📚 OpenRCE is preserved as a read-only archive. Launched at RECon Montreal in 2005. Registration and posting are disabled.








Flag: Tornado! Hurricane!

 Forums >>  Debuggers  >>  Unpacking Themida

Topic created on: July 29, 2009 17:28 CDT by Cluster .

hi,
i want to unpack GameGuard that is protected by Themida.
I dont know which version it is because PEiD says nothing found. The first problem that i get is, when i open it in Olly, it just load a few lines and then olly crashes. Is there a solution for this?

  gnukish     July 30, 2009 12:43.11 CDT
Gameguard emulator/killer, find it ... study it, and use it.

Game hacking isn't easy because a lot of games are packed with custom/known packers. There's also some anti-debug/anti-disassembly tricks involved while reversing games. So try referring the OpenRCE library and a few books.

  jumpzero     July 30, 2009 20:25.47 CDT
well, ollydbg has a bug when it analyzes certain instructions concerned with fpu

there are several patches out there which fixes it, i'm using phant0m plug in.

or just stop the debugger on system-break, and edit the binary near entrypoint u see. just make any of ff ff ff ff's into 90(nop)s.

or of course u can write your own patch.

it might trigger the self modification senser of themida, so i suggest using a patch.

i'm afraid to tell u it won't be easy to unpack themida and recover the original exe when u don't even know these basic things.(no offense)

  cli4fun     August 18, 2009 17:44.38 CDT
hi Cluster, i would like to know your progress with this :)

as i'm learning too, we can share some ideas maybe ...

unfortunately i have just wine to run those "targets" that use gameguard.

i have to install windows i guess :/

but anyway, i hate that "rootkit", i was looking some days ago to play some games in the linux, then i was unhappy because most online games use this thing :(

i would like to ask the experienced crackers or reversers that have dealed with it ...

is possible to patch just the "target" and lave the gameguard?

i sure i can't run gameguard with wine, so thats the only way ...

  cli4fun     August 19, 2009 13:37.56 CDT
Today i downloaded the demo of "Themida", what was the surprise? :P

Its packed with Themida too, so no way to try study some apps with it through wine.

Maybe some years ahead i try again!

Anyway, if you Cluster got some good news about it i would like to hear about.

Good luck with it.

  Sirmabus     August 20, 2009 05:14.22 CDT
Check out http://tuts4you.com and it's forums..

Note: Registration is required to post to the forums.

There are 31,328 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Question about memor...
Dec/12


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit