A small tutorial - unpacking GMO main.exe

Results 1 to 18 of 18
  1. #1
    NN - Nord & Noob mauka is offline
    MemberRank
    Jul 2004 Join Date
    1,735Posts

    A small tutorial - unpacking GMO main.exe

    On request

    Download contains:
    - Unpack script v 0.1( my first olly script )
    - Ollydbg
    - Scylla import reconstructor
    - Video tutorial

    Download link:
    Code:
    http://failiem.lv/u/ybfvvns
    GMO unpacker v0.2.txt
    GMO unpacker v0.3.txt
    Last edited by mauka; 30-01-13 at 04:55 AM. Reason: Script update


  2. #2
    Account Upgraded | Title Enabled! ggragonss is offline
    MemberRank
    Mar 2012 Join Date
    HongKongLocation
    380Posts

    Re: A small tutorial - unpacking GMO main.exe

    Thanks. It so helpful .

  3. #3
    Proficient Member R3jectZ is offline
    MemberRank
    Jun 2011 Join Date
    PhilippinesLocation
    198Posts

    Re: A small tutorial - unpacking GMO main.exe

    Quote Originally Posted by mauka View Post
    On request

    Download contains:
    - Unpack script ( my first olly script )
    - Ollydbg
    - Scylla import reconstructor
    - Video tutorial

    Download link:
    Code:
    http://failiem.lv/u/ybfvvns
    bro its a HTML only .. not video tutorial .. make a Video tutorial bro :D

  4. #4
    NN - Nord & Noob mauka is offline
    MemberRank
    Jul 2004 Join Date
    1,735Posts

    Re: A small tutorial - unpacking GMO main.exe

    swf <> avi, who cares.. If u like download 200mb AVI tutorial instead of 10mb swf.. im feel sory about u xD

  5. #5
    Apprentice hateroc22 is offline
    MemberRank
    May 2009 Join Date
    11Posts

    Re: A small tutorial - unpacking GMO main.exe

    Mauka u have Offset Edit FONT main 1.4D ?

  6. #6
    Proficient Member R3jectZ is offline
    MemberRank
    Jun 2011 Join Date
    PhilippinesLocation
    198Posts

    Re: A small tutorial - unpacking GMO main.exe

    Quote Originally Posted by mauka View Post
    swf <> avi, who cares.. If u like download 200mb AVI tutorial instead of 10mb swf.. im feel sory about u xD
    do you have 200MB Tutorial ? if you have please pm to me :D i need it bro :D

  7. #7
    Account Upgraded | Title Enabled! lstngl is offline
    MemberRank
    Sep 2010 Join Date
    199Posts

    Re: A small tutorial - unpacking GMO main.exe

    Real i just curious is there complety guıide what is the all offset story yea i know i googled i research i got this at teaory, but how can u abble to find whats offests what for what kind research u got there. i been here such a long time i saw so many coders they are all leave community, but then came new ones :D okay i don have that much time but i wanna do somthing on olly now mauka can complainant about my post he is right but i try to understand your guide :D if i could i would post about to your guide.

    But thanks anyway seems like good guide to someone.

  8. #8
    NN - Nord & Noob mauka is offline
    MemberRank
    Jul 2004 Join Date
    1,735Posts

    Re: A small tutorial - unpacking GMO main.exe

    Reversing <> Cracking ;)

    crack is like 500% easy then reverse from low to high lang.. so thouse who u think are "pro: are gays for me :F
    This script is very simply - macro

  9. #9
    Account Upgraded | Title Enabled! lstngl is offline
    MemberRank
    Sep 2010 Join Date
    199Posts

    Re: A small tutorial - unpacking GMO main.exe

    yea i did watch your script its understandable :D anyhow i want to know more than this.
    by thy way i know whats low programing and Reverse engeniring but its not good enough to do someting for myself so still im making my own projects on C# its not strong Language as i wnated to be anyway i keep searching your Topics here i hope i ll get more info from you and others.

  10. #10
    CAARL, THAT KILLS PEOPLE! SmallHabit is offline
    MemberRank
    Oct 2010 Join Date
    LatviaLocation
    231Posts

    Re: A small tutorial - unpacking GMO main.exe

    hey mauka, have some error's when search for IAT, there are some missing functions? how to deal with them? :)

    Something like this - Screenshot by Lightshot

  11. #11
    Account Upgraded | Title Enabled! lstngl is offline
    MemberRank
    Sep 2010 Join Date
    199Posts

    Re: A small tutorial - unpacking GMO main.exe

    wehats that program u are using? :D

  12. #12
    Proficient Member phit666 is offline
    MemberRank
    Apr 2007 Join Date
    197Posts

    Re: A small tutorial - unpacking GMO main.exe

    Quote Originally Posted by SmallHabit View Post
    hey mauka, have some error's when search for IAT, there are some missing functions? how to deal with them? :)

    Something like this - Screenshot by Lightshot
    Use win7 x64

  13. #13
    NN - Nord & Noob mauka is offline
    MemberRank
    Jul 2004 Join Date
    1,735Posts

    Re: A small tutorial - unpacking GMO main.exe

    Restore IT copy/paste it from any of old no-protected main.exe vers or give a try to another IT reconstructor @ http://www.manhunter.ru/underground/...pe_faylov.html

    PS. i stop dev this script ^__^ use 0.3v at your own risk
    - on process of unpacking main.exe its will create file "MAINPATCHES.txt" with offsets of Mu.exe, GG so u dont bother later to search it manualy..

