![]() |
|
#1
|
||||
|
||||
![]()
not a big deal but I hope u like it ,Thanks to Carbon For unpack file.
https://docs.google.com/file/d/0B402...SzA/edit?pli=1
__________________
Ur Best Friend Ahmadmansoor ![]() Always My Best Friend: Aaron & JMI & ZeNiX |
The Following 22 Users Gave Reputation+1 to ahmadmansoor For This Useful Post: | ||
arlequim (02-06-2014), benney (02-11-2014), besoeso (02-06-2014), canopus (02-10-2014), chessgod101 (02-11-2014), copyleft (02-08-2014), Dreamer (02-05-2014), giv (02-06-2014), h8er (02-11-2014), Insid3Code (02-05-2014), Kla$ (02-06-2014), KuNgBiM (02-08-2014), mr.exodia (02-05-2014), nikkapedd (02-10-2014), nikre (02-06-2014), NoneForce (02-09-2014), softgate (02-06-2014), tonyweb (02-08-2014), ZeNiX (02-08-2014) |
The Following User Says Thank You to ahmadmansoor For This Useful Post: | ||
Indigo (07-19-2019) |
#2
|
||||
|
||||
The tut is so direct.
I love it. I saw it twice and spent a few time to adjust my IDA to work with WinDbg. My system is Windows 8.1 x64, so it is a little tricky. Then, one question pops up. WinLicense x64 does not have any anti-debug protection? I thought it will detect my debugger. |
The Following User Says Thank You to ZeNiX For This Useful Post: | ||
Indigo (07-19-2019) |
#3
|
||||
|
||||
Hi ZeNIX and thanks that u like it .
the unpacked file use the lost options in packing ,that why not detect ur debugger. That all .
__________________
Ur Best Friend Ahmadmansoor ![]() Always My Best Friend: Aaron & JMI & ZeNiX |
The Following User Says Thank You to ahmadmansoor For This Useful Post: | ||
Indigo (07-19-2019) |
#4
|
||||
|
||||
Winlicense x64 has anti-debug stuff, but it's not really strong. I believe only some minor PEB changes (easy), ProcessDebugPort and ProcessDebugFlags check. Also some anti guard page, but im not 100% on that
__________________
x64dbg: http://x64dbg.com My Blog: http://mrexodia.cf |
The Following User Says Thank You to mr.exodia For This Useful Post: | ||
Indigo (07-19-2019) |
#5
|
||||
|
||||
Oh, I forgot to ask one more thing.
Is there anti-dump tricks on WinLicense x64? Such as CPIUD, Heap Stack,....? |
The Following User Says Thank You to ZeNiX For This Useful Post: | ||
Indigo (07-19-2019) |
#6
|
|||
|
|||
Hi,Ahmadmansoor
I test u tuts,but I can not setup the IDA Process option correctly.I do not know how fill the Parameters option.It pop up the warning message:The file can't be loaded by the debugger plugin.Please verify that the parameters are valid.I install WinDDK contains the Debuggers directory.Please tell that How config the IDA 64 + WinDDK dbgsvr.exe,thank you! |
The Following User Says Thank You to [ID]ZE For This Useful Post: | ||
Indigo (07-19-2019) |
#7
|
|||
|
|||
[ID]ZE, if you are using ida v6.1 go to the folder "cfg" and open the file ida.cfg
search this string Code:
// // Location of Microsoft Debugging Engine Library (dbgeng.dll) // This value is used by both the windmp (dump file loader) and the windbg // debugger module. Please also refer to dbg_windbg.cfg // (note: make sure there is a semicolon at the end) //DBGTOOLS = "put here the full path of your windbg install folder"; |
The Following User Says Thank You to nikkapedd For This Useful Post: | ||
Indigo (07-19-2019) |
#8
|
||||
|
||||
@[ID]ZE : what u did and not work the steps is very clear .
run IDA x64 version ( if u have it ![]() u will find it in : Quote:
Done .
__________________
Ur Best Friend Ahmadmansoor ![]() Always My Best Friend: Aaron & JMI & ZeNiX |
The Following User Gave Reputation+1 to ahmadmansoor For This Useful Post: | ||
stantheguy (06-11-2014) |
The Following User Says Thank You to ahmadmansoor For This Useful Post: | ||
Indigo (07-19-2019) |
#9
|
||||
|
||||
Very interesting, do you know if the segments area that shall be analyzed would be the same each time in the low security settings.Or have spesific signaturs
Thinking off doing a plugin script to automate the process if so. |
The Following User Says Thank You to Storm Shadow For This Useful Post: | ||
Indigo (07-19-2019) |
#10
|
||||
|
||||
Here you go @ahmadmansoor
PHP Code:
if error get it here.(RAW) http://pastie.org/9381756 check if it produces code correct, if correct. procced to ScullaHide Winlicense testfile Easy settings TIGER64 (Red) UnpackmeWLx64.zip Last edited by Storm Shadow; 07-13-2014 at 02:43. |
The Following 2 Users Gave Reputation+1 to Storm Shadow For This Useful Post: | ||
ahmadmansoor (07-13-2014), DMichael (07-13-2014) |
The Following User Says Thank You to Storm Shadow For This Useful Post: | ||
Indigo (07-19-2019) |
#11
|
||||
|
||||
@Storm Shadow: Just wondering, why is my name in the script?
Greetings
__________________
x64dbg: http://x64dbg.com My Blog: http://mrexodia.cf |
The Following User Says Thank You to mr.exodia For This Useful Post: | ||
Indigo (07-19-2019) |
#12
|
||||
|
||||
Quote:
![]() I thought you didnt mind. ![]() NB!! if it dosent jump to right code after script, it didnt find the right IAT. |
The Following User Says Thank You to Storm Shadow For This Useful Post: | ||
Indigo (07-19-2019) |
#13
|
||||
|
||||
@Storm Shadow : thanks for concern of this topic ,Now I am out trying to do some work ,back and try ,and movie flash will always be Welcome
![]()
__________________
Ur Best Friend Ahmadmansoor ![]() Always My Best Friend: Aaron & JMI & ZeNiX |
The Following User Gave Reputation+1 to ahmadmansoor For This Useful Post: | ||
Storm Shadow (07-13-2014) |
The Following User Says Thank You to ahmadmansoor For This Useful Post: | ||
Indigo (07-19-2019) |
![]() |
Thread Tools | |
Display Modes | |
|
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Winlicense (Themida) 2.4.6 x64 Help for Bypass/Unpack | Reaper | General Discussion | 2 | 04-30-2021 18:37 |