Silent
February 28th, 2001, 18:17
i tried to unwrap this application:
http://www.sybase.com/detail/1,3693,1010602,00.html
(sybase's PowerDesigner 7.5 trial. warning, it's 42mb!) but i didn't get mentionable results. procdumps internal vbox-dumpers for vbox <4.2 don't work, the external (via bhrama) dumps the file, but the result doesn't look very good (maybe because some of the used dll's might be packed, too, maybe because my knowledge concerning pe's isn't the best). and for v4.3 i could only find one unwrapper wich works only on win2k
. the tutorials for v4.3 seem to be very easy, but the program i try to unwrap looks completely different (not the normal mv/cmp/jmp after the getprocaddress). so i think it may be packed with version 4.5 (http://208.240.131.116/products/vbox/download.html). anyone got:
1) a way to identify the used version of vbox?
2) a tutorial/unwrapper for version 4.5
http://www.sybase.com/detail/1,3693,1010602,00.html
(sybase's PowerDesigner 7.5 trial. warning, it's 42mb!) but i didn't get mentionable results. procdumps internal vbox-dumpers for vbox <4.2 don't work, the external (via bhrama) dumps the file, but the result doesn't look very good (maybe because some of the used dll's might be packed, too, maybe because my knowledge concerning pe's isn't the best). and for v4.3 i could only find one unwrapper wich works only on win2k

1) a way to identify the used version of vbox?
2) a tutorial/unwrapper for version 4.5