girl
April 18th, 2004, 19:22
unpack it
I'm a chinaese gril
help me
thankyou
I'm a chinaese gril
help me
thankyou
View Full Version : unpack me





maybe compatible issues
| [Originally Posted by esther]1. why you need to unpack it? For fun and laughter 2. why we need to unpack it? To help her to unpacked it,if you suceed in unparking it she give you a kiss LOL 3. what proctector's name is? (is it your protector?) Dunno,doesn't run in my win2k,maybe I have softice installed ![]() Update: It doesn't run even softice disavbled maybe compatible issues |


push dword ptr fs:[0]
push esp
sub dword ptr [esp], 4
mov fs:[0], esp ; <- olly v 1.08b will hang after single stepping this
pop eax
pop dword ptr fs:[0]
| [Originally Posted by evaluator]ok, in decrypted protector section I see api name ZwQueryInformationProcess; on XP this breaks 2 time; second time this api called with parameter 7; traced it.. so it works like IsDebuggerPresent, but gives info from KPEB(Ring0 PEB); So this is, why can detected Ring3 API debuggers; |

Or maybe he taught Kayaker how it worked.
Anyway, well worth the read, as Kayaker generally goes deeper into the code then others generally do. Must be because he spends so much time "gliding over the surface" [in his Kayak] every chance he gets.
learning quite a few tricks...
LOL. Also, override GetTickCount and return a constant value always..piece of cake. Now just have to dump at OEP. Well, OEP is a little harder to find, because of stupid other checks, but it's easy manually, just hard automated. That's why I never finished yet, got busy with other things.| [Originally Posted by evaluator]curious, but i tried search for word "ZwQueryInformationProcess", & search sux because too much long word?? can you fix it? |
)