Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 12-03-2013, 01:56
Tomy73 Tomy73 is offline
Friend
 
Join Date: Nov 2013
Location: Europe
Posts: 74
Rept. Given: 57
Rept. Rcvd 5 Times in 2 Posts
Thanks Given: 155
Thanks Rcvd at 23 Times in 18 Posts
Tomy73 Reputation: 6
What tools for unpack this?

Hello.

As the topic title says.
I wanna know ¿what tools you recommended to me for unpack the protection that I show in the images attached?
Many thanks in advanced.

Kindly regards.
Attached Images
File Type: jpg RDG 1.JPG (32.1 KB, 28 views)
File Type: jpg RDG 2B.JPG (40.5 KB, 25 views)
File Type: jpg PEID.jpg (81.5 KB, 25 views)
Reply With Quote
  #2  
Old 12-03-2013, 02:21
wilson bibe wilson bibe is offline
VIP
 
Join Date: Nov 2012
Posts: 492
Rept. Given: 489
Rept. Rcvd 439 Times in 180 Posts
Thanks Given: 859
Thanks Rcvd at 176 Times in 112 Posts
wilson bibe Reputation: 400-499 wilson bibe Reputation: 400-499 wilson bibe Reputation: 400-499 wilson bibe Reputation: 400-499 wilson bibe Reputation: 400-499
Are you talking about this?
http://forum.tuts4you.com/topic/33882-what-tools-for-unpack-this/
You have the answer by Conquest.................
Reply With Quote
  #3  
Old 12-03-2013, 02:40
Tomy73 Tomy73 is offline
Friend
 
Join Date: Nov 2013
Location: Europe
Posts: 74
Rept. Given: 57
Rept. Rcvd 5 Times in 2 Posts
Thanks Given: 155
Thanks Rcvd at 23 Times in 18 Posts
Tomy73 Reputation: 6
Hello Wilson bibe.

Yes, i´m talking about this.
I make here the question again for take more opinions.
If i can´t make the same question here, I apologize for this and the administrators can delete this post.
Sorry to all.

Kindly regards
Reply With Quote
  #4  
Old 12-03-2013, 04:32
giv's Avatar
giv giv is offline
VIP
 
Join Date: Jan 2011
Location: Romania
Posts: 1,657
Rept. Given: 801
Rept. Rcvd 1,283 Times in 561 Posts
Thanks Given: 226
Thanks Rcvd at 562 Times in 240 Posts
giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299
1. Brain
2. Will
Reply With Quote
The Following User Gave Reputation+1 to giv For This Useful Post:
Tomy73 (12-03-2013)
  #5  
Old 12-03-2013, 14:27
Dreamer's Avatar
Dreamer Dreamer is offline
Family
 
Join Date: May 2012
Posts: 604
Rept. Given: 613
Rept. Rcvd 659 Times in 257 Posts
Thanks Given: 117
Thanks Rcvd at 170 Times in 128 Posts
Dreamer Reputation: 38
try this tut from Elvis rept

Quick_tut.part1.rar

Quick_tut.part2.rar
Reply With Quote
The Following User Gave Reputation+1 to Dreamer For This Useful Post:
Tomy73 (12-03-2013)
  #6  
Old 12-03-2013, 15:38
Conquest Conquest is offline
Friend
 
Join Date: Jan 2013
Location: 0x484F4D45
Posts: 125
Rept. Given: 46
Rept. Rcvd 29 Times in 17 Posts
Thanks Given: 31
Thanks Rcvd at 60 Times in 29 Posts
Conquest Reputation: 29
Themida isnt an easy protector. Do not take it on your heart but you are not ready for it yet. But as giv said you will need the will and strong motivation to unpack it. Start learning about pe-coff format today and how kernel works will drive you to the proper way . There are lots of documents about themida/winlicence read them and the best is imitate what elders has done to unpack themida. You will learn 80% from them. rest will need experience but sure enough if you have the will, you will be able to unpack themida(not only this target but every themida protected target as well as most of the basic targets) within 6 months.
May god bless you
Reply With Quote
The Following User Gave Reputation+1 to Conquest For This Useful Post:
Tomy73 (12-03-2013)
  #7  
Old 12-03-2013, 18:08
Tomy73 Tomy73 is offline
Friend
 
Join Date: Nov 2013
Location: Europe
Posts: 74
Rept. Given: 57
Rept. Rcvd 5 Times in 2 Posts
Thanks Given: 155
Thanks Rcvd at 23 Times in 18 Posts
Tomy73 Reputation: 6
Many thanks to Dreamer and Conquest for answer.

To Dreamer: Can you upload this files to other site for download?
I´m newbie in this forum and i can´t download at this moment.

To Conquest: I now at this moment i´m not ready for themida, but i wanna
starting learning reading documents and info about it.
I´m newbie in this but I have practiced with other protections
along 3 year (Learning tuts and solving some Crackme)
I know is not easy and this take me a lot of time, but this is not problem because the important for me i learn.
Many thanks again to all for try to help me and apologize if I have annoyed someone.

Kindly regards.
Reply With Quote
  #8  
Old 12-03-2013, 18:51
giv's Avatar
giv giv is offline
VIP
 
Join Date: Jan 2011
Location: Romania
Posts: 1,657
Rept. Given: 801
Rept. Rcvd 1,283 Times in 561 Posts
Thanks Given: 226
Thanks Rcvd at 562 Times in 240 Posts
giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299
To understand the basics of packing/unpacking first read the document from here:
Quote:
http://msdn.microsoft.com/en-us/windows/hardware/gg463119.aspx
Reply With Quote
The Following User Gave Reputation+1 to giv For This Useful Post:
Tomy73 (12-04-2013)
  #9  
Old 12-08-2013, 14:57
0xd0000 0xd0000 is offline
Family
 
Join Date: Nov 2013
Posts: 51
Rept. Given: 3
Rept. Rcvd 37 Times in 14 Posts
Thanks Given: 9
Thanks Rcvd at 21 Times in 12 Posts
0xd0000 Reputation: 37
When it comes to tools and tuts, grab yourself a copy of this.

Content listing attached.


This is a complete archive (site rip) of all files on Tuts 4 You as of July 2011 except for the malware samples - you will need to download these directly from Tuts 4 You.

I have created the torrent as directories and files rather than one archive which gives you the option to download files individually or in categories. The entire collection is 3.69 GB of which some sections may be of little interest to some but you have the option of downloading what you want.

This collection will be updated annually so please check at the following link for the official and up-to-date torrent file:

http://tuts4you.com/download.php?view.3162

Please remember to seed the torrent and help share the knowledge within the reversing community. I hope this satisfies the leechers, thank you!

Teddy Rogers.
Attached Files
File Type: txt Tuts 4 You - Collection 2011 - Contents.txt (122.7 KB, 7 views)
Reply With Quote
The Following 3 Users Gave Reputation+1 to 0xd0000 For This Useful Post:
giv (12-08-2013), rceArchivist (12-04-2023), Tomy73 (12-09-2013)
  #10  
Old 12-08-2013, 18:45
Tomy73 Tomy73 is offline
Friend
 
Join Date: Nov 2013
Location: Europe
Posts: 74
Rept. Given: 57
Rept. Rcvd 5 Times in 2 Posts
Thanks Given: 155
Thanks Rcvd at 23 Times in 18 Posts
Tomy73 Reputation: 6
Many thanks to 0xd0000(Teddy Rogers) and Giv for all the info.
Now I´m reading and learning many tuts and other info i take.
When i´m more documented about this i try to formulate my doubts.
Many thanks to all who are helping me.

