Log in

View Full Version : problems with a program protected by aspack + aspr


orestes
August 12th, 2004, 15:34
Time ago I have used stripper 2.07f and PEid 0.92 to unpack a program that the programer always protect two times, before he used aspack 1.06 and aspack 2.1, but in recent days he used asprotect 1.23 RC4 and aspack 2.11. The problem now is that the first packer can be removed but the second how is a unpacked file non a original packed the tool don't reconize. I really unpack the last version but now i can't do it.

If first I use stripper to unpack, PEid says that the unpacked program is packed by asprotect 1.23 RC4. But if first I use aspackdie to unpack PEid says that the unpacked program is packed by aspack 2.12

Well, actually i'm using asprdumper and works fine (excepts the debug of Manko that crash maybe because isn't aspr but seems like it), the problem is rebuild the IAT of the second unpacked, i try with revirgin 1.5 and Imprec 1.6 final, to trace i try ollydbg 1.1 because softice is detected (i work in xp, i can't use frogsice or ntdump)

Resuming I wanna know if there are other method to unpack and how i can rebuid the IAT because revirgin and Imprec show me only trash.

namrahus
August 13th, 2004, 17:28
It has to be unpacked manually.

orestes
August 13th, 2004, 19:35
Thanks namrahus, but I already tryied and I can't get it. I need to learn more before to get it.

JMI
August 14th, 2004, 13:24
Well then your path is clear. You need to study manual unpacking more and learn how to do it. There is much discussion already on this and other Forums on manually unpacking this version of ASPR. Time for you to read more than one or two tutes. Use the search button and things like "manual unpacking and ASPR" (without the quotes) or maybe even just "ASPR" or "Asprotect unpacking" (don't actually use the quotes in the search box.)

Regards,