![]() |
|
|
|
#1
|
|||
|
|||
|
Hi,
I'm trying to unpack the Speed Optimizer from Speedbit. http://speedoptimizer.com/ It's packed with SVKP 1.3x & i managed to find oep as 4604b2. What about it and the stolen bytes. Pls help. The UC2004's SVKP explorer don't works. |
|
#2
|
|||
|
|||
|
i-speed optimizers are trush, forget tham;
is other any good program protected with svkp.. about stolen bytes many times explaned, use search; |
|
#3
|
|||
|
|||
|
Formik maybe (dunno what is for you "good program")
_http://www.formik.rksoft.sk/ _http://www.rksoft.sk/Download/formik.exe Last edited by hosiminh; 01-08-2005 at 19:40. |
|
#4
|
|||
|
|||
|
speedoptimizer
Looks like 89 stolen bytes , oep == 00460459 |
|
#5
|
|||
|
|||
|
sorry, forgot about this thread..
so i dld-ed Formik. That was Delphi-app, so at OEP are ripped just few Delphi-standart instructions.. also there are 2 SVKP_Imported calls; (1st= mov eax,1; ret4; 2nd = ret) some decryptor calls, from where last 2 decrypted code conteins PE-header check. |
|
#6
|
|||
|
|||
|
Formik
Code:
....stolen bytes 004F9B79 90 NOP 004F9B7A 90 NOP 004F9B7B 90 NOP 004F9B7C 90 NOP 004F9B7D 90 NOP 004F9B7E 90 NOP 004F9B7F 90 NOP 004F9B80 90 NOP 004F9B81 90 NOP 004F9B82 90 NOP 004F9B83 90 NOP 004F9B84 E8 97D7F0FF CALL Formik.00407320 004F9B89 8B1D F8F04F00 MOV EBX,DWORD PTR DS:[4FF0F8] ; Formik.00500C8C 004F9B8F E8 603EFEFF CALL Formik.004DD9F4 004F9B94 84C0 TEST AL,AL ...and restore this bytes 004F9B79 55 PUSH EBP 004F9B7A 8BEC MOV EBP,ESP 004F9B7C 83C4 F0 ADD ESP,-10 004F9B7F B8 40974F00 MOV EAX,Formik.004F9740 004F9B84 E8 97D7F0FF CALL Formik.00407320 004F9B89 8B1D F8F04F00 MOV EBX,DWORD PTR DS:[4FF0F8] ; Formik.00500C8C 004F9B8F E8 603EFEFF CALL Formik.004DD9F4 004F9B94 84C0 TEST AL,AL 004F9B96 75 05 JNZ SHORT Formik.004F9B9D |
![]() |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| svkp | infern0 | General Discussion | 3 | 06-05-2011 18:34 |
| The new svkp 143 | britedream | General Discussion | 3 | 09-19-2004 22:22 |