Forums: How To Un - Asprotect 1.1b - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

How To Un - Asprotect 1.1b

#1 User is offline   Cheraz 

  • Private
  • Icon
  • Group: Members
  • Posts: 8
  • Joined: 02-July 05

Posted 02 July 2005 - 07:05 AM

Hi,

I'm looking for a way to get rid of asprotect 1.1b . I would like to analyse a program that is protected by asprotect. Unfortunately i only found programs for aprotect < 1 . Could you give me an advice?
0

#2 User is offline   gr33dy 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 25
  • Joined: 15-June 05

Posted 02 July 2005 - 01:05 PM

I haven't tried it myself but there is a program called "rAD" that may be able to do it: http://protools.reve...packers/rad.zip

Otherwise, this link may be helpful: http://www.ghu.as.ro...tuts/labba1.htm
0

#3 User is offline   belgther 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 650
  • Joined: 06-October 04

Posted 02 July 2005 - 05:45 PM

1)fire up olly.
2)open target program via olly.
3)go to options-debugging options-exceptions. remove everything except memory access violations in kernel32.
4)run the program. it will break. press shift+f9 each time it holds, counting how many times it held before it runs the program. note it.
5)restart the program. run again. press shift+f9, and press it so many times as you counted before -1. because on the last time, you will press shift+f8. I think you got the point.
6)plugins-command line-command line, type TC EIP<900000 and wait. It will hold at the OEP after a short time.
7)You can dump it, then fix your import table with ImpRec, then change the OEP with procdump or LordPE. Mostly, it works. If it quits, then you have to load the stack of the packed program manually.


This works with asprotect 1.2&1.3, but should work with 1.1 as well.

Have fun...
"The wisest one is the one who knows himself/herself." Quote of the life
belgther... aka... belgther
0

#4 User is offline   White Scorpion 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 674
  • Joined: 05-September 04

Posted 03 July 2005 - 01:31 AM

Interesting Belgther, i never really did something with manual unpacking, but it is very interesting to learn :lol:

As for your problem Cheraz, take a look at this site, although in russia, it has some tools available for download, including several unpackers for asprotect.
The path of access leads to the server of wisdom..

The Syringe - My Latest Project.
Errors, Vulnerabilities & Exploits explained.
----
www.white-scorpion.nl
www.info-sec.eu
www.info-sec.info
0

#5 User is offline   Cheraz 

  • Private
  • Icon
  • Group: Members
  • Posts: 8
  • Joined: 02-July 05

Posted 03 July 2005 - 01:44 AM

Thanks guys, you're really helpful.
0

#6 User is offline   belgther 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 650
  • Joined: 06-October 04

Posted 03 July 2005 - 07:58 AM

White Scorpion, on Jul 3 2005, 10:31 AM, said:

As for your problem Cheraz, take a look at this site, although in russia, it has some tools available for download, including several unpackers for asprotect.


Well, these asprotect unpackers never worked by me, i tested some of them in windows 98 some years ago. That's the reason why I started manual unpacking.
BTW, you can take a look at hxxp://biw.rult.at . it has god tutorials about this subject, too. I learned the way i mentioned from that site.
"The wisest one is the one who knows himself/herself." Quote of the life
belgther... aka... belgther
0

#7 User is offline   White Scorpion 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 674
  • Joined: 05-September 04

Posted 03 July 2005 - 09:41 AM

biw.rult.at nowadays is reversing.be
i've been a member on that site for about a year now, i haven't visited it since a couple of months ago, but i will asap.
The path of access leads to the server of wisdom..

The Syringe - My Latest Project.
Errors, Vulnerabilities & Exploits explained.
----
www.white-scorpion.nl
www.info-sec.eu
www.info-sec.info
0

#8 User is offline   r4d14t10n 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 21
  • Joined: 27-December 03

Posted 04 July 2005 - 10:50 AM

if u just want to analys it ....u can dump it with programs like ProcDump ... or Win32 Intro ... hmmm if u cant find them ... pm me..
0

#9 User is offline   Slayer666 

  • Private
  • Icon
  • Group: Members
  • Posts: 12
  • Joined: 06-February 04

Posted 26 August 2005 - 07:43 PM

Check This:

Break Asprotect

;)
0

#10 User is offline   320X 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 473
  • Joined: 13-December 03

Posted 31 October 2005 - 04:11 PM

exetools web there are many unpackers

View Postbelgther, on Jul 3 2005, 02:45 AM, said:

1)fire up olly.
2)open target program via olly.
3)go to options-debugging options-exceptions. remove everything except memory access violations in kernel32.
4)run the program. it will break. press shift+f9 each time it holds, counting how many times it held before it runs the program. note it.
5)restart the program. run again. press shift+f9, and press it so many times as you counted before -1. because on the last time, you will press shift+f8. I think you got the point.
6)plugins-command line-command line, type TC EIP<900000 and wait. It will hold at the OEP after a short time.
7)You can dump it, then fix your import table with ImpRec, then change the OEP with procdump or LordPE. Mostly, it works. If it quits, then you have to load the stack of the packed program manually.


This works with asprotect 1.2&1.3, but should work with 1.1 as well.

Have fun...


really great method, thanks :)
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting