Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Enigma Alternativ Unpacker 1.1
- Titan.dll loading check was successfully!
- Na,das hast du aber fein gemacht ;)
- Real target name is: UnPackMe.TEP.3.80.exe
- MODULEBASE: 00400000 | ASCII "MZP"
- ENTRY: 0040A5C7 | UnPackMe.<ModuleEntryPoint>
- SectionEnd: 903000
- TLS: 007ED000
- TLS_CB: 007ED00C
- TLS_CB_IN: 007ED020
- Enigmasection is: 47F000
- ENIGMA VERSION | 3.70 - Static Scan!
- ----------------------------------
- DLL_Loader.dll
- ----------------------------------------------------------------------
- RVA: C850C | VA: 54750C | Func: EP_CheckUpStartupPasswordHashString
- RVA: C855C | VA: 54755C | Func: EP_CheckupCopies
- RVA: C856C | VA: 54756C | Func: EP_CheckupCopiesCurrent
- RVA: C8564 | VA: 547564 | Func: EP_CheckupCopiesTotal
- RVA: C85C4 | VA: 5475C4 | Func: EP_CheckupFindProcess
- RVA: C85C4 | VA: 5475C4 | Func: EP_CheckupFindProcessA
- RVA: C85CC | VA: 5475CC | Func: EP_CheckupFindProcessW
- RVA: C857C | VA: 54757C | Func: EP_CheckupIsEnigmaOk
- RVA: C8574 | VA: 547574 | Func: EP_CheckupIsProtected
- RVA: C8584 | VA: 547584 | Func: EP_CheckupVirtualizationTools
- RVA: C85A4 | VA: 5475A4 | Func: EP_CryptDecryptBuffer
- RVA: C85AC | VA: 5475AC | Func: EP_CryptDecryptBufferEx
- RVA: C8594 | VA: 547594 | Func: EP_CryptEncryptBuffer
- RVA: C859C | VA: 54759C | Func: EP_CryptEncryptBufferEx
- RVA: C8534 | VA: 547534 | Func: EP_CryptHashBuffer
- RVA: C853C | VA: 54753C | Func: EP_CryptHashFileA
- RVA: C8544 | VA: 547544 | Func: EP_CryptHashFileW
- RVA: C854C | VA: 54754C | Func: EP_CryptHashStringA
- RVA: C8554 | VA: 547554 | Func: EP_CryptHashStringW
- RVA: C858C | VA: 54758C | Func: EP_EnigmaVersion
- RVA: C851C | VA: 54751C | Func: EP_MiscCountryCode
- RVA: C8514 | VA: 547514 | Func: EP_MiscGetWatermark
- RVA: C8524 | VA: 547524 | Func: EP_ProtectedStringByID
- RVA: C852C | VA: 54752C | Func: EP_ProtectedStringByKey
- RVA: C83BC | VA: 5473BC | Func: EP_RegCheckAndSaveKey
- RVA: C83C4 | VA: 5473C4 | Func: EP_RegCheckAndSaveKeyA
- RVA: C83CC | VA: 5473CC | Func: EP_RegCheckAndSaveKeyW
- RVA: C836C | VA: 54736C | Func: EP_RegCheckKey
- RVA: C8374 | VA: 547374 | Func: EP_RegCheckKeyA
- RVA: C84F4 | VA: 5474F4 | Func: EP_RegCheckKeyEx
- RVA: C837C | VA: 54737C | Func: EP_RegCheckKeyW
- RVA: C85FC | VA: 5475FC | Func: EP_RegDecryptRegistrationInformation
- RVA: C83D4 | VA: 5473D4 | Func: EP_RegDeleteKey
- RVA: C85F4 | VA: 5475F4 | Func: EP_RegEncryptRegistrationInformation
- RVA: C8354 | VA: 547354 | Func: EP_RegHardwareID
- RVA: C835C | VA: 54735C | Func: EP_RegHardwareIDA
- RVA: C8364 | VA: 547364 | Func: EP_RegHardwareIDW
