Contribute  :  Web Resources  :  Past Polls  :  Site Statistics  :  Downloads  :  Forum  
    BiW ReversingThe challenge is yours    
 Welcome to BiW Reversing
 Sunday, April 02 2023 @ 10:24 AM CEST
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

UNKNOWN PAKER

 
Post new topic   Reply to topic    www.reversing.be Forum Index -> Unpacking
View previous topic :: View next topic  
Author Message
seven
Occasional Poster
Occasional Poster


Joined: 02 Jun 2005
Posts: 30

PostPosted: Mon Oct 23, 2006 3:13 pm    Post subject: UNKNOWN PAKER Reply with quote

HI ALL ,

CAN U HELP ME WITH THIS PACKER COZ I CANT

FIND OUT WHICH PACKER UZED HERE :

hXXp://www.vb-decompiler.org/index.php?p=Download

THANX SO MUCH .
Back to top
View user's profile Send private message
haggar
Regular
Regular


Joined: 19 Mar 2005
Posts: 246

PostPosted: Mon Oct 23, 2006 6:03 pm    Post subject: Reply with quote

VMProtect 1.xx

It's not packer, it is VirtualMachine obfuscator.


Why do you want to know?
Back to top
View user's profile Send private message
seven
Occasional Poster
Occasional Poster


Joined: 02 Jun 2005
Posts: 30

PostPosted: Tue Oct 24, 2006 1:42 am    Post subject: Reply with quote

thanx haggar , doez VirtualMachine obfuscator meanz :

compressor + protector COZ B4 DUMPING THE PROGGIE

SIZE WAZ 288 KB AND WHEN U DUMP IT U GET 5.7 MB

WHICH MEANZ ITZ COMPRESSOR BESIDE PROTECTOR ,

COZ I WANT ANY TOOL CAN HANDLE VISUAL BASIC

PROGGIEZ , LAST THING HAGGAR PLZ CAN U POINT TO

THE ENTRY POINT ?

THANX SO MUCH
Back to top
View user's profile Send private message
haggar
Regular
Regular


Joined: 19 Mar 2005
Posts: 246

PostPosted: Tue Oct 24, 2006 1:05 pm    Post subject: Reply with quote

VMProtector replaces opcodes and whole procedures with emulated opcodes and poly obfuscation. It uses Virtual Machine to emulate replaced opcodes. So if you want to crack it, you must reverse Virtual Machine instructions and write your own dissasembler. As you can see, very hard job.


This particular app used very bad implemented VMProtector protection. Only TWO OPCODES are stolen from OEP. So, to remove protection from this VB decompiler, you need just to restore first two opcodes. App is VB , and first two opcodes in every VB app are

PUSH SlowGold.00426E90 - that points to VB5!.#* in file

CALL <JMP.&MSVBVM60.#100> - that points to first jump above PUSH.


But this program is demo and you will not gain anything with this.



See you.

regards
Back to top
View user's profile Send private message
seven
Occasional Poster
Occasional Poster


Joined: 02 Jun 2005
Posts: 30

PostPosted: Tue Oct 24, 2006 7:06 pm    Post subject: Reply with quote

thanx so much haggar
Back to top
View user's profile Send private message
Akrobat
New to the board
New to the board


Joined: 26 Oct 2006
Posts: 1

PostPosted: Sat Oct 28, 2006 3:14 am    Post subject: Reply with quote

All last versions of programs GPcH Soft are protected by protector DotFix NiceProtect!
Including a protector! The protector weak is removed for some seconds!
Last version VBDecompilera as is protected by this protector!
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    www.reversing.be Forum Index -> Unpacking All times are GMT + 1 Hour
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group
 Copyright © 2023 BiW Reversing
 All trademarks and copyrights on this page are owned by their respective owners.
Powered By Geeklog 
Created this page in 0.95 seconds