Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 12-14-2002, 03:40
BoostMan
 
Posts: n/a
Unpacking ASProtect with OllyDbg???

Hi,

i just want to know if it is possible to unpack
an ASProtected file with OllyDbg, or is it only
possible by tracing with SoftIce?

If an anyone help an not so advanced reverser
it would be very nice!

Best regards

BoostMan
Reply With Quote
  #2  
Old 12-14-2002, 17:19
_Servil_ _Servil_ is offline
VIP
 
Join Date: Jan 2002
Posts: 171
Rept. Given: 57
Rept. Rcvd 12 Times in 2 Posts
Thanks Given: 78
Thanks Rcvd at 27 Times in 13 Posts
_Servil_ Reputation: 12
you can't OD is a app-level dbgr, have to use SI.
__________________
_Servil_
SemtekSoft Corporation, Inc.
Reply With Quote
  #3  
Old 12-15-2002, 05:16
BoostMan
 
Posts: n/a
Thanx for the info!
BoostMan
Reply With Quote
  #4  
Old 12-15-2002, 23:11
crusader
 
Posts: n/a
Why not?

Unpacking Asprotect can be done with Olly surely? Aspr doesnt have any ring-0 trick as far as i am aware of?
Reply With Quote
  #5  
Old 12-15-2002, 23:59
_Servil_ _Servil_ is offline
VIP
 
Join Date: Jan 2002
Posts: 171
Rept. Given: 57
Rept. Rcvd 12 Times in 2 Posts
Thanks Given: 78
Thanks Rcvd at 27 Times in 13 Posts
_Servil_ Reputation: 12
why not?
i remember once i done this and got lost at int 2e which OD isn't able to trace. As I got info at OD phorum it might be implemented in version 2.
Beside this (IMO) clearing debug registers works nice on OD i think there's no superbpm for OD
__________________
_Servil_
SemtekSoft Corporation, Inc.

Last edited by _Servil_; 12-16-2002 at 04:12.
Reply With Quote
  #6  
Old 12-20-2002, 17:49
xxxxx
 
Posts: n/a
well it actually work.

1. Find OEP
2. Execute till OEP (OLLY - mem breakpoint to access on OEP)
3. PEDump - put all flags(rebuild options part), select REBUILD NEW IMPORT TABLE
4. PEDump - REBUILD PE (Check if you can load it in Olly debugger)
5. IMPREC - Find all api-s
6. IMPREC - Make fix dump
7. Eventually - Fix OEP in PE header if imprec didn't do already
8. Eventually - check on win 98 if all dll functions are exported

I try and success.
Reply With Quote
  #7  
Old 12-20-2002, 17:51
xxxxx
 
Posts: n/a
sorry forgot something

this metod work only with ASPROTECT ver 1.2, 1.2 new strain
and before.
Reply With Quote
  #8  
Old 01-13-2003, 17:43
menw
 
Posts: n/a
You might consider using revirgin.

Find it at h++p://www.woodmann.com/fravia/index.htm
.

I´m not sure if you get it working, but it´s worth a try.
(I still must find the time to look closer at this thing).

menw

P.S.: If it turns out to be usefull, please post your experience.
Reply With Quote
  #9  
Old 01-18-2003, 23:38
ByTESCRK
 
Posts: n/a
OllyDBG unpack ASPR

Maybe our friend RNarvaja could be comments something about of that.

Ricardo, si ves esto quiz� puedas comentarlo.
Reply With Quote
  #10  
Old 01-18-2003, 23:45
_Servil_ _Servil_ is offline
VIP
 
Join Date: Jan 2002
Posts: 171
Rept. Given: 57
Rept. Rcvd 12 Times in 2 Posts
Thanks Given: 78
Thanks Rcvd at 27 Times in 13 Posts
_Servil_ Reputation: 12
nope, its cleared debug registers you can't stop it any way on OEP
__________________
_Servil_
SemtekSoft Corporation, Inc.
Reply With Quote
  #11  
Old 01-19-2003, 01:45
Squidge's Avatar
Squidge Squidge is offline
Drunken Squirrel
 
Join Date: Oct 2002
Posts: 412
Rept. Given: 4
Rept. Rcvd 9 Times in 4 Posts
Thanks Given: 0
Thanks Rcvd at 6 Times in 6 Posts
Squidge Reputation: 9
I find it's easier to dump the process whilst it's running, and then investigate that file to find the OEP.
Reply With Quote
  #12  
Old 01-21-2003, 00:30
ByTESCRK
 
Posts: n/a
Is easy dump with Olly, my problem is building IAT

You can see a tute here

hxxp://karpoff.redfutura.net/manuales/0catch/archivos_0catch/asprotect%201.23%20con%20ollydbg.doc

Sorry is spanish. But you can take the idea.

Last edited by ByTESCRK; 01-21-2003 at 00:44.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ASProtect SKE unpacking TempoMat General Discussion 10 08-24-2016 17:48
need help unpacking ASProtect Fade General Discussion 8 05-25-2011 22:12
Unpacking asprotect britedream General Discussion 7 09-01-2004 01:46


All times are GMT +8. The time now is 15:34.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )