首页
社区
课程
招聘
[转帖]ObsidiumUnpacker by winndy
发表于: 2009-12-2 22:27 4844

[转帖]ObsidiumUnpacker by winndy

2009-12-2 22:27
4844
ObsidiumUnpacker by winndy

FROM :CRACKL@B

ObsidiumUnpacker by winndy
winndywinndy This quote was last edited by winndy on 2009-11-28 20:43

http://www.unpack.cn/viewthread.php?tid=42938

ObsidiumUnpacker


winndy

CNwinndy@hotmail.com


The unpacker is not fully tested. Any bugs or feedbacks ,please contact me.

Use at your own risk!
1 Usage


Long option Short option Comment
--unpack -f The full path name of the target
--injectdll -i The full path name of the dll to be injected when stop at OEP
--funcname -n The function name to be called of the injected dll.The default name is DoJob.int DoJob(void* pData)The pData points to a structure.The first DWORD is the ImageBase of the target.The second DWORD is the ImageSize of the target.The third DWORD is the PID of the target.
--patch_registered Patch sdk function ‘isRegistered’ return true.Sometimes,this will cause error.
--DONT_PARSE_STOLEN Do not clear the junk code in the raw stolen code.If the unpacker is hang up, try to use this option.
--BE_QUIET Don’t ask the user when unpacking is done.
--help -h Print usage.





SDK fix is not supported yet.
2 Example

2.1 The simple example


ObsidiumUnpacker.exe --unpack=c:\testob.exe

Or ObsidiumUnpacker.exe -f c:\testob.exe


2.2 Use ObsidiumUnpacker as a loader, and inject a dll to crack it.


ObsidiumUnpacker.exe --unpack=c:\obsidium.exe --injectdll=c:\InjectToObsidium.dll

Or ObsidiumUnpacker.exe -f c:\obsidium.exe –i =c:\InjectToObsidium.dll

This will load the obsidium.exe and inject dll to crack it.


ObsidiumUnpacker.exe --unpack=c:\obsidium.exe --injectdll=c:\InjectToObsidium.dll --patch_registered

Or ObsidiumUnpacker.exe -f c:\obsidium.exe –i =c:\InjectToObsidium.dll --patch_registered

This will load the obsidium.exe and inject dll to crack it,and it will show “registered”.But this probably cause error.For obsidium v1.3.6.4 it will cause error.


If you have a customized function name,you can use like this:

ObsidiumUnpacker.exe -f c:\obsidium.exe -i =c:\InjectToObsidium.dll --funcname=YOURFUNCTION


2.3 be quiet option


ObsidiumUnpacker.exe --unpack=c:\testob.exe --BE_QUIET

Or ObsidiumUnpacker.exe -f c:\testob.exe
--BE_QUIET

This will cause the unpacker exit after it finishes its work.


3 History

2009.11.28

V 0.1 beta

Supported Obsidium version:

V1.3.5.7

V1.3.6.0

V1.3.6.1

V1.3.6.3

V1.3.6.4

SDK is not supported yet.

OS: WinXP SP3, Vista, other OS is not tested.
4 Bugs and Test

If you got bugs,please contact me.

The target size is limited to below 3M.

And the target must not be commercial software.

If the target is dll, you should also provide the exe associated with the dll.

And you must provide both the original file and the packed file.

The name of the packed file has the suffix of the version number of Obsidum and the OS.

For example,If the exe is aaa.exe,the and the obsidium is v1.3.6.4, the OS is XPSP3,the packed file name will be aaa_Ob1364_XP_SP3.exe.

And I don’t guarantee all the bugs will be fixed.Sorry.
5 Greetings

Reserved.

If you find some bugs, your name probably will be here. J

[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)

收藏
免费 1
支持
分享
最新回复 (13)
雪    币: 97697
活跃值: (200834)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
2
http://rapidshare.de/files/48772264/tmp.zip.html
2009-12-2 22:28
0
雪    币: 97697
活跃值: (200834)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
3
winndy

I reproduced it possible?

Hope to bring about a good tool for.
2009-12-2 22:33
0
雪    币: 198
活跃值: (1585)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
4
unpack上参加测试都要支付10UB,呵呵。
2009-12-3 08:05
0
雪    币: 440
活跃值: (737)
能力值: ( LV9,RANK:690 )
在线值:
发帖
回帖
粉丝
5
顶一个
打算过几天再公开的

卖不卖UB是我的自由。
2009-12-3 09:13
0
雪    币: 1485
活跃值: (884)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
6
支持winndy!
2009-12-3 13:46
0
雪    币: 97697
活跃值: (200834)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
7
Thank you, looking forward to here.
2009-12-3 16:17
0
雪    币: 304
活跃值: (82)
能力值: ( LV9,RANK:170 )
在线值:
发帖
回帖
粉丝
8
晕死, 早知道我就不下unpackcn那个了...
2009-12-4 08:41
0
雪    币: 161
活跃值: (261)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
9
感謝大大分享.
2009-12-4 09:44
0
雪    币: 2411
活跃值: (1412)
能力值: ( LV4,RANK:50 )
在线值:
发帖
回帖
粉丝
10
支持 winndy 和 林板.
2009-12-4 16:10
0
雪    币: 233
活跃值: (11)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
11
过来支持一下,还是很不错的东西
2009-12-4 22:12
0
雪    币: 370
活跃值: (15)
能力值: ( LV9,RANK:170 )
在线值:
发帖
回帖
粉丝
12
出口转内销?
2009-12-4 22:54
0
雪    币: 12348
活跃值: (5113)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
13

看来是来晚了哟
2010-10-16 11:40
0
雪    币: 97697
活跃值: (200834)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
14
Google.

Программное обеспечение выпуска и Windows Crack Обучение
Нам-Dabei Guanyin Бодхисаттва Нам без митабха
上传的附件:
2010-10-16 11:54
0
游客
登录 | 注册 方可回帖
返回
//