티스토리 뷰

반응형

Themida and WinLicense 2.0.1.0 (Unpacking) by LCF-AT

LCF-AT:

Today I show you an example how to unpack Themida / WinLicense

Unpack WinLicense_UnpackMe! v2.0.1.0

- Find OEP / Near OEP / stolen code
- Find IAT / Magic Jump / Use GDI32 - API will not redirect in TM / WL
- Get Full IAT / Fix VM API call´s and jump´s / Use Script
- Repair stolen code / find input and output / log results
- Delete useless section´s to reduce the target size



'Reverse Engineering > Unpacking' 카테고리의 다른 글

VMProtect 1.70.4 (Unpacking)  (2) 2009.01.11
ASProtect-2.4-SKE-Manual-Unpacking  (0) 2008.08.15
Unpack 강좌 종합  (5) 2008.06.05
yoda.s.Protector.v.1.03.2 mup  (5) 2008.04.01
upack_v0.37_-_dwing_mup  (0) 2008.04.01
pecompact_1.68_-_1.84_mup  (0) 2008.04.01
pe_diminisher_v0.1_mup  (0) 2008.04.01
댓글