What to do if i can't run the app to main windows, since the app do not run at all without licence? (TwinrNA2.0.18beta)
get the other ollyscript [Only registered and activated users can see links. Click Here To Register...]Quote:
I know but the script need to be run while debugging the app to its main windows, and to do so i need a valid licence because TwinrNA2.0.18beta don't run at all without licence :s
So the script always gime
OllyScript error!
Error on line 35
Text: lc
No such command: lc
(I use OllyScript v0.92, odbg110 9in1 for Themida, PhantOm Plugin v1.54, OllyDump v3.00.110, StrongOD v0.2.3.328)
EDIT : always after step 3 i get "TODO: <File description> has stopped working"Quote:
Do this run the unpacker 1.0 script (easily method)
1)HWID or TRIAL check ==> YES
2)temporary memory direct HWID patch==> NO
3)continue the script
4)script finished ! all patches are written into a new file now
it will appear a message you can run whenever u like and press F9 it will start TwinR..... or continue to get the IAT at the OEP
Quote:
Hi,
I alraedy unpacked TwinrSEA 20.25 yesterday with my unpacker script!After unpacking the app starts with the message NAG then you get a nag about the aaaa.edit file.Then you can get a runtime message NAG and then the unpacked file closed.If you remember that Twinr has to debug it to kill the runtime error nag and then you have to correct the addresses for the x & y coordinates if you can also remember this from some older Twinr versions!
004FC5ED /E9 AE1B1700 JMP 0066E1A0 OEP
IAT start
008692CC 77DA5DCF ADVAPI32.RevertToSelf
IAT end
$+116C >74CB4BAF oledlg.OleUIBusyW
$+1170 >00000000
If you now use UIF then enter as new IAT address 008790AC
New IAT start
008790AC 77F4157D ntdll.RtlGetLastWin32Error
New IAT end
$+CE4 >76BB32DD psapi.EnumProcesses
$+CE8 >00000000
Now you can dump & fix.And now you can debug the unpcked file.
Do this run the unpacker 1.0 script (easily method)
1)HWID or TRIAL check ==> YES
2)temporary memory direct HWID patch==> NO
3)continue the script
4)script finished ! all patches are written into a new file now
it will appear a message you can run whenever u like and press F9 it will start TwinR..... or continue to get the IAT at the OEP