Exetools  

Go Back   Exetools > General > Source Code

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 10-20-2014, 03:07
quygia128's Avatar
quygia128 quygia128 is offline
Family
 
Join Date: Apr 2011
Location: SomeWhere
Posts: 109
Rept. Given: 243
Rept. Rcvd 182 Times in 47 Posts
Thanks Given: 122
Thanks Rcvd at 30 Times in 19 Posts
quygia128 Reputation: 100-199 quygia128 Reputation: 100-199
Yes, it shouldn't work for other Packed file.

Your Loader need add code loop(for/while) to detect WMProtect have been decrypted your app code(Real code you need patch), verify it then byte is exist, you will be suspend process and patch code before resume process.
That's all

BR,
quygia128
Reply With Quote
  #2  
Old 10-20-2014, 03:21
0x22 0x22 is offline
Family
 
Join Date: Aug 2014
Posts: 66
Rept. Given: 14
Rept. Rcvd 47 Times in 18 Posts
Thanks Given: 12
Thanks Rcvd at 64 Times in 21 Posts
0x22 Reputation: 47
Quote:
Originally Posted by quygia128 View Post
Yes, it shouldn't work for other Packed file.

Your Loader need add code loop(for/while) to detect WMProtect have been decrypted your app code(Real code you need patch), verify it then byte is exist, you will be suspend process and patch code before resume process.
That's all

BR,
quygia128
It works as long as you insert the correct offsets. It works on all VMProtect with self-checks as well as Safengine's selfcheck, tested on multiple protected files and i have cracks released with this loader for weeks without complains.
Reply With Quote
  #3  
Old 10-20-2014, 04:01
Carbon Carbon is offline
VIP
 
Join Date: Sep 2013
Posts: 113
Rept. Given: 7
Rept. Rcvd 189 Times in 48 Posts
Thanks Given: 0
Thanks Rcvd at 60 Times in 19 Posts
Carbon Reputation: 100-199 Carbon Reputation: 100-199
Quote:
Originally Posted by 0x22 View Post
It works as long as you insert the correct offsets. It works on all VMProtect with self-checks as well as Safengine's selfcheck, tested on multiple protected files and i have cracks released with this loader for weeks without complains.
It still depends on the hardware (CPU power) of the machine. I have done a VMP loader myself in the past and I had to use Sleep() with a certain amount of time. The good thing is that you can automatically bruteforce the correct Sleep time more or less for a specific machine.

Real release groups don't allow "loader" cracks for obvious reasons.
__________________
My blog: https://ntquery.wordpress.com
Reply With Quote
  #4  
Old 10-20-2014, 09:41
0x22 0x22 is offline
Family
 
Join Date: Aug 2014
Posts: 66
Rept. Given: 14
Rept. Rcvd 47 Times in 18 Posts
Thanks Given: 12
Thanks Rcvd at 64 Times in 21 Posts
0x22 Reputation: 47
Quote:
Originally Posted by Carbon View Post
It still depends on the hardware (CPU power) of the machine. I have done a VMP loader myself in the past and I had to use Sleep() with a certain amount of time. The good thing is that you can automatically bruteforce the correct Sleep time more or less for a specific machine.

Real release groups don't allow "loader" cracks for obvious reasons.
Are you talking about my loader?
I'm not sure if i understood you correctly, because the source i posted here does not depend on hardware/CPU becuase it does not use sleep.
Sleep is a method i would never use at all, its shit, cuz yes as you said CPU.

I accept your critizism but i released my source to be nice, so that people that may not be "that" expericed with this, might solve it with my working method as well as giving people an idea to work on, and on how it could done.

To be honest i couldnt give two shits about what real release groups allow or not.
In my eyes, a working method is a working method, as long as the program opens, I'm happy and the users that use it will remain happy.

Good day.

Last edited by 0x22; 10-20-2014 at 10:29.
Reply With Quote
The Following User Gave Reputation+1 to 0x22 For This Useful Post:
b30wulf (10-20-2014)
The Following User Says Thank You to 0x22 For This Useful Post:
niculaita (08-30-2016)
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On


Similar Threads
Thread Thread Starter Forum Replies Last Post
[HELP] How to write a simple Loader in ASM on MSDOS stoney81 General Discussion 5 12-20-2024 15:55
Simple Task [make loader for UPX target]... diablo2oo2 General Discussion 1 12-30-2004 07:03


All times are GMT +8. The time now is 19:22.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )