Log in

View Full Version : For asprotect lovers


LaptoniC
May 15th, 2002, 16:01
I have tried to write unpacker for aspr.I guess %40 is done.I have documented IAT loader.I wont work on this unpacker for a long time.I need to concentrate on my finals.
Play with it.Hope you like it.

Ni2
May 16th, 2002, 14:51
Hi LaptoniC!

Whassup mate? I cant believe you are gonna stop your secret project Like with girls, you shouldnt stop things in the middle (bad for your brain after a long while)

I just want to give you some strength to continue with your project, cos you have done a very good work till now

Regards,
Ni2

crUsAdEr
May 16th, 2002, 19:37
Damn.. :>>>...

Lapto, you beat me to it :>... decided to code a decryptor instead so that i can learn some crypto along the way... does your dump or decrypt the target? And did you find out what the last emu API is? I never seen it being used though...

Anyway, i hope Alex doesnt take it too hard, cos now that AsProtected is really useless, with your unpacker and GLOBAL's inline patcher, it is rendered useless... hopefully he will come up with a brand new AsProtect 2.0 for us to play with, it is nice to reverse clean code... though obfuscated... wonder when he will release THE version that kills both Revirgin and ImPrec as he promises...

tiil then, good luck for ur exams Lapto... /me need lots of luck too :>>
crUsAdEr

LaptoniC
May 16th, 2002, 23:33
If you dump at first getprocaddress of IAT loader you will have clean.exe which wont have any aspr dips without iat ofcourse.Because I hook gpa you can build the import table I guess.
Yes I found the emulated apis.Last one is DllFunctionCall from vb.Everything else in source code and notes.txt.

crUsAdEr
May 17th, 2002, 00:17
Yeah that is what i did initially in my dumper... patch the IAt mangling routine to build it instead of mangling it :>... then dump from there...

but guess my coding skill is too crap... as you have seen, the loader doesnt seem very stable... hence i decide to do a safer one which decrypt the file without running it... thus learn the algo along the way...

nice, who could have guessed that DllFunctionCall :>... thanx for the info...

Hwoarang
May 17th, 2002, 06:07
very good idea LaptoniC..congrats
DllFunctionCall? hum, I never saw VB applications protected by aspr=/

tsehp
May 17th, 2002, 20:09
Quote:
Originally posted by crUsAdEr
Damn.. :>>>...
inline patcher, it is rendered useless... hopefully he will come up with a brand new AsProtect 2.0 for us to play with, it is nice to reverse clean code... though obfuscated... wonder when he will release THE version that kills both Revirgin and ImPrec as he promises...


crUsAdEr


>>at least ! there is about 1 year and half I wait for this moment

always remember those words : if it runs it can be defeated...

+orc memories.

tsehp

amois
May 18th, 2002, 04:49
I think, PcGuard 4.04d, 4.05d already killed Revirgin & Imprec.

Hwoarang
May 18th, 2002, 14:26
amois:
I really doubt that it's true...as far as I know pcguard can't even trick icedumps it rebuilder.

r00t
May 18th, 2002, 17:05
Hi, anyone can tell me what's
GLOBAL inline patcher?, if it makes asprotect useless, i want it.

(i cannot find it in google).

Greets.

SilberFuchs
May 18th, 2002, 21:02
look at:

Tools of our Trade (AIPH)


....Asprotect is not useless, is a good prog. But it seems, that the shareware-programmer aren't able to use the good features of Asprotect...

ciao
SilberFuchs