Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 01-09-2004, 21:03
R@dier
 
Posts: n/a
Here is a quick rundown

Load into Oly

0063D000 > 53 PUSH EBX
0063D001 55 PUSH EBP
0063D002 8BE8 MOV EBP,EAX <---------------F7 till here
0063D004 33DB XOR EBX,EBX
0063D006 EB 60 JMP SHORT Target.0063D068


goto dump window
Ctrl G enter the value of the esp register
set a breakpoint on hardware access dword on the address in the ESP register

press F9

0063D2CB 5D POP EBP
0063D2CC 5B POP EBX <---- you will stop here
0063D2CD -E9 145EE7FF JMP Target.004B30E6 <---- jump to OEP
0063D2D2 0000 ADD BYTE PTR DS:[EAX],AL

F7 until you hit the oep

004B30E6 55 PUSH EBP <--- OEP
004B30E7 8BEC MOV EBP,ESP
004B30E9 6A FF PUSH -1
004B30EB 68 70444C00 PUSH Target.004C4470
004B30F0 68 4C154B00 PUSH Target.004B154C


Use olydump plugin and enjoy your unpacked program


Best Wishes

R@dier
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Armadillo 8.6 unpacking problem eAGLe_eYe General Discussion 8 03-11-2013 22:43
Problem unpacking a Morphined .exe lordnasty General Discussion 4 06-27-2005 07:24
Manual Unpacking problem Nilrem General Discussion 15 01-10-2004 17:41


All times are GMT +8. The time now is 00:13.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )