paco
March 22nd, 2004, 05:46

First of all , I introduce myself as a newbie in unpacking. I read a lot of tutorials and forums but I'm still not able to unpack a file called Dont be lame. .This program is packed with bit-arts by Read the FAQ sofware wrapper (crunched/PE heuristic as checked by PEiD) . It has no evaluation possibility and you must to be connected to their server for validation before the software can be unpacked on the drive.
I tried to manually unpack it but the dumped file is always below the original weight ( 1.5Mb and the packed file weights 4.47Mb) . The Import segment is always destroyed each time I disassemble the file.When I use Ollydbg, it always warns that the Module Entry Point is outside the range... . This is very confusing to me and I can't find the OEP.
When I read Heathcliff tute about fusion v3 (bit-arts), I thought that I found my way. Unfortunately the approch was quite different because here I have no demo or evaluation version available.
I spent more than three months, using a lot of tools ( SI/PEiD/Revirgin/Ollydbg/IDA Pro...) without success, so questions :
1- Is it possible that an unpacked file weights lower than the packed one ?
2- How can I achieve this unpacking without connection to their server ?
3- Does anyone have experience with this kind of file or protection?
Any help will be highly appreciated.
Tks for helping me cause I'm really newbie . I came to this forum for education purpose and as French-speaking, it is also an opportunity to improve my English. So sorry for all the mistakes I made.
Regards
Paco