Exetools

Exetools (https://forum.exetools.com/index.php)
-   General Discussion (https://forum.exetools.com/forumdisplay.php?f=2)
-   -   private exe protector unpacking? (https://forum.exetools.com/showthread.php?t=19446)

0xall0c 03-06-2020 19:45

little more debugging and i get to know that the pattern function in some way compares some bytes with another bytes generated from the same function, so right now i am patching the function to contain [ebp-1] = 0, what if i make [ebp-1]=0 with valid data not patching then i think i would not get the exception as the same data is later getting xored with the real oep section? is this correct?

0xall0c 03-13-2020 03:52

ok i give up, can anyone hand me the solution? so that i can actually see whats happening?

GautamGreat 05-15-2020 20:29

Quote:

Originally Posted by h4sh3m (Post 119461)
Hi

You can use this patterns :


It's not too hard bypassing this protector's registration (as I remember) but not tested on newer versions.


BR,
h4sh3m

Hi the last pattern seems working but if target is encrypted then the code section not decrypted and program crashes.

Can you give little more information about it? maybe some older notes you've wrote while analysis or anything

0xall0c 07-13-2020 00:47

i didnt create any notes! although yea it crashes because of wrong decryption, you have to get the key!


All times are GMT +8. The time now is 21:16.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX