orestes
August 12th, 2004, 15:34
Time ago I have used stripper 2.07f and PEid 0.92 to unpack a program that the programer always protect two times, before he used aspack 1.06 and aspack 2.1, but in recent days he used asprotect 1.23 RC4 and aspack 2.11. The problem now is that the first packer can be removed but the second how is a unpacked file non a original packed the tool don't reconize. I really unpack the last version but now i can't do it.
If first I use stripper to unpack, PEid says that the unpacked program is packed by asprotect 1.23 RC4. But if first I use aspackdie to unpack PEid says that the unpacked program is packed by aspack 2.12
Well, actually i'm using asprdumper and works fine (excepts the debug of Manko that crash maybe because isn't aspr but seems like it), the problem is rebuild the IAT of the second unpacked, i try with revirgin 1.5 and Imprec 1.6 final, to trace i try ollydbg 1.1 because softice is detected (i work in xp, i can't use frogsice or ntdump)
Resuming I wanna know if there are other method to unpack and how i can rebuid the IAT because revirgin and Imprec show me only trash.
If first I use stripper to unpack, PEid says that the unpacked program is packed by asprotect 1.23 RC4. But if first I use aspackdie to unpack PEid says that the unpacked program is packed by aspack 2.12
Well, actually i'm using asprdumper and works fine (excepts the debug of Manko that crash maybe because isn't aspr but seems like it), the problem is rebuild the IAT of the second unpacked, i try with revirgin 1.5 and Imprec 1.6 final, to trace i try ollydbg 1.1 because softice is detected (i work in xp, i can't use frogsice or ntdump)
Resuming I wanna know if there are other method to unpack and how i can rebuid the IAT because revirgin and Imprec show me only trash.