    Code:
     MSG "GMO main.exe unpack script v0.3 by Mauka"  
     var Poffset
     var pos
     var mu1
     var mu2
     var sj    
     VAR addr
     mov mu1, 1 //Wip Patch close mu.exe? 1=yes 0=no
     mov mu2, 1 //Wip Patch start mu.exe? 1=yes 0=no
    
     LCLR
     BC
     BPHWC
     Estep  
     Estep 
     BPHWS esp,"r"
     ERUN
     Estep  
     Esti 
     Estep 
     Esti
     Cmt eip,"The (near) OEP, by mauka"
     
     mov pos, eip
     Loop: 
     Find pos, #6A02E8????????59C3# //Fix float error at run time
     cmp $RESULT, 0
     Jz EndLoop
     mov Poffset, $RESULT
     Log Poffset, "Float fix  Poffset = "
     Cmt Poffset,"This is the FLOAT ERROR!"
     Asm Poffset, "RETN"
     mov pos, Poffset 
     Jmp Loop
    
     EndLoop: 
     cmp mu1, 1
     jne startmu
     Mov pos, 00401000 //start offset
     Find pos, #74??????????????????????????E8????????????????????EB??????????????00??????????????????????????????????????????????E8??????????????????????????68????????68????????E8????????5959E8????????????????????0074??#
     cmp $RESULT, 0
     Jz GG0
     mov Poffset, $RESULT 
     ITOA Poffset
     MOV addr, $RESULT
     OPCODE Poffset  
     WRTA "MAINPATCHES.txt", "Start GG: "+ addr+" "+$RESULT+"  "+$RESULT_1 
     JMP GG1:
     GG0:
     Msg "U nee find and fix GG start manualy" 
     GG1:  
     cmp mu1, 1
     jne startmu
     Mov pos, 00401000 //start offset
     Find pos, #68????????68????????E8????????5959E8????????????????????0074??#
     cmp $RESULT, 0
     Jz GGSucess  
     PREOP $RESULT 
     mov Poffset, $RESULT  
     ITOA Poffset
     MOV addr, $RESULT
     OPCODE Poffset  
     WRTA "MAINPATCHES.txt", "GG Sucess: "+ addr+" "+$RESULT+"  "+$RESULT_1 
     JMP MUExecC
     GGSucess:
     Msg "U nee find and fix GG sucess manualy"  
     MUExecC:
     cmp mu1, 1
     jne startmu
     Mov pos, 00401000 //start offset
     Find pos, #74??6A006A006A10FF??????????FF??????????FF????E8????????59#
     cmp $RESULT, 0
     Jz MuClose
     mov Poffset, $RESULT 
     ITOA Poffset
     MOV addr, $RESULT
     OPCODE Poffset  
     WRTA "MAINPATCHES.txt", "Close MU.exe: "+ addr+" "+$RESULT+"  "+$RESULT_1 
     JMP MUExe
     MuClose:
     Msg "U nee find and fix 'Close' Mu.exe manualy"
     MUExe:
     cmp mu1, 1
     jne startmu
     Mov pos, 00401000 //start offset
     Find pos, #75??68????????68????????E8????????595968????????8D??????????50E8????????59596A058D??????????50FF15#
     cmp $RESULT, 0
     Jz MuErr
     mov Poffset, $RESULT 
     ITOA Poffset
     MOV addr, $RESULT
     OPCODE Poffset  
     WRTA "MAINPATCHES.txt", "Start MU.exe: "+ addr+" "+$RESULT+"  "+$RESULT_1 
     JMP End
     MuErr:
     Msg "U nee find and fix execute Mu.exe manualy"
    
    
     End:
     BC
     BPHWC
     Msg "Script finished! Dump process and fix IAT"
    Attached Files Attached Files
    Last edited by mauka; 30-01-13 at 01:25 AM.

  14. #14
    ^_^ ashlay is offline
    MemberRank
    Jun 2010 Join Date
    BrazilLocation
    888Posts

    Re: A small tutorial - unpacking GMO main.exe

    any1 can reupload the video?

  15. #15
    Enthusiast rejor is offline
    MemberRank
    Apr 2014 Join Date
    RaGEZONELocation
    34Posts

    Re: A small tutorial - unpacking GMO main.exe

    Has somebody got all of things from this topic?
    Please upload them again. Thanks so much!

  16. #16
    Apprentice amye0611 is offline
    MemberRank
    Aug 2010 Join Date
    10Posts

    Re: A small tutorial - unpacking GMO main.exe

    Seem to hard to unpacking GMO right. and noone consider this topic.
    So sad.....where are developer.....?

  17. #17
    Apprentice FeeHMandyson is offline
    MemberRank
    Mar 2014 Join Date
    12Posts

    Re: A small tutorial - unpacking GMO main.exe

    @mauka, please post the video tutorial..! thanks!

  18. #18
    Valued Member huythao229 is offline
    MemberRank
    Jul 2012 Join Date
    Viet NamLocation
    103Posts

    Re: A small tutorial - unpacking GMO main.exe

    Dear All! Reload link tutorial by mauka : http://www.mediafire.com/download/ms...p3hi/GmoTut.7z



Advertisement