![]() |
|
|
|
#1
|
|||
|
|||
|
I just think that its better that when topics of bypassing protections in a commercial app are discussed, its better to do so in private sub-sections of the forum rather than in a thread thats visible to everyone on the internet including non-members of the forum.
If I google "Armadillo unpacking 9.64" , this thead is shown among the top 5 hits. Nothing wrong @Wilson Bibe - till the author of the author decides to sue you for the damages, if they can trace out your "real" identity.That's why I say that these things should be done privately ...I hope that this thread can be moved to a private sub-section of the forum. Thats all ![]() P.S : Just to avoid any members saying that I am unable to recover the scrambled imports, I'd posted that screenshot showing that was able to recover all the imports without issues. No super-powers needed for that
|
|
#2
|
|||
|
|||
|
@TechLord:
Did you do the "Junk Marking", to see the decrypted code and disable emulation or is there an easy way? I get to see where the Security.Dll (I think its the security dll, cause if I disable the writes JE/alloc it will say can't allocate Dll error) is loaded, what loads it and stuff, also I got to see where the decrypted code gets written for the first time. But I couldn't find the second Junk marker. Still trying... and its frustrating.. Also I've tried using UIF, and my manual splicing fix still works, then attached the memory regions missing(like the one I believe is the Security Dll and the one with size 0E6000H) but the dump crashes. I thing I am missing the API redirection/emulation Fix. I wish I could put all of this in a video. Quote:
Got past the second Junk Marker its actually a Call that decrypts the code pages, I believe I am at the Import Redirection itself, need help now. Code:
Anything Seems familiar? 1. http://i.imgur.com/dgzYpm7g.png 2. http://i.imgur.com/F242Krhg.png 3. http://i.imgur.com/8WhNlCkg.png Code:
So here is a video, check it out.. I am getting almost 740 api's but still can't get the dump working. Video Oh I missed it, the error I get is "Out of Memory" Come on Guys, its about time, someone helped me... Ben Last edited by Benten; 10-27-2017 at 19:18. |
|
#3
|
|||
|
|||
|
@TechLord,where you at I need help man... still waiting for that tut
|
![]() |
| Tags |
| armadillo, armadillo unpacking, import elimination, tutorial request |
| Thread Tools | |
| Display Modes | |
|
|