Reverse Engineering/Unpacking
Themida and WinLicense 2.0.1.0 (Unpacking)
Reverser - J.M.C -
2008. 10. 31. 17:42
반응형
Themida and WinLicense 2.0.1.0 (Unpacking) by LCF-AT
LCF-AT:
Today I show you an example how to unpack Themida / WinLicense
Unpack WinLicense_UnpackMe! v2.0.1.0
- Find OEP / Near OEP / stolen code
- Find IAT / Magic Jump / Use GDI32 - API will not redirect in TM / WL
- Get Full IAT / Fix VM API call´s and jump´s / Use Script
- Repair stolen code / find input and output / log results
- Delete useless section´s to reduce the target size