Quote:
Originally Posted by vandermere
Sounds like BS to me :-(
|
Well it is not. Here is the stripped .exe as proof.
Short how to do it yourself (thx VolX):
Get OllyDbg.
Get OllyDbgScript (or use the one supplied)
Watch the video in the .zip (you will learn all that it is to learn from this - DO NOT MISS IT)
You will also need PEiD, ImportREC (got it cracklab.ru - google translate is your friend), Explorer Suite (free - google it) and of course latest OG Walker (10.8.8)
Open .exe in OllyDbg and run the script as shown. Use ImportREC to add references to the freshly unpacked .exe and modify the start point with CFF Explorer.
Then grab a decompiler (i use IDA) and a hex editor (i use HxD) and get yourself busy :P
______
Why OG ? Simple - any attempt to unpack the lineageii.dll has broken it and simply ends up in error or just doesn't work. Plus, debugging with L2 active could prove to be a pain in the ***. I am pretty sure that IG verify system is now the same with OG.
Please contribute to this as i don't think i have the experience required in doing this all by myself.
Regards