type.

The only protector I know of that will screw LordPE full dumps is Armadillo.

-Lunar
Reply With Quote
  #3  
Old 02-04-2005, 13:29
Crk
 
Posts: n/a
i did all that.. and the most strange part is that don't give any warning about the debugger.. running now SOFTICE 4.05 for win9x and runs perfect.. but never get into the finish of the encrypting...used some hardware bpm .. but never ends most be some anti debug trick ,, the section don't have names so far i remember and fix image size with LordPE don't do nothing when i dump it the code is still not decrypted even when i got the app.(nag) full loaded .....any ideas?
Reply With Quote
  #4  
Old 02-05-2005, 16:32
Newbie_Cracker's Avatar
Newbie_Cracker Newbie_Cracker is offline
VIP
 
Join Date: Jan 2005
Posts: 227
Rept. Given: 72
Rept. Rcvd 26 Times in 12 Posts
Thanks Given: 50
Thanks Rcvd at 25 Times in 18 Posts
Newbie_Cracker Reputation: 26
- Use ollydbg too. I think its better for visualizing the codes and registers.
- BP on IsDebuggerPresent, int 1,and use icedump with "protect on" for finding its anti-debug sections, if exists any.

Quote:
Lunar :

The only protector I know of that will screw LordPE full dumps is Armadillo
Another unknown protector skrews LordPE too. It closes most of crack tools like monitoring tools, ollydbg, and LordPE. I used PE Tools 1.5 and it dumped garbage code.
Please test "Password Reminder 1.7" too.
Reply With Quote
  #5  
Old 02-06-2005, 08:49
Jay Jay is offline
VIP
 
Join Date: Feb 2002
Posts: 249
Rept. Given: 31
Rept. Rcvd 3 Times in 3 Posts
Thanks Given: 15
Thanks Rcvd at 13 Times in 5 Posts
Jay Reputation: 3
Quote:
Another unknown protector skrews LordPE too
If I remember correctly that was protected with softdefender at least earlier version were and vaguely recall sdpro did cause problems with lpe, I don't remember if standard version did.
Reply With Quote
  #6  
Old 02-06-2005, 13:49
Crk
 
Posts: n/a
nothing works, excuse me newbie cracker but you're not telling anything new.. have you been able to dump useable code with dumped.exe?? i need solutions not guessings

Regards
Reply With Quote
  #7  
Old 02-06-2005, 19:41
taos's Avatar
taos taos is offline
The Art Of Silence
 
Join Date: Aug 2004
Location: In front of my screen
Posts: 580
Rept. Given: 65
Rept. Rcvd 54 Times in 19 Posts
Thanks Given: 69
Thanks Rcvd at 137 Times in 36 Posts
taos Reputation: 54
Quote:
Originally Posted by Crk
i need solutions not guessings
3 EXE's packed:
dvdxrescue.exe
OEP=45ac1c
IAT=46affc size:6e0

platinum.exe
OEP=4530ca
IAT=48bffc size:750

xpress.exe
OEP=43de26
IAT=472ffc size:66c

I've attached unpacked & cracked solutions.

hxxp://s19.yousendit.com/d.aspx?id=19C2EREKI3XFL3CB1UH33Z5UUH

Regards
Reply With Quote
  #8  
Old 02-06-2005, 21:09
D-Jester's Avatar
D-Jester D-Jester is offline
VIP
 
Join Date: Nov 2003
Location: Ohio, USA
Posts: 269
Rept. Given: 39
Rept. Rcvd 61 Times in 41 Posts
Thanks Given: 0
Thanks Rcvd at 4 Times in 4 Posts
D-Jester Reputation: 61
Question

Were you able to identify the packer/ecryptor?
I was begining to think it was XtreamLok.
Did you write a walkthrough?
__________________
Even as darkness envelops and consumes us, wrapping around our personal worlds like the hand that grips around our necks and suffocates us, we must realize that life really is beautiful and the shadows of despair will scurry away like the fleeting roaches before the light.
Reply With Quote
  #9  
Old 02-06-2005, 22:05
Frequency
 
Posts: n/a
Taos,
could you please give a quick tut if possible? THis company (312 Studios) used to Use Protection Plus for their Software but switched. I tried for a while but got no where. If you find some time can you please elaborate on how you found OEP? thanks,
-H3rCuL3s
Reply With Quote
  #10  
Old 02-06-2005, 22:22
Crk
 
Posts: n/a
I've attached unpacked & cracked solutions.

Dear Taos i really apreciate your help but this don't really help me since i'm looking for knowledge and not unpacked exe. me and all here will be glad if you explain a little about this cryptor and how you unpacked. so still this is useless from my point of view... not ofenses

i would like to break registration scheme.. but as you know before that i most have the files decrypted and running good... i believe also a .dll which maybe depends of this is also packet .. with Peid you can find out which one is. i have uninstalled this i will check it later again.

Regards

Last edited by Crk; 02-06-2005 at 22:27.
Reply With Quote
  #11  
Old 02-08-2005, 22:19
taos's Avatar
taos taos is offline
The Art Of Silence
 
Join Date: Aug 2004
Location: In front of my screen
Posts: 580
Rept. Given: 65
Rept. Rcvd 54 Times in 19 Posts
Thanks Given: 69
Thanks Rcvd at 137 Times in 36 Posts
taos Reputation: 54
I'm too busy to writte a tut. when I have time maybe.
The registration scheme and the original EXE are packed in differents ways so you must crack the reg scheme (using SICE or stolen code) and then, when you bypass the reg., you will see how the loader unpacks the original file and go to the OEP.

I don't know what type of protection is (it creates threads)...
If my job permits me, I will post more info.
Regards.
Reply With Quote
  #12  
Old 02-10-2005, 16:00
Crk
 
Posts: n/a
you haven't answell any cuestion sound very misterious your way to handle this without sharing any tips if i would like cracked exe's this topic wouldn't be done here and will be on Requests ..i don't need any cracked exe by now for this excepting understanding the way this cryptor or packer works and how to unpack it. the answers keeps unanswered andthe topic remains alive.

Regards
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Help for unknown protector Newbie_Cracker General Discussion 9 01-11-2011 17:42
An Unknown Packer ! Newbie_Cracker General Discussion 10 10-11-2005 14:35
Unknown Packer deephousederek General Discussion 10 03-06-2005 10:04


All times are GMT +8. The time now is 06:39.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )