Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 04-13-2005, 07:08
TmC TmC is offline
VIP
 
Join Date: Aug 2004
Posts: 328
Rept. Given: 1
Rept. Rcvd 15 Times in 9 Posts
Thanks Given: 2
Thanks Rcvd at 22 Times in 16 Posts
TmC Reputation: 15
Unhappy Out of Control Asprotect

Hi all, i'm trying to unpack Advanced Office Password Recovery, by Elcomsoft, at the time i'm writing, v3.03 and protected with(PEiD says ASProtect v1.2x (New Strain) *).

I downloaded as much as tutorials i could and looked for all unpackers and searched for all olly scripts but everything doesn't work.

Following some tutorials by Ferrari i read:

Load the program in Olly and you'll be here:

00401000 > 68 01505200 PUSH aopr.00525001<---------- You are initially here
00401005 |. E8 01000000 CALL aopr.0040100B
0040100A \. C3 RETN
0040100B $ C3 RETN

-> OK

Shift+F9 and program will throw an access violation:

Access violation when writing to [00000000] - use Shift+F7/F8/F9 to pass exception to program

-> OK

Ctrl+B and put : 8B 17 89 02 EB

-> STOP: The search reports that item is not found

FROM HERE I DON'T KNOW HOW TO GO ON.

Can someone help me? I'm a bit puzzled...


UPDATE:

Very strange, but with stripper 2.11rc2 i managed to have a running program.
The code is terribly mangled, entry point of the program can be found no more
nor the false one neither the real one. WinDasm crashes. It cannot be dumped again and iat cannot be found, although i managed to have one clean one.
I managed to patch the registration dialogue with breakpoint on GetDialogItem, but now i need to crack the initial check, to make it view registered.
I try to break on RegOpenKey, RegQueryValue but nothing relevant happens. seems that the key where the key should be stored is never opened. I know for sure that registration keys are handled internally and are not ASPR keys.

Someone has suggestions for me?

In attach unpacked and IAT.
Attached Files
File Type: txt tree.txt (29.6 KB, 3 views)
File Type: rar aopr_.part1.rar (781.3 KB, 2 views)
File Type: rar aopr_.part2.rar (547.0 KB, 5 views)

Last edited by TmC; 04-13-2005 at 11:26.
Reply With Quote
  #2  
Old 04-13-2005, 15:03
codeX codeX is offline
{RES} Cracker
 
Join Date: Dec 2004
Location: C:\WINDOWS\SYSTEM32
Posts: 163
Rept. Given: 1
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 3
Thanks Rcvd at 1 Time in 1 Post
codeX Reputation: 0
Hi,
Please provide a link for packed program.

Anyway is the 'stripped' program works fine without any crashes?
Reply With Quote
  #3  
Old 04-13-2005, 17:13
TmC TmC is offline
VIP
 
Join Date: Aug 2004
Posts: 328
Rept. Given: 1
Rept. Rcvd 15 Times in 9 Posts
Thanks Given: 2
Thanks Rcvd at 22 Times in 16 Posts
TmC Reputation: 15
Unhappy

Quote:
Originally Posted by codeX
Hi,
Please provide a link for packed program.

Anyway is the 'stripped' program works fine without any crashes?
9987://www.elcomsoft.com/download/aopr.zip

The stripped works, but is hard to crack because the entire executable is smashed by the unpacker.
Anyway, because it works with 2.11 and not with 2.07f, PEiD and ProtectionID are far from beein right. It should be at least 1.23-2.x Asprotect and not Asprotect 1.2 New Strain.

Puzzled
Reply With Quote
  #4  
Old 04-13-2005, 23:13
Vepergen
 
Posts: n/a
TMC: It's exactly ASPR 1.31
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 10:15.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )