Unpack Me
Astalavista Forum Index :: Crack Me's and Challenges :: Unpack Me
Post new topic   This topic is locked: you cannot edit posts or make replies. View previous topic :: View next topic
  Unpack Me
Author Message
K.I.M
Good Member
Good Member


Offline
No Image
Joined: 13 Dec 2007
Posts: 79

Reply with quote
No Image
heres my protected file unpack it and write a tourital

Code:
http://www.2shared.com/file/2852542/be648d5b/Get_IPs.html
View user's profile Send private message
PostDate Posted:Sat Feb 16, 2008 2:26 am
Thanks: 2Thanked 1 Times In 0 Posts

Author Message
SHKODRAN
Hall of Fame
Hall of Fame


Offline
No Image
Joined: 09 Jun 2007
Posts: 90

Reply with quote
No Image
What neded you the decompressed program or the way like is made?
View user's profile Send private message MSN Messenger
PostDate Posted:Sat Feb 16, 2008 12:14 pm
Thanks: 0Thanked 6 Times In 2 Posts

Author Message
chupachu
Super Member
Super Member


Offline
No Image
Joined: 20 May 2007
Posts: 779

Reply with quote
No Image
I think he wants a tutorial :)

_________________
Have a nice day!
View user's profile Send private message
PostDate Posted:Sat Feb 16, 2008 2:18 pm
Thanks: 2Thanked 5 Times In 5 Posts

Author Message
K.I.M
Good Member
Good Member


Offline
No Image
Joined: 13 Dec 2007
Posts: 79

Reply with quote
No Image
chupachu wrote:
I think he wants a tutorial Smile


yes ur right
View user's profile Send private message
PostDate Posted:Sun Feb 17, 2008 6:16 am
Thanks: 2Thanked 1 Times In 0 Posts

Author Message
LCF-AT
Special Member
Special Member


Offline
No Image
Joined: 17 Jan 2008
Posts: 205
Location: Chateau-Saint-Martin

Reply with quote
No Image
The app is protected with armadillo 5.40 with NO special features but one this protection use a little trick with GetTickCount. Smile
Your download link:
Code:
CALL 00BB9100
CMP DWORD PTR DS:[C1D5B8],0
JNZ SHORT 00BEC46C
CALL DWORD PTR DS:[C0E344]             ; kernel32.GetTickCount
MOV DWORD PTR DS:[C1D5B8],EAX          ; Get_IP's.00472E68
JMP SHORT 00BEC456

So you must set a value in eax because eax is 0 after GetTickCount to jump over the API or olly runs endless. Smile This is a VB app.
Your download link:
Code:
004012A0   PUSH Get_IP's.004081E8     ; <- OEP
004012A5   CALL Get_IP's.0040129A     ; JMP to MSVBVM60.ThunRTMain
One invalid pointer can cut away its just a loop.Iat size E8.
After unpacking no checks pops up just the normal running app.

greetz
View user's profile Send private message
PostDate Posted:Sun Feb 17, 2008 7:02 am
Thanks: 0Thanked 44 Times In 29 Posts

Author Message
zuma555
Good Member
Good Member


Offline
No Image
Joined: 05 Jan 2008
Posts: 89

Reply with quote
No Image
Okay LCF-AT is an unpacking god. Trust him! lol Wink
View user's profile Send private message
PostDate Posted:Sun Feb 17, 2008 3:35 pm
Thanks: 0Thanked 0 Times In 0 Posts

Author Message
chupachu
Super Member
Super Member


Offline
No Image
Joined: 20 May 2007
Posts: 779

Reply with quote
No Image
zuma555 wrote:
Okay LCF-AT is an unpacking god. Trust him! lol ;)


agreed.. just not so sure that its a he ;)

_________________
Have a nice day!
View user's profile Send private message
PostDate Posted:Sun Feb 17, 2008 3:36 pm
Thanks: 2Thanked 5 Times In 5 Posts

Author Message
zuma555
Good Member
Good Member


Offline
No Image
Joined: 05 Jan 2008
Posts: 89

Reply with quote
No Image
WHAT? how the hell you can say that a girls knows so much on unpacking??lol chups we are talking about a girls its a minor being. Very Happy
View user's profile Send private message
PostDate Posted:Sun Feb 17, 2008 3:39 pm
Thanks: 0Thanked 0 Times In 0 Posts

Author Message
Encrypto
Super Member
Super Member


Offline
No Image
Joined: 26 Jun 2007
Posts: 996

Reply with quote
No Image
Zuma555 i would like you to shut your trap ! Girls are human beings like
you !. Maybe it is foreign to you but keep your idiotic opinions to yourself.
Think how manytimes LCF-AT Has helped you and say that again!.

How dare you hold such beliefs is un-believable.

P.S : keep up the good work LCF-AT

_________________

sig by skytactic. Thanks mate.
View user's profile Send private message
PostDate Posted:Sun Feb 17, 2008 4:26 pm
Thanks: 3Thanked 110 Times In 40 Posts

Author Message
chupachu
Super Member
Super Member


Offline
No Image
Joined: 20 May 2007
Posts: 779

Reply with quote
No Image
All i can say is that LCF-AT is a respected part of RE scene, willing to help when asked
and very skilled unpacker, this forum shud be happy to have sucha individual onboard.

One has to respect time LCF-AT spent while helpin others!

On the other hand users with lack of respect and bad attitude are a problem
on every forum, its up to moderators to deal with them as they want.

BR, ChupaChu!

_________________
Have a nice day!
View user's profile Send private message
PostDate Posted:Sun Feb 17, 2008 8:48 pm
Thanks: 2Thanked 5 Times In 5 Posts

Author Message
LCF-AT
Special Member
Special Member


Offline
No Image
Joined: 17 Jan 2008
Posts: 205
Location: Chateau-Saint-Martin

Reply with quote
No Image
Hello together,

i just wanna say that this is a good RE board what i like and of course i try also to help other people with some RE problems if i can and i also will need sometimes help for my problems.Thank´s chupachu for this nice words so we
know us already a little bit and i have just to say same about you. Smile
And also a thank´s for all other reverser on this place for the good welcome.

greetz
View user's profile Send private message
PostDate Posted:Mon Feb 18, 2008 12:52 am
Thanks: 0Thanked 44 Times In 29 Posts

Display posts from previous:   
Post new topic   This topic is locked: you cannot edit posts or make replies.    Page 1 of 1 All times are GMT


Back to top


 
Astalavista Forum Index :: Crack Me's and Challenges :: Unpack Me



Search This Topic:
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by Astalavista.MS Team © 2004
Image Here Image Here Image Here