|
#1
|
|||
|
|||
Visual Protect
I have a target that is protected with visual protect and I havent found very much info on unpacking it, if someone could point me in the right direction I would be most grateful.
I found one tut on unpacking with TRW and i'm using Olly |
#2
|
||||
|
||||
I have a tut for OllyDbg, but it's in french, I'll upload it if you want it, it's easy to understand, the screenshots explain everything. If not, post the target here, I'm sure someone will right one for you or guide you on how to unpack it.
|
#3
|
|||
|
|||
Thanks
I cant download it if you posted it here( the tut), i dont have enough posts to make downloads !
The target is Stormpredator it can be downloaded from here h**p://www.stormpredator.com Many thanks bukkake Last edited by Spotted Horse; 09-10-2004 at 10:55. |
#4
|
||||
|
||||
Must be your lucky day, the tut I have is for an old version of StromPredator, but still works for the new version, I just tried it.
Since you can't download, I'll try to explain here. Run Olly, and set it like this (Options->Debugging options): In SFX: "Trace entry real blockwise", and enable "Pass exceptions to SFX extractor" Load the target, press F9, you get that "Visual Protect trial" box, click "try" button, then let OllyDbg trace it, it will land in the EOP (0047CAE0), then dump the target. Start ImportRec, enter the EOP (7CAE0), then press "Get import", then "show invalid", then click "Autotrace", it will take a few seconds, so just be patient. Delete the thunk at RVA 00083818, double click thunk RVA 003B00E0, choose module "kernel32.dll", then scroll down to "Kernel32.GetProcAdress", should be "ord:0191", select it then click ok, then click "Fix dump", and choose the file you dumped with OllyDbg, target unpacked and no more nag window |
#5
|
|||
|
|||
I made license for VisualProtect self and XNView DeLuxe (first version).
It's very easy and need only VisualProtect and all!!! |
#6
|
|||
|
|||
I have a bug in windows xp and imprec gives me a message that it cant run tracer !?!?!? I followed your to post to a tee, but this damn windows xp is the biggest pain in the ass after you have a virus in the system!!! snag it, evidence eliminator, internet explorer ( i'm running Opera) and 4 other programs have the same problem as imprec...........they dont run right !
Thanks a million for the tut bukkake its just turned out to be a waste of time for us all until i get windows fixed Last edited by Spotted Horse; 09-11-2004 at 05:11. |
Thread Tools | |
Display Modes | |
|
|