Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 01-01-2005, 02:18
the_beginner the_beginner is offline
Friend
 
Join Date: Feb 2004
Location: Germany
Posts: 85
Rept. Given: 114
Rept. Rcvd 13 Times in 7 Posts
Thanks Given: 97
Thanks Rcvd at 16 Times in 9 Posts
the_beginner Reputation: 13
shit Asprotect 2.0 help please

hi

try many Days create a loader or unpack this File please help me to find the rigt way

ok i load my proggy on olly press F9 ,then stopt ,i press 37 times shif+F9 then i must patch a int41 ( CD 41 ) fill with nop press shit F9 again ,F9 another CD41 must patch the proggi start's with a nag i click ok then come a CD68 fill with NOP and it Runs but i can't find the OEP
another test peid say OEP ist 00420b30 ok I look and I have trace on this point but the fucking ITA

can someone help me please

BTW its create a nice reg key ,you cant read or change
Attached Files
File Type: zip DVR-StudioPro.zip (1.13 MB, 32 views)
Reply With Quote
  #2  
Old 01-01-2005, 02:33
britedream britedream is offline
Friend
 
Join Date: Jun 2002
Posts: 436
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 7 Times in 7 Posts
britedream Reputation: 0
Hi the_beginner

to get rid of the nag, see why the target comes to 48bf7c check the two calls above and go inside the 48bf7c. I think your oep is at 4110e4 but it is emulated, you don't have to nop anything. To make your life easier patch GetTickCount. By the way you , if you are inline patching then you can get by without knowing the oep.

Regards.

Last edited by britedream; 01-01-2005 at 20:33.
Reply With Quote
  #3  
Old 01-01-2005, 20:37
the_beginner the_beginner is offline
Friend
 
Join Date: Feb 2004
Location: Germany
Posts: 85
Rept. Given: 114
Rept. Rcvd 13 Times in 7 Posts
Thanks Given: 97
Thanks Rcvd at 16 Times in 9 Posts
the_beginner Reputation: 13
hi

thanks you write i dont nop anything but if i dont nop it terminatet :-( ,bpx on getTickCount wont work ,because the Autor of the Software use a own 30 day counter Trick ist very nice (can't delete )

cu
Reply With Quote
  #4  
Old 01-01-2005, 22:15
britedream britedream is offline
Friend
 
Join Date: Jun 2002
Posts: 436
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 7 Times in 7 Posts
britedream Reputation: 0
I don't mean bpx ,you aren't hiding olly very well, I checked it using olly on xp1 and it works without closing.GetTickCount is also used for protection, but I doubt it will effect olly.

in respond to your post below , please check your pm.

Last edited by britedream; 01-02-2005 at 01:30.
Reply With Quote
  #5  
Old 01-02-2005, 00:59
the_beginner the_beginner is offline
Friend
 
Join Date: Feb 2004
Location: Germany
Posts: 85
Rept. Given: 114
Rept. Rcvd 13 Times in 7 Posts
Thanks Given: 97
Thanks Rcvd at 16 Times in 9 Posts
the_beginner Reputation: 13
hmmm
i have rename the ollydbg ,have patched the ollydbg,exe hide debugger runs ,i know what you mine but how can I better Hiding???

edit : I have try on 2 pc and 3 system 2xWin2k 1 xp pro sp1 if I not NOP the cd41 and CD68 it's crash

Last edited by the_beginner; 01-02-2005 at 03:15.
Reply With Quote
  #6  
Old 01-03-2005, 00:53
Crk
 
Posts: n/a
OEP: 004727D0

know be prepared for manual IAT repair
Reply With Quote
  #7  
Old 01-03-2005, 03:29
the_beginner the_beginner is offline
Friend
 
Join Date: Feb 2004
Location: Germany
Posts: 85
Rept. Given: 114
Rept. Rcvd 13 Times in 7 Posts
Thanks Given: 97
Thanks Rcvd at 16 Times in 9 Posts
the_beginner Reputation: 13
thanks ,but I dont know how can repair my IAT
Reply With Quote
  #8  
Old 01-03-2005, 14:06
Crk
 
Posts: n/a
Asprotect destroy IAT so you most find it and dump it from memory then you will have to do manual fix and maybe finish it with imprec ..by now i give you my quick working solution.. try ! Nag should be gone as well

Last edited by Crk; 01-03-2005 at 14:10.
Reply With Quote
  #9  
Old 01-03-2005, 16:40
Titanius
 
Posts: n/a
@Crk

I am interested in unpacking this thing to. I have the same problems like the_beginner
with this stuff.

Can you please discribe how you find the OEP and how you fix the IAT ?

Unfortunately, i can't download your attachement.
Reply With Quote
  #10  
Old 01-03-2005, 20:15
Crk
 
Posts: n/a
i find OEP manually with BPX on API getmodulehandlea and about IAT i can't fix it. this is newest Asprotect 2.x. maybe britedream has a solution for us
Reply With Quote
  #11  
Old 01-03-2005, 20:27
the_beginner the_beginner is offline
Friend
 
Join Date: Feb 2004
Location: Germany
Posts: 85
Rept. Given: 114
Rept. Rcvd 13 Times in 7 Posts
Thanks Given: 97
Thanks Rcvd at 16 Times in 9 Posts
the_beginner Reputation: 13
@ Crk tahks for your loader but it's work on my PC :-( ,i have many play with the Date soo my time it's over , can you tell me how you make the loader so ca i fix the exe file because I Know what I must change (I have cracked some version befor packet with yoda then asprotect 1,2x)
cu
Reply With Quote
  #12  
Old 01-04-2005, 00:06
diablo2oo2's Avatar
diablo2oo2 diablo2oo2 is offline
Family
 
Join Date: Mar 2004
Posts: 232
Rept. Given: 7
Rept. Rcvd 111 Times in 26 Posts
Thanks Given: 2
Thanks Rcvd at 20 Times in 7 Posts
diablo2oo2 Reputation: 100-199 diablo2oo2 Reputation: 100-199
if you know what you must change, then make a loader. killing the process crc check is easy (pm me if you want to know how)...
__________________
Thinking In Bytes
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Apatana Studio shit CodeCracker General Discussion 0 03-04-2018 16:16
New Asprotect?? loman General Discussion 7 02-04-2004 20:34


All times are GMT +8. The time now is 05:04.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )