[Release] Unpack GlobalDekaron dekaron.exe [Tutorial]

10/04/2009 13:36 KenDark#31
oh that explains a lot more...
thanks
10/05/2009 03:22 GurdyMan#32
The 4.8.1 seems to know ollydbg is onto it. It crashes immediately after hitting run to find the first ZwContinue BP.
10/05/2009 09:34 HellSpider#33
Quote:
Originally Posted by GurdyMan View Post
The 4.8.1 seems to know ollydbg is onto it. It crashes immediately after hitting run to find the first ZwContinue BP.
Well it has debugger checks but those are just regular so the PhantOm plugin will bypass them with the PEB (ProcessEnvironmentBlock) option enabled.

I will post the unpacked dekaron.exe today because some people have some issues getting it unpacked correctly.
10/05/2009 21:01 GurdyMan#34
Quote:
Originally Posted by InstantDeath View Post
Well it has debugger checks but those are just regular so the PhantOm plugin will bypass them with the PEB (ProcessEnvironmentBlock) option enabled.

I will post the unpacked dekaron.exe today because some people have some issues getting it unpacked correctly.
Well, it seems it just doesn't like my computer. Could it be the phantom driver file is 32-bit only and so it's not actually running on my 64-bit?

It's a good tut. I'm learning either way. Just not by doing. ;)

Edit: Eh, yup it's the 64-bit. I can't open any program on my computer with ollydbg1.1 even 32bit apps. LordPE shows about 30 of over 100 running processes on my computer. It doesn't even see notepad which is 64 bit. I'm gonna do some more searching, but this looks like one of those things that I'm just going to have to let others do for me.
10/05/2009 22:27 TheNevan#35
Hehe, i figured it out after a while, couldnt use the video, didnt have shockwave =_=. thanks! :D
10/05/2009 22:45 HellSpider#36
Quote:
Originally Posted by GurdyMan View Post
Well, it seems it just doesn't like my computer. Could it be the phantom driver file is 32-bit only and so it's not actually running on my 64-bit?

It's a good tut. I'm learning either way. Just not by doing. ;)

Edit: Eh, yup it's the 64-bit. I can't open any program on my computer with ollydbg1.1 even 32bit apps. LordPE shows about 30 of over 100 running processes on my computer. It doesn't even see notepad which is 64 bit. I'm gonna do some more searching, but this looks like one of those things that I'm just going to have to let others do for me.
If I remember right, Olly doesn't support 64-bit.
10/07/2009 18:22 aligabo#37
We are waiting for your tutorial..!
Give us the fishing rod...
I love you and your amazing job
10/07/2009 21:20 HellSpider#38
Quote:
Originally Posted by aligabo View Post
We are waiting for your tutorial..!
Give us the fishing rod...
I love you and your amazing job
Why are you waiting? Just download the tutorial from the first post :).
10/07/2009 23:38 -8gX#39
Fishing rod?
10/08/2009 01:25 GurdyMan#40
Quote:
Originally Posted by InstantDeath View Post
If I remember right, Olly doesn't support 64-bit.
Yeah, so far Ollydbg2.0 does, and PE Tools is an amazing substitute for LordPE.
10/08/2009 04:04 -8gX#41
PE Explorer is my favorite. PM me if you dont wanna spend 200$ on it. :)

But yes, PE Tools will work just fine too :)
10/17/2009 19:37 Bigshow107#42
mm i got question
when i make a break point on ZwContinue and i run it
its send me to other line and its gime Teminated
oh can you post the ollybg vitutral look? i liked it xD
10/18/2009 15:40 HellSpider#43
I need to remake the tutorial. They changed the packer a bit after I made the tutorial.
10/31/2009 22:24 manozabuza#44
I need to know when the tutorial will be available again. And where do I download the tools needed to use along with OllyDbg. And what they are.
10/31/2009 22:34 ~Kakkarot~#45
you download those programs from [Only registered and activated users can see links. Click Here To Register...]