Log in

View Full Version : please about nsp pack


milad
December 26th, 2005, 15:47
If anybody have informantion about unpack nsp pack
Please answer me

mr haggar
December 26th, 2005, 17:05
What version?

/////////////////////////////////////////////////////
/*
Script for unpacking NsPack v2.3 by haggar
*/
msg "Ignore ALL exceptions!"
var addr
sti
sti
mov addr,esp
bphws addr,"r"
esto
bphwc addr
sti
an eip
cmt eip,"This is the OEP."
ret
///////////////////////////////////////////////////

////////////////////////////////////////////////////
/*
Script for NsPAck 3.1 version
*/
msg "Ignore all exceptions!!!"
find eip,#E9????????8BB5??FEFFFF0BF60F84970000008B95??FEFFFF03F2833E00750E#
bp $RESULT
esto
bc eip
sti
an eip
cmt eip,"<-- OEP! Found by haggar "
ret
////////////////////////////////////////////////////////////////////

milad
December 27th, 2005, 05:13
Thank you Mr hagger For your reply
in memory with olly onlly see nsp0 nsp1 nsp2
in pied nothing*

When press ITA AutoSearch in Imprec see Message
could not find anything good at this OEP! :-(
and can't unpack it Is there any tutorial about unpack nspack
I had try with script anthor script and the same message
If you can help me

milad
December 27th, 2005, 15:35
Dear Mr Haggr I think it is nsp 1.4
can you help me with script or the to unpack it
thank's

Lord_Looser
December 27th, 2005, 15:53
I have no idea of unpacking NsPack but perhaps you forgot to substract OEP with modules base address:
OEP in ImpRec = OEP in OllyDbg - 0x0400000 in most cases.

mr haggar
December 27th, 2005, 18:00
I think that one of those two scripts ends on jump to OEP. So you need just to hit F7 once and then you are at the OEP. I cannot help you more because it is simple packer, more help would mean that I unpack it for you. You'll find way

milad
December 28th, 2005, 07:08
Thank you mr haggar and Lord_Looser
I am beginner in crack, you and Gabril and ricardo and all in the forum
make me love the crack and love the assembly and Programmer

when use your script
0053D6FC F3:A4 REP MOVS BYTE PTR ES:[EDI],BYTE PTR DS:[>;

<-- OEP! Found by haggar
you must press shift+f7 when press it you arrive into nt.dll
I don't know what i can to do so ask you to help me
I wish to apply my thanks again
My mail is tannous70@hotmail.com If i can get your mail