|
ARTeam Tutorial Visit:
http://cracking.accessroot.com
|
http://forum.accessroot.com Unpacking NeoLite v1.0 - v1.01 |
|
Information |
Unpacking NeoLite v2.0 |
|
Target |
Smart Bomb PC Shutdown Demo v2.1 |
|
Available |
http://grinders.withernsea.com/tools/evidence_eliminator_v5.058.exe |
|
Tools |
|
|
Protection |
Neolite v1.0 - v1.01 |
|
level |
Beginner |
|
Category |
Unpacking |
|
Author |
Nilrem - 28th July 2004 |
|
Requirements |
Windows XP, IE 5.5, (1024x768) and above for best viewing |
|
0.
Introduction
|
|
Wow, I've written more than one tutorial in a month! That hasn't happened in a while. Well here we have NeoLite v1.0 - v1.01, but isn't it easier or the same as NeoLite v2.0, nope, it's just as easy, but not as quick. 8-) There might be a quicker way, but I couldn't find any documentation so that's why I am writing this tutorial. Before reading this tutorial I suggest you read my tutorial on unpacking version 2.0 of this particular protection: Download:
http://grinders.withernsea.com/tutorials/unpacking_neolite_v2.0.rar |
|
1.
Unpacking Neolite v1.0 - v1.01
|
|
Ok, well where do we
start? At the beginning of course. Sorry, I've always
wanted to say that. 8-)
|
|
2. Dumping
The Target
|
|
I should not need to tell you how to
dump the target because you should have learnt that
whilst reading the tutorial I told you to read, naughty
naughty. 8-) |
|
3.
Rebuilding the IAT
|
|
In most cases (that I have come across) the unpacked targets
of a NeoLite packed program do not need the IAT rebuilding, that is not the case
with Evidence Eliminator. Launch ImpREC (Import Reconstructor, I really want to
shake the hand of the author of this excellent utility). Select Evidence
Eliminator from the drop down list of active processes. Change the OEP, Image
Base - OEP = Real OEP, so 00400000 - 00408F94 = 8F94, so enter that into the OEP
box and click the 'IAT AutoSearch' button. Then click the 'Get Imports' button,
as you can see there is nothing left to fix as what is found is valid. Now click
the 'Fix Dump' button and fix our dump. 8-) |
|
4. Conclusion
|
|
Lesson Learnt Hopefully you have learnt that if you
can't find any documentation on something, then try it
yourself, experiment, remember "I hear and I forget, I
see and I remember, I do and I understand.". I know I
said that I would (in the conclusion of my last
tutorial) write a tutorial on inline patching NeoLite,
but it really isn't neccessary, if you can inline patch
UPX or Aspack then you can inline patch NeoLite. |
|
8. Greetingz
|
|
[MAIN TEAM] [Nilrem] |