Сейчас на форуме: (+5 невидимых)

 eXeL@B —› WorldWide —› Help with unpacking Themida
Посл.ответ Сообщение

Ранг: 1.2 (гость)
Активность: 0=0
Статус: Участник

Создано: 23 июля 2013 22:29 · Поправил: ZeroTears
· Личное сообщение · #1

Gentlemen,

This is not (specifically) a request for cracking. I'm mostly stuck trying to unpack a themida protected EXE. If this does belong in the crack request. Please lock and don't hit me with your ban hammer to hard >_<

I'm using ollydbg with the following plugins.
CodeDoctor
MUltimate Assembler
ODbgScript
Oreans UnVirtualizer
PhantOm
StringOD
and using LCF-AT's themida script

I've tried multiple times to find the OEP for this file (Make.exe) however, i'm having really no luck. You can see my poor attempt at dumping in the poor attempt folder.

What i'm most interested in is how this can be dumped. I'm still very new, but need a little guidance.

If someone would dump it, and give an example of how they achieved the goal and what tools were used it would greatly be appreciated!

Thanks!
-Z




Ранг: 623.6 (!), 521thx
Активность: 0.330.9
Статус: Участник
_Вечный_Студент_

Создано: 24 июля 2013 03:18
· Личное сообщение · #2

There is literaly millions of tutorials around dedicated to exactly your problem.
This one for example:
--> http://www.oocities.org/r_etarded/ollydump/ollydump.html<--
Read it, hopefully it'll help.

-----
Give me a HANDLE and I will move the Earth.




Ранг: 1.2 (гость)
Активность: 0=0
Статус: Участник

Создано: 24 июля 2013 04:55
· Личное сообщение · #3

plutos, Thanks for your reply.

I have followed tons of tuts (mostly from tuts4you and by LCF-AT) but either i fully don't understand, or this exe is protected in a different way. (but i'm not sure how to tell).

I have analyzed with exeinfo, peid, and they all show it packed with themida.

Thanks
-Z




Ранг: 623.6 (!), 521thx
Активность: 0.330.9
Статус: Участник
_Вечный_Студент_

Создано: 24 июля 2013 07:03 · Поправил: plutos
· Личное сообщение · #4

What do you mean, "but i'm not sure how to tell"?
You just deternined the type of protector, did not you? ("they all show it packed with themida")
So, if this is indeed the case, read about unpacking .exe's packed with Themida. There is a lot written about it even here on this forum, just search.

-----
Give me a HANDLE and I will move the Earth.




Ранг: 1.2 (гость)
Активность: 0=0
Статус: Участник

Создано: 25 июля 2013 01:11
· Личное сообщение · #5

Plutos,

I did determine the type of protector. It is Themida. However, i'm unsure if its protected with multiple protectors. (Sorry if i was not clear).

My problem has been finding the OEP or Near OEP. Following a ton of tuts, with no luck. I've tried both using scripts, and doing the manual way. There are anti-dumps, so i know doing it the manual way will prove difficult. After setting a memory breakpoint on the code address in memory, i never end up at the OEP (or close). Even after stepping over all of the debugging detectors.

Sorry, i know newbs like me are thorns in the side.

-Z



Ранг: 134.1 (ветеран), 246thx
Активность: 0.220.1
Статус: Участник
realist

Создано: 25 июля 2013 23:24
· Личное сообщение · #6

ZeroTears
program is written in Visual C#
used tools MegaDumper, UniversalFixer, de4dot
try --> unpacked <--

| Сообщение посчитали полезным: ZeroTears

Ранг: 1.2 (гость)
Активность: 0=0
Статус: Участник

Создано: 25 июля 2013 23:57 · Поправил: ZeroTears
· Личное сообщение · #7

@Jaa...

Thank you very much! I downloaded those tools from Tuts4you. The Universal fixer was the key to fixing the dump. After I dumped the app before with MegaDumper it was not coming up in reflector, so i thought it was in another language. (I did not know about the fixer).

I do have a successful dump now. I'm still working towards doing it myself with olly. Un-Packing is hard, Patience is key.

Thumbs up for you sir!

-Z


 eXeL@B —› WorldWide —› Help with unpacking Themida
:: Ваш ответ
Жирный  Курсив  Подчеркнутый  Перечеркнутый  {mpf5}  Код  Вставить ссылку 
:s1: :s2: :s3: :s4: :s5: :s6: :s7: :s8: :s9: :s10: :s11: :s12: :s13: :s14: :s15: :s16:


Максимальный размер аттача: 500KB.
Ваш логин: german1505 » Выход » ЛС
   Для печати Для печати