![]() |
|
|
|
#1
|
|||
|
|||
|
Thinstall unpacking
Hi all,
are the any tutorials or other informations about unpacking a thinstall-packed program out there? Thanks in advance. bKACK oUT |
|
#2
|
|||
|
|||
|
You have a target I can try?
|
|
#3
|
|||
|
|||
|
Hi SvensK,
i want to reverse Reason 2.5 from Propellerhead, sorry, dont have a smaller target. I know the packer works only when connected to the internet and uses eliptical-curve algo and other funny stuff. |
|
#4
|
|||
|
|||
|
I havent had a deep look at Thinstall internally....but my few tests tell me that it leaves the EXE almost untouched when decrypted, so you can make a dump (by regions) and construct the original EXE without suffering much
![]() It's true that they use a local file system inside the EXE and that makes .NET application to be run without problems after protecting (no mangling any structures)...but, well, I think this is another story....
|
|
#5
|
|||
|
|||
|
Thanks alot peleon.
|
|
#6
|
||||
|
||||
|
Quote:
Sorry 4 my bad English iam only human
|
|
#7
|
|||
|
|||
|
so ... and what about several exe's and dll's? how it dump? ... I try to unpack Thinstall.exe and get only first .exe file
|
|
#8
|
||||
|
||||
|
Quote:
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|