General Subjects
Anything GameHacking related, not multiplayer, that doesn't go in the other subforums below.

Go Back   The World of Game Hacking > General GameHacking > General Subjects

IRC Rules
Post New Thread  Reply
 
LinkBack Thread Tools Display Modes
  (#1 (permalink)) Old
Posting Well
 


16-Bit Member

 
Posts: 25
Join Date: Jan 2009
Last Online: 07-21-2009 10:21 PM
Reputation: W1z8it is on a distinguished road
User is Offline
   
Unpacking Themida 2.0.8.0 - 06-28-2009, 10:30 PM

How would I go about unpacking an exe that was packed with Themida 2.0.8.0?
  
Reply With Quote
  (#2 (permalink)) Old
Crew
 


64-Bit Member

 
Posts: 170
Join Date: Sep 2006
Last Online: Today 04:49 AM
Reputation: Ksbunker is on a distinguished road
User is Offline
   
re: - 06-29-2009, 07:20 AM

Show's how to bypass one trick implemented by many packers.

Basically, find the 'pushad', usually one of, if not the first instructions. Step over. Hardware breakpoint dump value in esp. In other words, when 'popad' is executed break. Typically thereis either a jmp to OEP is push/ret to OEP after the popad. Once at OEP, dump file and fix imports with ImpRec.

How the ESP trick actually works - KOrUPt

Of course, themida may not use this method in which case my advice would be useless. But a cool trick nonetheless to know!

Regarding specific themida help, not sure... maybe BiW Reversing - The challenge is yours can help.
  
Reply With Quote
  (#3 (permalink)) Old
Posting Well
 


16-Bit Member

 
Posts: 25
Join Date: Jan 2009
Last Online: 07-21-2009 10:21 PM
Reputation: W1z8it is on a distinguished road
User is Offline
   
06-29-2009, 10:47 AM

Quote Originally Posted by Ksbunker View Post
Show's how to bypass one trick implemented by many packers.

Basically, find the 'pushad', usually one of, if not the first instructions. Step over. Hardware breakpoint dump value in esp. In other words, when 'popad' is executed break. Typically thereis either a jmp to OEP is push/ret to OEP after the popad. Once at OEP, dump file and fix imports with ImpRec.

How the ESP trick actually works - KOrUPt

Of course, themida may not use this method in which case my advice would be useless. But a cool trick nonetheless to know!

Regarding specific themida help, not sure... maybe BiW Reversing - The challenge is yours can help.
I'll check it out, cheers.
  
Reply With Quote
  (#4 (permalink)) Old
Crew
 
Ribs's Avatar
 


32-Bit Member

 
Posts: 90
Join Date: Jul 2008
Location: TEAM {RES} & WOGH
Last Online: 02-06-2010 03:32 PM
Reputation: Ribs is on a distinguished road
User is Offline
  Send a message via Yahoo to Ribs  
06-29-2009, 05:06 PM

This is here not a ReV Board so try other way....no crack things here....and if so wrong topic also...

R
  
Reply With Quote
  (#5 (permalink)) Old
Posting Well
 


16-Bit Member

 
Posts: 25
Join Date: Jan 2009
Last Online: 07-21-2009 10:21 PM
Reputation: W1z8it is on a distinguished road
User is Offline
   
06-29-2009, 05:30 PM

Quote Originally Posted by Ribs View Post
This is here not a ReV Board so try other way....no crack things here....and if so wrong topic also...

R
Eh?..
  
Reply With Quote
  (#6 (permalink)) Old
n00bie
 


8-Bit Member

 
Posts: 8
Join Date: Jun 2009
Last Online: 07-10-2009 07:14 AM
Reputation: bofoverflo is on a distinguished road
User is Offline
usa
  Send a message via AIM to bofoverflo  
06-30-2009, 03:45 AM

Quote Originally Posted by W1z8it View Post
Eh?..
Unpacking as in cracking. try out ARTEAM REDIRECT. It has everything you need in the forums.
  
Reply With Quote
  (#7 (permalink)) Old
Posting Well
 


16-Bit Member

 
Posts: 25
Join Date: Jan 2009
Last Online: 07-21-2009 10:21 PM
Reputation: W1z8it is on a distinguished road
User is Offline
   
06-30-2009, 12:30 PM

Quote Originally Posted by bofoverflo View Post
Unpacking as in cracking. try out ARTEAM REDIRECT. It has everything you need in the forums.
I'm not cracking anything, I just wanna see how a game cheating device program ticks...
  
Reply With Quote
  (#8 (permalink)) Old
Supervisor
 
[Psych]'s Avatar
 


256-Bit Member

 
Posts: 1,615
Join Date: Jan 2008
Reputation: [Psych] will become famous soon enough
User is Offline
   
07-01-2009, 05:16 PM

If you have zero unpacking experience, then going after Themida is like trying to get to the second floor of your house with no stairs... or something... heh

You can't just breeze your way through using simple tricks which work on simple packers. Themida is a protector, and as such employs various techniques to deter reversing. However, provided you can setup your Olly well, then there are some ollyscripts around that will take care of plenty of targets. It's a cheap way out, but it may work for you, so maybe do that. Web... go... now



“I can't be bothered with been a ba$tard these days. It's too much effort”. ~Apache
Rules <> Search <> PM
  
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes




New To Site? Need Help?


All times are GMT +1. The time now is 09:57 PM.


Powered by vBulletin
Copyright ©1995 - 2009 GameHacking.com & CES