Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 08-30-2004, 22:26
britedream britedream is offline
Friend
 
Join Date: Jun 2002
Posts: 436
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 7 Times in 7 Posts
britedream Reputation: 0
Unpacking asprotect

I have been asked by a gentleman and good friend from this forum to give some tips on iat , but since asprotect has different varieties , it is worth it to show you one that you have not seen yet, so you will have another concept of asprotect[easy one] . I will pick a target that I think it is very useful for many pc user and has the recent asprotect, this target is registry clean expert , the new version 3.51 is released this month.

let us scan the target first, load it and use my script to go to oep, will notice two things a- no stolen b- look at the dump pane , it suggests that our imports might be here , let us see how close is that to reality.

steps:
1- restart the target and shift+ f9 till you see in the dump pane definite pattern such as:
00476000 82 D3 08 00 64 D2 08 00 ‚Ó.dÒ.
00476008 78 D2 08 00 88 D2 08 00 xÒ.ˆÒ.
00476010 9A D2 08 00 AA D2 08 00 šÒ.ªÒ.
00476018 BA D2 08 00 CC D2 08 00 ºÒ.ÌÒ.
00476020 DE D2 08 00 EC D2 08 00 ÞÒ.¨¬Ò.
00476028 00 D3 08 00 10 D3 08 00 .Ó.Ó.
00476030 1E D3 08 00 CC D3 08 00 Ó.ÌÓ.
00476038 BC D3 08 00 A8 D3 08 00 ¼Ó.¡§Ó.
00476040 94 D3 08 00 56 D2 08 00 ¡±Ó.VÒ.
00476048 6E D3 08 00 56 D3 08 00 nÓ.VÓ.

select all patterns , that is about till address xxx840, and set memory break point on write.

2- shift+f9 tell you see eax with an api entered in [edx], F9,continue in doing so, tell you see a bad entry[ you may hit the bad entry first], change eax to the good register , ebx, you can do few more f9s to make sure No more bad entries,but I can assure you, there aren't any, so remove the bp , f9, you will be at exception, hit the "-" key, undo change you have made.

3- use my script to go to oep, impotrec will fix the one item left, dump and attach the import. all done

note:
there are few things to fix , but are normal, if you have hard time , I will show how to fix them as well as how to register the target.
[note2]
script asplasltex_oepnewall2 has been corrected to work well.


regards.

Last edited by britedream; 09-02-2004 at 05:07.
Reply With Quote
  #2  
Old 08-30-2004, 23:43
R@dier
 
Posts: n/a
Hi britedream,


Thanks for your valuable advice, it worked perfect

Best Wishes

R@dier
Reply With Quote
  #3  
Old 08-31-2004, 00:00
JMI JMI is offline
Leader
 
Join Date: Jan 2002
Posts: 1,627
Rept. Given: 5
Rept. Rcvd 199 Times in 99 Posts
Thanks Given: 0
Thanks Rcvd at 96 Times in 94 Posts
JMI Reputation: 100-199 JMI Reputation: 100-199
Don't know if it makes any difference to the process, because I have not had time to try your technique, but the vendor did release a 3.52 verson on August 27th. The 3.51 version is still available on the net with minimal searching.

Thanks for the information.

Regards,
__________________
JMI
Reply With Quote
  #4  
Old 08-31-2004, 00:26
britedream britedream is offline
Friend
 
Join Date: Jun 2002
Posts: 436
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 7 Times in 7 Posts
britedream Reputation: 0
Thanks JMI for the info

I did check it, and there is no difference between the two versions as far as asprotect concern.

Regards.
Reply With Quote
  #5  
Old 08-31-2004, 00:30
R@dier
 
Posts: n/a
Hi,

I used version 3.52, no probs at all


Best Wishes
R@dier
Reply With Quote
  #6  
Old 08-31-2004, 21:52
britedream britedream is offline
Friend
 
Join Date: Jun 2002
Posts: 436
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 7 Times in 7 Posts
britedream Reputation: 0
Script asplastex_oepnewall2 has been corrected to work as good as alplastex_oepnewall.


Regards.

Last edited by britedream; 09-02-2004 at 05:09.
Reply With Quote
  #7  
Old 08-31-2004, 23:47
JMI JMI is offline
Leader
 
Join Date: Jan 2002
Posts: 1,627
Rept. Given: 5
Rept. Rcvd 199 Times in 99 Posts
Thanks Given: 0
Thanks Rcvd at 96 Times in 94 Posts
JMI Reputation: 100-199 JMI Reputation: 100-199
Britedream

Entirely too much good work coming from you lately. No, wait, you always do good work. Keep it coming.

Regards,
__________________
JMI
Reply With Quote
  #8  
Old 09-01-2004, 01:46
britedream britedream is offline
Friend
 
Join Date: Jun 2002
Posts: 436
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 7 Times in 7 Posts
britedream Reputation: 0
Pleasure to participate in your forum.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ASProtect SKE unpacking TempoMat General Discussion 10 08-24-2016 17:48
need help unpacking ASProtect Fade General Discussion 8 05-25-2011 22:12


All times are GMT +8. The time now is 12:42.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )