Reverse Engineering/Unpacking

Themida and WinLicense 2.0.1.0 (Unpacking)

Reverser - J.M.C - 2008. 10. 31. 17:42
반응형

Themida and WinLicense 2.0.1.0 (Unpacking) by LCF-AT

LCF-AT:

Today I show you an example how to unpack Themida / WinLicense

Unpack WinLicense_UnpackMe! v2.0.1.0

- Find OEP / Near OEP / stolen code
- Find IAT / Magic Jump / Use GDI32 - API will not redirect in TM / WL
- Get Full IAT / Fix VM API call´s and jump´s / Use Script
- Repair stolen code / find input and output / log results
- Delete useless section´s to reduce the target size