- RVA: C83EC | VA: 5473EC | Func: EP_RegKeyCreationDate
- RVA: C83F4 | VA: 5473F4 | Func: EP_RegKeyCreationDateEx
- RVA: C8414 | VA: 547414 | Func: EP_RegKeyDays
- RVA: C8424 | VA: 547424 | Func: EP_RegKeyDaysLeft
- RVA: C841C | VA: 54741C | Func: EP_RegKeyDaysTotal
- RVA: C83FC | VA: 5473FC | Func: EP_RegKeyExecutions
- RVA: C840C | VA: 54740C | Func: EP_RegKeyExecutionsLeft
- RVA: C8404 | VA: 547404 | Func: EP_RegKeyExecutionsTotal
- RVA: C83DC | VA: 5473DC | Func: EP_RegKeyExpirationDate
- RVA: C83E4 | VA: 5473E4 | Func: EP_RegKeyExpirationDateEx
- RVA: C8444 | VA: 547444 | Func: EP_RegKeyGlobalTime
- RVA: C8454 | VA: 547454 | Func: EP_RegKeyGlobalTimeLeft
- RVA: C844C | VA: 54744C | Func: EP_RegKeyGlobalTimeTotal
- RVA: C85D4 | VA: 5475D4 | Func: EP_RegKeyInformation
- RVA: C85D4 | VA: 5475D4 | Func: EP_RegKeyInformationA
- RVA: C85DC | VA: 5475DC | Func: EP_RegKeyInformationW
- RVA: C845C | VA: 54745C | Func: EP_RegKeyRegisterAfterDate
- RVA: C8464 | VA: 547464 | Func: EP_RegKeyRegisterAfterDateEx
- RVA: C846C | VA: 54746C | Func: EP_RegKeyRegisterBeforeDate
- RVA: C8474 | VA: 547474 | Func: EP_RegKeyRegisterBeforeDateEx
- RVA: C842C | VA: 54742C | Func: EP_RegKeyRuntime
- RVA: C843C | VA: 54743C | Func: EP_RegKeyRuntimeLeft
- RVA: C8434 | VA: 547434 | Func: EP_RegKeyRuntimeTotal
- RVA: C85E4 | VA: 5475E4 | Func: EP_RegKeyStatus
- RVA: C83B4 | VA: 5473B4 | Func: EP_RegLoadAndCheckKey
- RVA: C839C | VA: 54739C | Func: EP_RegLoadKey
- RVA: C83A4 | VA: 5473A4 | Func: EP_RegLoadKeyA
- RVA: C8504 | VA: 547504 | Func: EP_RegLoadKeyEx
- RVA: C83AC | VA: 5473AC | Func: EP_RegLoadKeyW
- RVA: C8384 | VA: 547384 | Func: EP_RegSaveKey
- RVA: C838C | VA: 54738C | Func: EP_RegSaveKeyA
- RVA: C84FC | VA: 5474FC | Func: EP_RegSaveKeyEx
- RVA: C8394 | VA: 547394 | Func: EP_RegSaveKeyW
- RVA: C85EC | VA: 5475EC | Func: EP_RegShowDialog
- RVA: C85BC | VA: 5475BC | Func: EP_SplashScreenHide
- RVA: C85B4 | VA: 5475B4 | Func: EP_SplashScreenShow
- RVA: C84EC | VA: 5474EC | Func: EP_TrialClockReversedDays
- RVA: C84BC | VA: 5474BC | Func: EP_TrialDateTillDate
- RVA: C84CC | VA: 5474CC | Func: EP_TrialDateTillDateEndEx
- RVA: C84C4 | VA: 5474C4 | Func: EP_TrialDateTillDateStartEx
- RVA: C8494 | VA: 547494 | Func: EP_TrialDays
- RVA: C84A4 | VA: 5474A4 | Func: EP_TrialDaysLeft
- RVA: C849C | VA: 54749C | Func: EP_TrialDaysTotal
- RVA: C84D4 | VA: 5474D4 | Func: EP_TrialExecutionTime
- RVA: C84E4 | VA: 5474E4 | Func: EP_TrialExecutionTimeLeft
- RVA: C84DC | VA: 5474DC | Func: EP_TrialExecutionTimeTotal
- RVA: C847C | VA: 54747C | Func: EP_TrialExecutions
- RVA: C848C | VA: 54748C | Func: EP_TrialExecutionsLeft
- RVA: C8484 | VA: 547484 | Func: EP_TrialExecutionsTotal
- RVA: C84AC | VA: 5474AC | Func: EP_TrialExpirationDate
- RVA: C84B4 | VA: 5474B4 | Func: EP_TrialExpirationDateEx
- RVA: EA160 | VA: 569160 | Func: Start
- ----------------------------------------------------------------------
- ----------------------------------------------------------------------
- RVA: C850C | VA: 54750C | VM PUSH VALUE: 5A3BFA84 | Func: EP_CheckUpStartupPasswordHashString
- RVA: C855C | VA: 54755C | VM PUSH VALUE: 5A3B8FD1 | Func: EP_CheckupCopies
- RVA: C856C | VA: 54756C | VM PUSH VALUE: 5A3B8FD0 | Func: EP_CheckupCopiesCurrent
- RVA: C8564 | VA: 547564 | VM PUSH VALUE: 5A3B8A0C | Func: EP_CheckupCopiesTotal
- RVA: C85C4 | VA: 5475C4 | VM PUSH VALUE: 5A3BBE89 | Func: EP_CheckupFindProcess
- RVA: C85C4 | VA: 5475C4 | VM PUSH VALUE: 5A3BBE89 | Func: EP_CheckupFindProcessA
- RVA: C85CC | VA: 5475CC | VM PUSH VALUE: 5A3BF2ED | Func: EP_CheckupFindProcessW
- RVA: C857C | VA: 54757C | VM PUSH VALUE: 5A3B8B99 | Func: EP_CheckupIsEnigmaOk
- RVA: C8574 | VA: 547574 | VM PUSH VALUE: 5A3BE248 | Func: EP_CheckupIsProtected
- RVA: C8584 | VA: 547584 | VM PUSH VALUE: 5A3B82FC | Func: EP_CheckupVirtualizationTools
- RVA: C85A4 | VA: 5475A4 | VM PUSH VALUE: 5A3BCEB8 | Func: EP_CryptDecryptBuffer
- RVA: C85AC | VA: 5475AC | VM PUSH VALUE: 5A3BEEB5 | Func: EP_CryptDecryptBufferEx
- RVA: C8594 | VA: 547594 | VM PUSH VALUE: 5A3BC00C | Func: EP_CryptEncryptBuffer
- RVA: C859C | VA: 54759C | VM PUSH VALUE: 5A3BDC03 | Func: EP_CryptEncryptBufferEx
- RVA: C8534 | VA: 547534 | VM PUSH VALUE: 5A3BDE97 | Func: EP_CryptHashBuffer
- RVA: C853C | VA: 54753C | VM PUSH VALUE: 5A3B846F | Func: EP_CryptHashFileA
- RVA: C8544 | VA: 547544 | VM PUSH VALUE: 5A3B8FE6 | Func: EP_CryptHashFileW
- RVA: C854C | VA: 54754C | VM PUSH VALUE: 5A3BB740 | Func: EP_CryptHashStringA
- RVA: C8554 | VA: 547554 | VM PUSH VALUE: 5A3BE30E | Func: EP_CryptHashStringW
- RVA: C858C | VA: 54758C | VM PUSH VALUE: 5A3BDE3B | Func: EP_EnigmaVersion
- RVA: C851C | VA: 54751C | VM PUSH VALUE: 5A3BF070 | Func: EP_MiscCountryCode
- RVA: C8514 | VA: 547514 | VM PUSH VALUE: 5A3B8162 | Func: EP_MiscGetWatermark
- RVA: C8524 | VA: 547524 | VM PUSH VALUE: 5A3BEF16 | Func: EP_ProtectedStringByID
- RVA: C852C | VA: 54752C | VM PUSH VALUE: 5A3BDF26 | Func: EP_ProtectedStringByKey
- RVA: C83BC | VA: 5473BC | VM PUSH VALUE: 5A3BBE73 | Func: EP_RegCheckAndSaveKey
- RVA: C83C4 | VA: 5473C4 | VM PUSH VALUE: 5A3BDED4 | Func: EP_RegCheckAndSaveKeyA
- RVA: C83CC | VA: 5473CC | VM PUSH VALUE: 5A3BC818 | Func: EP_RegCheckAndSaveKeyW
- RVA: C836C | VA: 54736C | VM PUSH VALUE: 5A3BB86A | Func: EP_RegCheckKey
- RVA: C8374 | VA: 547374 | VM PUSH VALUE: 5A3BF528 | Func: EP_RegCheckKeyA
- RVA: C84F4 | VA: 5474F4 | VM PUSH VALUE: 5A3BBFC2 | Func: EP_RegCheckKeyEx
- RVA: C837C | VA: 54737C | VM PUSH VALUE: 5A3BDE05 | Func: EP_RegCheckKeyW
- ----------------------------------------------------------------------
- RVA: C85FC | VA: 5475FC | VM PUSH VALUE: DeCrypt_ | Func: EP_RegDecryptRegistrationInformation
- ----------------------------------------------------------------------
- RVA: C83D4 | VA: 5473D4 | VM PUSH VALUE: 5A3B96C2 | Func: EP_RegDeleteKey
- ----------------------------------------------------------------------
- RVA: C85F4 | VA: 5475F4 | VM PUSH VALUE: DeCrypt_ | Func: EP_RegEncryptRegistrationInformation
- ----------------------------------------------------------------------
- RVA: C8354 | VA: 547354 | VM PUSH VALUE: 5A3BEEB4 | Func: EP_RegHardwareID
- RVA: C835C | VA: 54735C | VM PUSH VALUE: 5A3BBE8A | Func: EP_RegHardwareIDA
- RVA: C8364 | VA: 547364 | VM PUSH VALUE: 5A3BD22F | Func: EP_RegHardwareIDW
- RVA: C83EC | VA: 5473EC | VM PUSH VALUE: 5A3BDC63 | Func: EP_RegKeyCreationDate
- RVA: C83F4 | VA: 5473F4 | VM PUSH VALUE: 5A3BC503 | Func: EP_RegKeyCreationDateEx
- RVA: C8414 | VA: 547414 | VM PUSH VALUE: 5A3BDFF7 | Func: EP_RegKeyDays
- RVA: C8424 | VA: 547424 | VM PUSH VALUE: 5A3BE08B | Func: EP_RegKeyDaysLeft
- RVA: C841C | VA: 54741C | VM PUSH VALUE: 5A3BBFAA | Func: EP_RegKeyDaysTotal
- RVA: C83FC | VA: 5473FC | VM PUSH VALUE: 5A3BE927 | Func: EP_RegKeyExecutions
- RVA: C840C | VA: 54740C | VM PUSH VALUE: 5A3B9D8E | Func: EP_RegKeyExecutionsLeft
- RVA: C8404 | VA: 547404 | VM PUSH VALUE: 5A3B8C7F | Func: EP_RegKeyExecutionsTotal
- RVA: C83DC | VA: 5473DC | VM PUSH VALUE: 5A3B846E | Func: EP_RegKeyExpirationDate
- RVA: C83E4 | VA: 5473E4 | VM PUSH VALUE: 5A3B94CC | Func: EP_RegKeyExpirationDateEx
- RVA: C8444 | VA: 547444 | VM PUSH VALUE: 5A3BE099 | Func: EP_RegKeyGlobalTime
- RVA: C8454 | VA: 547454 | VM PUSH VALUE: 5A3B94CD | Func: EP_RegKeyGlobalTimeLeft
- RVA: C844C | VA: 54744C | VM PUSH VALUE: 5A3B8A67 | Func: EP_RegKeyGlobalTimeTotal
- RVA: C85D4 | VA: 5475D4 | VM PUSH VALUE: 5A3BEACC | Func: EP_RegKeyInformation
- RVA: C85D4 | VA: 5475D4 | VM PUSH VALUE: 5A3BEACC | Func: EP_RegKeyInformationA
- RVA: C85DC | VA: 5475DC | VM PUSH VALUE: 5A3BE30F | Func: EP_RegKeyInformationW
- RVA: C845C | VA: 54745C | VM PUSH VALUE: 5A3BE603 | Func: EP_RegKeyRegisterAfterDate
- RVA: C8464 | VA: 547464 | VM PUSH VALUE: 5A3BC069 | Func: EP_RegKeyRegisterAfterDateEx
- RVA: C846C | VA: 54746C | VM PUSH VALUE: 5A3B94CE | Func: EP_RegKeyRegisterBeforeDate
- RVA: C8474 | VA: 547474 | VM PUSH VALUE: 5A3B8A66 | Func: EP_RegKeyRegisterBeforeDateEx
- RVA: C842C | VA: 54742C | VM PUSH VALUE: 5A3BC502 | Func: EP_RegKeyRuntime
- RVA: C843C | VA: 54743C | VM PUSH VALUE: 5A3B894F | Func: EP_RegKeyRuntimeLeft
- RVA: C8434 | VA: 547434 | VM PUSH VALUE: 5A3BF04D | Func: EP_RegKeyRuntimeTotal
- RVA: C85E4 | VA: 5475E4 | VM PUSH VALUE: 5A3B8C1D | Func: EP_RegKeyStatus
- RVA: C83B4 | VA: 5473B4 | VM PUSH VALUE: 5A3B8A0D | Func: EP_RegLoadAndCheckKey
- RVA: C839C | VA: 54739C | VM PUSH VALUE: 5A3BB381 | Func: EP_RegLoadKey
- RVA: C83A4 | VA: 5473A4 | VM PUSH VALUE: 5A3BF299 | Func: EP_RegLoadKeyA
- RVA: C8504 | VA: 547504 | VM PUSH VALUE: 5A3BEF15 | Func: EP_RegLoadKeyEx
- RVA: C83AC | VA: 5473AC | VM PUSH VALUE: 5A3BEF14 | Func: EP_RegLoadKeyW
- RVA: C8384 | VA: 547384 | VM PUSH VALUE: 5A3BF48F | Func: EP_RegSaveKey
- RVA: C838C | VA: 54738C | VM PUSH VALUE: 5A3BBAE5 | Func: EP_RegSaveKeyA
- RVA: C84FC | VA: 5474FC | VM PUSH VALUE: 5A3BC322 | Func: EP_RegSaveKeyEx
- RVA: C8394 | VA: 547394 | VM PUSH VALUE: 5A3B82FD | Func: EP_RegSaveKeyW
- RVA: C85EC | VA: 5475EC | VM PUSH VALUE: 5A3BB380 | Func: EP_RegShowDialog
- RVA: C85BC | VA: 5475BC | VM PUSH VALUE: 5A3BEACE | Func: EP_SplashScreenHide
- RVA: C85B4 | VA: 5475B4 | VM PUSH VALUE: 5A3BF2EF | Func: EP_SplashScreenShow
- RVA: C84EC | VA: 5474EC | VM PUSH VALUE: 5A3BB864 | Func: EP_TrialClockReversedDays
- RVA: C84BC | VA: 5474BC | VM PUSH VALUE: 5A3BDC5E | Func: EP_TrialDateTillDate
- RVA: C84CC | VA: 5474CC | VM PUSH VALUE: 5A3BD4F4 | Func: EP_TrialDateTillDateEndEx
- RVA: C84C4 | VA: 5474C4 | VM PUSH VALUE: 5A3BDB6C | Func: EP_TrialDateTillDateStartEx
- RVA: C8494 | VA: 547494 | VM PUSH VALUE: 5A3BCE7C | Func: EP_TrialDays
- RVA: C84A4 | VA: 5474A4 | VM PUSH VALUE: 5A3BF7BD | Func: EP_TrialDaysLeft
- RVA: C849C | VA: 54749C | VM PUSH VALUE: 5A3BE30D | Func: EP_TrialDaysTotal
- RVA: C84D4 | VA: 5474D4 | VM PUSH VALUE: 5A3BD002 | Func: EP_TrialExecutionTime
- RVA: C84E4 | VA: 5474E4 | VM PUSH VALUE: 5A3BDE54 | Func: EP_TrialExecutionTimeLeft
- RVA: C84DC | VA: 5474DC | VM PUSH VALUE: 5A3B9CA9 | Func: EP_TrialExecutionTimeTotal
- RVA: C847C | VA: 54747C | VM PUSH VALUE: 5A3BC716 | Func: EP_TrialExecutions
- RVA: C848C | VA: 54748C | VM PUSH VALUE: 5A3BDF25 | Func: EP_TrialExecutionsLeft
- RVA: C8484 | VA: 547484 | VM PUSH VALUE: 5A3BF7BC | Func: EP_TrialExecutionsTotal
- RVA: C84AC | VA: 5474AC | VM PUSH VALUE: 5A3BF993 | Func: EP_TrialExpirationDate
- RVA: C84B4 | VA: 5474B4 | VM PUSH VALUE: 5A3B87C0 | Func: EP_TrialExpirationDateEx
- RVA: EA160 | VA: 569160 | VM PUSH VALUE: 5A3B82E3 | Func: Start
- ----------------------------------------------------------------------
- All Exports Functions - Addresses - VM Values logged!
- Found and Patched Anti Plug at: 4C71D4
- 1 New CRC found at: 4C0879
- CRC_1 was patched
- VM OEP SIGN FOUND!
- ENIGMA VERSION | 3.80 - Intern EP Scan = Real Version!
- Possible used RegSheme found!
- Address: 540597 - SETNE AL
- Address: 5405D6 - SETNE AL
- MJ found and patched at: 53C264
- HWID check is disbaled by user!
- PRE_CHECKER: 00547790
- OEP is inside of the target!
- APIs located in main target!
- 004616F4
- 000005C4
- ---------- IAT DATA ----------
- IATSTART VA: 4616F4
- IATEND VA: 461CB8
- IAT SIZE : 5C4
- 004616F4
- 00461CB8
- 000005C4
- ------------------------------
- Calling LLA & GPA was disabled!
- Found main API Table!
- Reg Jump Table Functions
- ----------------------------------
- Jump to Push - API == RVA: 1417FC | VA: 5417FC | Func: EP_RegHardwareID
- Jump to Push - API == RVA: 1417F4 | VA: 5417F4 | Func: EP_RegHardwareIDA
- Jump to Push - API == RVA: 1418BC | VA: 5418BC | Func: EP_RegHardwareIDW
- Jump to Push - API == RVA: 143584 | VA: 543584 | Func: EP_RegCheckKey
- Jump to Push - API == RVA: 143570 | VA: 543570 | Func: EP_RegCheckKeyA
- Jump to Push - API == RVA: 143624 | VA: 543624 | Func: EP_RegCheckKeyW
- Jump to Push - API == RVA: 144364 | VA: 544364 | Func: EP_RegSaveKey
- Jump to Push - API == RVA: 144350 | VA: 544350 | Func: EP_RegSaveKeyA
- Jump to Push - API == RVA: 144488 | VA: 544488 | Func: EP_RegSaveKeyW
- Jump to Push - API == RVA: 144F00 | VA: 544F00 | Func: EP_RegLoadKey
- Jump to Push - API == RVA: 144EEC | VA: 544EEC | Func: EP_RegLoadKeyA
- Jump to Push - API == RVA: 145164 | VA: 545164 | Func: EP_RegLoadKeyW
- Jump to Push - API == RVA: 145714 | VA: 545714 | Func: EP_RegLoadAndCheckKey
- Jump to Push - API == RVA: 1460CC | VA: 5460CC | Func: EP_RegCheckAndSaveKey
- Jump to Push - API == RVA: 1460B8 | VA: 5460B8 | Func: EP_RegCheckAndSaveKeyA
- Jump to Push - API == RVA: 1460F8 | VA: 5460F8 | Func: EP_RegCheckAndSaveKeyW
- Jump to Push - API == RVA: 1456C4 | VA: 5456C4 | Func: EP_RegDeleteKey
- Jump to Push - API == RVA: 145C10 | VA: 545C10 | Func: EP_RegKeyExpirationDate
- Jump to Push - API == RVA: 145C80 | VA: 545C80 | Func: EP_RegKeyExpirationDateEx
- Jump to Push - API == RVA: 145E08 | VA: 545E08 | Func: EP_RegKeyCreationDate
- Jump to Push - API == RVA: 146080 | VA: 546080 | Func: EP_RegKeyCreationDateEx
- Jump to Push - API == RVA: 145E70 | VA: 545E70 | Func: EP_RegKeyExecutions
- Jump to Push - API == RVA: 145EAC | VA: 545EAC | Func: EP_RegKeyExecutionsTotal
- Jump to Push - API == RVA: 145ED0 | VA: 545ED0 | Func: EP_RegKeyExecutionsLeft
- Jump to Push - API == RVA: 145EF4 | VA: 545EF4 | Func: EP_RegKeyDays
- Jump to Push - API == RVA: 145F30 | VA: 545F30 | Func: EP_RegKeyDaysTotal
- Jump to Push - API == RVA: 145F54 | VA: 545F54 | Func: EP_RegKeyDaysLeft
- Jump to Push - API == RVA: 145F78 | VA: 545F78 | Func: EP_RegKeyRuntime
- Jump to Push - API == RVA: 145FB4 | VA: 545FB4 | Func: EP_RegKeyRuntimeTotal
- Jump to Push - API == RVA: 145FD8 | VA: 545FD8 | Func: EP_RegKeyRuntimeLeft
- Jump to Push - API == RVA: 145FFC | VA: 545FFC | Func: EP_RegKeyGlobalTime
- Jump to Push - API == RVA: 146038 | VA: 546038 | Func: EP_RegKeyGlobalTimeTotal
- Jump to Push - API == RVA: 14605C | VA: 54605C | Func: EP_RegKeyGlobalTimeLeft
- Jump to Push - API == RVA: 145CB8 | VA: 545CB8 | Func: EP_RegKeyRegisterAfterDate
- Jump to Push - API == RVA: 145D28 | VA: 545D28 | Func: EP_RegKeyRegisterAfterDateEx
- Jump to Push - API == RVA: 145D60 | VA: 545D60 | Func: EP_RegKeyRegisterBeforeDate
- Jump to Push - API == RVA: 145DD0 | VA: 545DD0 | Func: EP_RegKeyRegisterBeforeDateEx
- Jump to Push - API == RVA: 145784 | VA: 545784 | Func: EP_TrialExecutions
- Jump to Push - API == RVA: 1457EC | VA: 5457EC | Func: EP_TrialExecutionsTotal
- Jump to Push - API == RVA: 14580C | VA: 54580C | Func: EP_TrialExecutionsLeft
- Jump to Push - API == RVA: 14582C | VA: 54582C | Func: EP_TrialDays
- Jump to Push - API == RVA: 145894 | VA: 545894 | Func: EP_TrialDaysTotal
- Jump to Push - API == RVA: 1458B4 | VA: 5458B4 | Func: EP_TrialDaysLeft
- Jump to Push - API == RVA: 145984 | VA: 545984 | Func: EP_TrialExpirationDate
- Jump to Push - API == RVA: 145A34 | VA: 545A34 | Func: EP_TrialExpirationDateEx
- Jump to Push - API == RVA: 145A6C | VA: 545A6C | Func: EP_TrialDateTillDate
- Jump to Push - API == RVA: 145B80 | VA: 545B80 | Func: EP_TrialDateTillDateStartEx
- Jump to Push - API == RVA: 145BC8 | VA: 545BC8 | Func: EP_TrialDateTillDateEndEx
- Jump to Push - API == RVA: 1458D4 | VA: 5458D4 | Func: EP_TrialExecutionTime
- Jump to Push - API == RVA: 14593C | VA: 54593C | Func: EP_TrialExecutionTimeTotal
- Jump to Push - API == RVA: 145960 | VA: 545960 | Func: EP_TrialExecutionTimeLeft
- Jump to Push - API == RVA: 1472AC | VA: 5472AC | Func: EP_TrialClockReversedDays
- Jump to Push - API == RVA: 1423F0 | VA: 5423F0 | Func: EP_RegCheckKeyEx
- Jump to Push - API == RVA: 144584 | VA: 544584 | Func: EP_RegSaveKeyEx
- Jump to Push - API == RVA: 144D04 | VA: 544D04 | Func: EP_RegLoadKeyEx
- Jump to Push - API == RVA: 141364 | VA: 541364 | Func: EP_CheckUpStartupPasswordHashString
- Jump to Push - API == RVA: 14113C | VA: 54113C | Func: EP_MiscGetWatermark
- Jump to Push - API == RVA: 146514 | VA: 546514 | Func: EP_MiscCountryCode
- Jump to Push - API == RVA: 140F18 | VA: 540F18 | Func: EP_ProtectedStringByID
- Jump to Push - API == RVA: 140FE0 | VA: 540FE0 | Func: EP_ProtectedStringByKey
- Jump to Push - API == RVA: 146124 | VA: 546124 | Func: EP_CryptHashBuffer
- Jump to Push - API == RVA: 14624C | VA: 54624C | Func: EP_CryptHashFileA
- Jump to Push - API == RVA: 1462E0 | VA: 5462E0 | Func: EP_CryptHashFileW
- Jump to Push - API == RVA: 146378 | VA: 546378 | Func: EP_CryptHashStringA
- Jump to Push - API == RVA: 14639C | VA: 54639C | Func: EP_CryptHashStringW
- Jump to Push - API == RVA: 140DE8 | VA: 540DE8 | Func: EP_CryptEncryptBuffer
- Jump to Push - API == RVA: 140E38 | VA: 540E38 | Func: EP_CryptEncryptBufferEx
- Jump to Push - API == RVA: 140E7C | VA: 540E7C | Func: EP_CryptDecryptBuffer
- Jump to Push - API == RVA: 140ECC | VA: 540ECC | Func: EP_CryptDecryptBufferEx
- Jump to Push - API == RVA: 146400 | VA: 546400 | Func: EP_CheckupCopies
- Jump to Push - API == RVA: 146440 | VA: 546440 | Func: EP_CheckupCopiesTotal
- Jump to Push - API == RVA: 146464 | VA: 546464 | Func: EP_CheckupCopiesCurrent
- Jump to Push - API == RVA: 146488 | VA: 546488 | Func: EP_CheckupIsProtected
- Jump to Push - API == RVA: 146490 | VA: 546490 | Func: EP_CheckupIsEnigmaOk
- Jump to Push - API == RVA: 140F10 | VA: 540F10 | Func: EP_EnigmaVersion
- Jump to Push - API == RVA: 146590 | VA: 546590 | Func: EP_SplashScreenShow
- Jump to Push - API == RVA: 146598 | VA: 546598 | Func: EP_SplashScreenHide
- Jump to Push - API == RVA: 14680C | VA: 54680C | Func: EP_CheckupFindProcess
- Jump to Push - API == RVA: 14680C | VA: 54680C | Func: EP_CheckupFindProcessA
- Jump to Push - API == RVA: 146E5C | VA: 546E5C | Func: EP_CheckupFindProcessW
- Jump to Push - API == RVA: 142328 | VA: 542328 | Func: EP_RegKeyInformation
- Jump to Push - API == RVA: 142328 | VA: 542328 | Func: EP_RegKeyInformationA
- Jump to Push - API == RVA: 1422B0 | VA: 5422B0 | Func: EP_RegKeyInformationW
- Jump to Push - API == RVA: 140DE0 | VA: 540DE0 | Func: EP_Marker
- Jump to Push - API == RVA: 140DD8 | VA: 540DD8 | Func: EP_RegKeyStatus
- Jump to Push - API == RVA: 14728C | VA: 54728C | Func: EP_CheckupVirtualizationTools
- Jump to Push - API == RVA: 1472A0 | VA: 5472A0 | Func: EP_RegShowDialog
- Jump to Push - API == RVA: 1475F4 | VA: 5475F4 | Func: EP_RegEncryptRegistrationInformation
- Jump to Push - API == RVA: 1475FC | VA: 5475FC | Func: EP_RegDecryptRegistrationInformation
- ----------------------------------
- OUTER_VM: 005668D8
- OUTER_START: 005639A0
- VM_POINTER_2_IN : 18 // VM Main Table
- VM_POINTER_1 : 585568
- VM_POINTER_1_IN : 2D01EFC <-- Dump VM
- VM_POINTER_2 : 2D01FD4
- VM_POINTER_2_IN : 18 <-- Dump VM
- VM_POINTER_3 : 2D01FD8
- VM_POINTER_3_IN : 48 <-- Dump VM
- VM_POINTER_4 : 2D01FDC
- VM_POINTER_4_IN : 0 <-- Dump VM
- ESP_POINTER : 58A2E0
- ESP_POINTER_IN : 3390590 <-- Change VM Pointer!
- VM - VA_2D00000_RVA_2900000_size_34000.mem
- VM was dumped!
- All VM was dumped!Add them with the right RVA and rebuid PE before fixing!
- Dont forget to change the ESP Pointer manually in your dumped file!
- Enigma 3.70 - 3.130 detected
- ---------- VM DATA ----------
- JUMP TABLE AT: 007F2BF4
- VM TABLE AT: 00000018
- LASTSEC: 007ED000
- 007F2BF4
- 00000018
- 007ED000
- -----------------------------
- TLS callback was killed!
- CHECKUP was found and patched!
- Stolen Code M1 nothing to fix!
- Script Finished - See Olly LOG for more infos!
- For VM fixing you can use my other script til version 3.70!
- Thank you and bye bye
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement