View Single Post
  #11  
Old 12-14-2005, 12:20
winndy winndy is offline
VIP
 
Join Date: Sep 2005
Posts: 236
Rept. Given: 104
Rept. Rcvd 26 Times in 12 Posts
Thanks Given: 27
Thanks Rcvd at 16 Times in 13 Posts
winndy Reputation: 26
Quote:
Originally Posted by deroko
This is just asprotect virtual .exe extracted by aspr itself into memory, same as secure.dll in armadillo. All protection is in it, so dumping it and analyzing it is a good way to understand how asprotect works.

That's at least my approach on every asprotected target.
But the imagebase is 003XXXXX,< 00400000,
OllyDump and LordPE could not dump it.
That's a problem troubled me.

The second is that could you explain more details about virtual .exe you mentioned.
Quote:
That's at least my approach on every asprotected target.
Need some tuts.


------------
Regards
Reply With Quote