#1
|
|||
|
|||
unpacking upx packed and scrambled pe
i am facing problem with unpacking upx packed and scrambled pe .Is there any tool available?here is a attachment namely 'remote anything' and is also available at 'www.twd-industries.com/en/downloads.htm'. The problem is of unpacking "slave.exe" when we unpack in winXX then it works fine in win 98/Me but the same unpack exe fail to work in winxp/win200/winnt. when we unpack in winxp/win200/winnt it works ,the same unpack exe fail to work .kindly help. some antivirus can trigger on slave .exe
|
#2
|
|||
|
|||
I havent tried it on your mentioned target but here is what I know
UPXUnpack by Bratalarm (unpacks most generic and scrambled upx packed files) Good 'ole PROCDUMP .. Unpack.. UPX works OK too on scrambled. Old but still kickin' "some" **** is "ProcDump". It will always remain in my best \TOOLS\ folder Quote:
|
#3
|
|||
|
|||
maybe u can unpack it by ollydbg manually
load the target and input "hr esp-4" in cmd bar. press f9 until you stop at OEP... rebuild imports by imprec then fix the dump file |
#4
|
||||
|
||||
use UPX ripper 1.3 By Zodiax to unpack (it works at your target) or rename sections to UPX0, UPX1 .... an leave .rsrc then use UPX recover plug-in from PE Tools to recover and use upx -d to unpack (tested on UPX scrambler) ... BOth methods leaves target almost 100% original as before packing ...
BtW> Sorry for my bad English Iam only human |
#5
|
|||
|
|||
where can i find UPX ripper 1.3 By Zodiax to unpack it. I have tried procdump and UPXUnpack by Bratalarm but with no success. is there any tutorial available for ollydbg
|
#6
|
|||
|
|||
UPX unpacking
Hi. Have you tried using UPX.exe's -d option? I have successfully used the built-in feature to unpack many executables while cracking them; why utilise external tools where they are completely unnecessary? ProcDump is overkill, IMO.
If you have any problems, let me know. -archaios |
#7
|
||||
|
||||
Quote:
|
#8
|
|||
|
|||
hey pals,,,
i am hung with a upx packed and modified pe ocx file.... how 2 unpack it successfully..???? i dumped the file successfully,,, using the dex method,,, now how 2 fix the imports... using importrec, as it loads the loaddll.exe and not the ocx.. after picking the ocx control, from pick dll, it shows module selected, and the image base and other things,, when i click on IAT . it shows that nothing found at this oep. help needed thanx TDW {RES} Last edited by The Day Walker!; 07-09-2005 at 04:44. |
#9
|
|||
|
|||
Unpacked sinply with PEiD
|
#10
|
|||
|
|||
peid is not unpacking it.....
i m tryin 2 unpack osenxpsuite v10 thanx TDW {RES} |
|
|
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
problem on unpacking a telock 0.98 b1 packed dll | peter888 | General Discussion | 6 | 05-25-2004 21:04 |