Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 06-28-2007, 21:19
TmC TmC is offline
VIP
 
Join Date: Aug 2004
Posts: 330
Rept. Given: 1
Rept. Rcvd 15 Times in 9 Posts
Thanks Given: 2
Thanks Rcvd at 23 Times in 17 Posts
TmC Reputation: 15
Oberon Game: Agatha Christie Murder on Nile

Hi all,
I've succesfully unpacked all Oberon Games, except this that is driving me and my olly crazy.

No script works, olly often crashes and i can't manage to unpack the program.

mr magic unpacker works but the purpose is learning, not automatically unpacking.

The program is this: crk://gamecenter.oberon-media.com/exe/Agatha_Christie-setup.exe

Did anyone succeed in unpacking? I tried to unpack other armadillo targets to ensure it was not a problem related to some settings, but this wasn't the case. I succesfully unpacked all the other titles.

When i try to unpack with fly's standard unpacking script it even crashes ollyscript.
Sometimes it does not even start and tries to write, with consequent access violations to things like 0000000B 0000008D and similar.

New armadillo?

Some ideas?

Last edited by TmC; 06-28-2007 at 21:21.
Reply With Quote
  #2  
Old 06-28-2007, 22:56
fly [CUG]'s Avatar
fly [CUG] fly [CUG] is offline
UpK
 
Join Date: Jul 2004
Location: һ������
Posts: 153
Rept. Given: 3
Rept. Rcvd 3 Times in 1 Post
Thanks Given: 5
Thanks Rcvd at 3 Times in 2 Posts
fly [CUG] Reputation: 3
Code:
004A0761    E8 A3E40000         call 004AEC09  ; This is the OEP!  Found By: fly
004A0766    E9 16FEFFFF         jmp 004A0581
Armadillo V4.0-V4.44.Standard.Protection.oSc
__________________

UpK

һ�����ꡭ����ƽ��!
http://www.unpack.cn
Reply With Quote
  #3  
Old 07-15-2007, 06:20
ahmadmansoor's Avatar
ahmadmansoor ahmadmansoor is offline
Coder
 
Join Date: Feb 2006
Location: Syria
Posts: 1,047
Rept. Given: 517
Rept. Rcvd 374 Times in 142 Posts
Thanks Given: 380
Thanks Rcvd at 416 Times in 119 Posts
ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399
Lightbulb Try to use "Armadillo OpenMutexA"

If u use "Armadillo OpenMutexA" script , and u pass all Exceptions and after 2
CreateThread then go to RET and u will find this Call
00D6036D FFD1 CALL ECX which go u to The OEP
this Is :
004118D6 . 6A 60 PUSH 60 This is the OEP
004118D8 . 68 A8>PUSH 004326A8
004118DD . E8 56>CALL 00412238
004118E2 . BF 94>MOV EDI,94
004118E7 . 8BC7 MOV EAX,EDI
004118E9 . E8 32>CALL 00410720
004118EE . 8965 >MOV DWORD PTR SS:[EBP-18],ESP
004118F1 . 8BF4 MOV ESI,ESP
004118F3 . 893E MOV DWORD PTR DS:[ESI],EDI
004118F5 . 56 PUSH ESI ; /pVersionInformation
004118F6 . FF15 >CALL DWORD PTR DS:[42E298] ; \GetVersionExA
use ArmInline then Dump the file ,and u wil find it by PEiD is
Microsoft Visual C++ 7.0 [Debug]
that all i have.................................
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
A 96KB Game!! ferrari General Discussion 9 06-02-2004 07:31


All times are GMT +8. The time now is 04:31.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )