Log in

View Full Version : Armadillo !!!!


Zilot
November 27th, 2003, 08:55
New Armadillo tut I wrote yesterday. Maybe will help someone to find out the best way to unpack this protector protected files.




http://members.fortunecity.com/zilot/Tutorial/armadillo.htm<---- Web version

http://members.fortunecity.com/zilot/Tutorial/Tutorial.zip<----- For download

I'll upload installation of Trojan Remover because in the meantime there is new version

Also will upload dumped.exe and fixed.exe files

Tomorrow

Zilot

mr.x
November 27th, 2003, 13:54
Thanks Zilot

seven
November 27th, 2003, 16:51
thx

volodya
November 27th, 2003, 17:14
Zilot, you are not that bad

dreambuddy
November 27th, 2003, 17:34
Thanks Zilot for this nice and helpful tutorial.

Zilot
November 28th, 2003, 07:22
Quote:
[Originally Posted by Vladimir]Zilot, you are not that bad .


Yesta Kapitan !!!!

esther
November 30th, 2003, 21:45
Woah!!! post dissapeared!?!

Zilot
December 1st, 2003, 11:25
Hey +SplAj

did you mean this :

http://www.postsmile.com/img/default/0520.gif

siba
December 10th, 2003, 09:41
Nice Tut
Thanks for Sharing

volodya
December 10th, 2003, 14:10
Hey, Mr. ZILOT. Everything is on wasm now and the links were modified.
Waiting for zipped target.

Offtop to forum admins:
Guys, you've done brilliant job and the forum looks really nice. The only thing which upsets me is avatar. I cannot change it to my custom one

dELTA
December 10th, 2003, 15:19
Ok, try now.

volodya
December 10th, 2003, 15:27
Much, much better
Delta, thank a lot. Good job!

JMI
December 10th, 2003, 17:44
There are a whole bunch of settings in the new AdminCP which we have to check and make sure are properly set and we are still learning the new styles and the new adminCP. However, we wanted to get the Board back open as quickly as possible and, so far, it appears that we didn't lose anything too important along the way. Once I deleted 2,600,00 entries in the backup from the searchindex and word index, we were finally able to get the "restore" to work properly. We're still working on a better backup script, but time has been short for "playing" of late. Hopefully, soon it will be a litter better automated.

Regards.

+SplAj
December 14th, 2003, 10:50
Hi Zilot

NO

That was not the icon. Unfortunately 'someone' with a detached sense of humor deleted my post with my chosen icon, which was VERY appropriate for the way the topic of conversation was developing IMHO.......a picture says a thousand words.

BTW thanks for that link to nice graphical icons site I enjoyed browsing them



ciao

Zilot
December 17th, 2003, 06:41
Quote:
[Originally Posted by +SplAj]Hi Zilot

NO

That was not the icon.


I didn't see that, just RCE MSG replay with link. But seems replay works excellent http://www.postsmile.com/img/default/0654.gif, I even couldn't access to this forum via cjb.net. I thought it was down. Then Volodya told me he replayed, fortunately I had in my browser magic number
66.98.132.48.

Changes always cause frustrations http://www.postsmile.com/img/default/0524.gif

nikolatesla20
December 18th, 2003, 16:55
Good tutorial Zilot.

Armadillo continues to "advance" in its complexity. One side effect is it actually becomes easier to make an unpacker for it (disregarding nanomites), since they are bound to forget something. This is one reason Lunar_Dust was able to keep up with versions without much trouble.

I like your handling of nanomites, you found the encrypted jump length table, good work ! Lunar_Dust came up with the int3 loader as you suggested, for GetRight 5.0 beta, and it worked very effectively. (Trademarked "NanoWrap". SImply make a program to act as a debugger, and decode the jump tables just as armadillo does it, and then plop in the jump table codes and compile (jump tables as c arrays). Worked like a charm. With little modification such a tool could easily auto-extract the jump tables and build itself into a wrapper. I used OllyDbg since its easy to track down tables with it.

But alas, other hobbies hold interest at this time

Seems Armadillo becomes popular lately ?

-nt20

Zilot
December 20th, 2003, 05:04
Thanks Tesla

Maybe I'm dumb, but are Lunar Dust and NT20 same person. As far I've seen, same style, same icon.......

Quote:
But alas, other hobbies hold interest at this time


Games ?

nikolatesla20
December 20th, 2003, 11:49
Lunar_Dust and I both work together on some RCE projects, that's why we have the same icon.

Other hobbies include metalworking, (I'm getting into metalcasting, starting with aluminum.) and some electronics work again.

Just wanna say keep up the good work !

-nt20