Kindly regards.
Reply With Quote
  #11  
Old 12-08-2013, 23:03
giv's Avatar
giv giv is offline
VIP
 
Join Date: Jan 2011
Location: Romania
Posts: 1,657
Rept. Given: 801
Rept. Rcvd 1,283 Times in 561 Posts
Thanks Given: 226
Thanks Rcvd at 562 Times in 240 Posts
giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299
Don't make any illusions. It will be years before you will know. Or you can learn mechanic from the tutorials whithout knowing in fact nothing. Is your choice.
Reply With Quote
The Following User Gave Reputation+1 to giv For This Useful Post:
Tomy73 (12-10-2013)
  #12  
Old 12-09-2013, 00:34
Conquest Conquest is offline
Friend
 
Join Date: Jan 2013
Location: 0x484F4D45
Posts: 125
Rept. Given: 46
Rept. Rcvd 29 Times in 17 Posts
Thanks Given: 31
Thanks Rcvd at 60 Times in 29 Posts
Conquest Reputation: 29
Quote:
Originally Posted by giv View Post
Don't make any illusions. It will be years before you will know. Or you can learn mechanic from the tutorials whithout knowing in fact nothing. Is your choice.
Well after all these years i have come to realize the fact that once you know where to hit, reversing is so easy that people dont reveal things really via tuts(well not all but most) . A usual format of tut is -> you open olly, click this button (no explanation why), click that button, use this script , hit breakpoint 62 times(though usually there should be another easy way but they just love to freak you out) and done you are at break point.
I open another target, copy the instruction and "Exception code: C0000005 ACCESS_VIOLATION"
The only way i could learn something was manually researching things on my own and dissecting at least 4~5 samples of certain protector.
Reply With Quote
The Following User Gave Reputation+1 to Conquest For This Useful Post:
Tomy73 (12-09-2013)
  #13  
Old 12-10-2013, 09:32
0xd0000 0xd0000 is offline
Family
 
Join Date: Nov 2013
Posts: 51
Rept. Given: 3
Rept. Rcvd 37 Times in 14 Posts
Thanks Given: 9
Thanks Rcvd at 21 Times in 12 Posts
0xd0000 Reputation: 37
Quote:
Originally Posted by Conquest View Post
Well after all these years i have come to realize the fact that once you know where to hit, reversing is so easy that people dont reveal things really via tuts(well not all but most) . A usual format of tut is -> you open olly, click this button (no explanation why), click that button, use this script , hit breakpoint 62 times(though usually there should be another easy way but they just love to freak you out) and done you are at break point.
I open another target, copy the instruction and "Exception code: C0000005 ACCESS_VIOLATION"
The only way i could learn something was manually researching things on my own and dissecting at least 4~5 samples of certain protector.
I agree here - tuts are great for reference, but that's about where it stops. You need to spend hours upon hours of research, mainly trial and error from the ground up.

When friends ask where to start, I direct them to the basic's. For those that are visual, some would say a quick youtube of a winrar patch is all they need to get started. For others, a simple crackme from crackmes and a copy of Olly with a tut on searching through strings. - or something from here: http://thelegendofrandom.com/blog/sample-page

The amount of time that is required to ramp up on RE is fairly subjective, some argue a seasoned developer has the edge --I tend to agree here, though had some argue it's better to start fresh so there is no paradigm shift to overcome, I can somewhat understand this, but it's a hard case to make.

As far as a RE¡¯s work—reminds me of a line from a book, except here the reference is to dev¡¯s, but I think the underlying principle still applies.

"Their work is one percent inspiration, the rest sweat-drenched detective work; their products are never finished or perfect, just varying degrees of "less broken"¡±
Reply With Quote
The Following 2 Users Gave Reputation+1 to 0xd0000 For This Useful Post:
Conquest (12-10-2013), Tomy73 (12-10-2013)
  #14  
Old 12-10-2013, 17:44
Tomy73 Tomy73 is offline
Friend
 
Join Date: Nov 2013
Location: Europe
Posts: 74
Rept. Given: 57
Rept. Rcvd 5 Times in 2 Posts
Thanks Given: 155
Thanks Rcvd at 23 Times in 18 Posts
Tomy73 Reputation: 6
Many thanks to all, for your answer.
I take in account all your opinions.
I write all the doubts that arise me.
Many thanks again for your help.

Kindly regards.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 07:26.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )