|
RL!dePacker v1.5 |
:: Tehnical info:
RL!dePacker
has a build in option to detect OEP. However this option does not work with
VB (always use FindOEP! function with VB applications and Force to manual
OEP?) and some packers. So if RL!dePacker can not unpack the file use FindOEP! function to detect correct
OEP, but use it only as a second resort since it can be jammed!
° Option Force OEP to manual address is used to force stopping on manual OEP address,
use this option ONLY if packer can not be unpacked (the target runs instead
of breaking at OEP or dumps at wrong OEP).
° Option Correct OEP to manual address is used
correct OEP in PE header of the unpacked file.
° Option Hide
unpacker from detection is used hide debugger from being detected by antiTricks. Option
Use tracer to correct IAT
is used to remove
all known redirection types.
° Option Fix Import elimination is used
on applications that relocate import table in memory outside PE32 file.
This option has been tested with AlexProtector 1.0 and RLPack TE 1.18. Please
note that even dow this option is in testing it should give good results
on all known redirection types (see TitanEngine).
° Option Paste PE.Header from disk is used
correct paste original PE header to the unpacked file.
Generic unpacker can unpack ONLY packers that do not use
IAT redirection, that don’t steal APIs and which fill out IAT table
in correct order. All ordinals that can be converted to API names are converted,
others are inserted into IAT as ordinals! Designed for NT systems,
Windows 2000 or later but it should work on Windows Millenium if you have psapi.dll
file!
Please note that this unpacker does NOT work with AV/FW
software (this means Kaspersky) which hooks LoadLibrary and GetProcAddress
in ring3. If you do not want to change your AV/FW solution run this unpacker
in VM. Then it should work fine.
:: What is new:
- Updated engine parts with unrealeased SDK 1.5 libraries
- Tested with even more packers
- Minor unpacker changes
::
Can I report a bug or contact the autors?
Here is the contact information which you can use
to contact us:
WebSite: http://www.reversinglabs.com
Email:
support(at)reversinglabs(dot)(com)
:: RL!dePacker
is tested with 101+ packers:
|
|
aUS
[Advanced UPX Scrambler] 0.4 - 0.5 |