Exetools  

Go Back   Exetools > General > General Discussion

Notices

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #10  
Old 12-14-2005, 02:02
deroko's Avatar
deroko deroko is offline
cr4zyserb
 
Join Date: Nov 2005
Posts: 217
Rept. Given: 13
Rept. Rcvd 30 Times in 14 Posts
Thanks Given: 7
Thanks Rcvd at 33 Times in 16 Posts
deroko Reputation: 30
Quote:
Originally Posted by winndy
Code:
003F4858     55                    push ebp                        ; HFFR.0045C3FC
003F4859     8BEC                mov ebp,esp
003F485B     83C4 B4            add esp,-4C
003F485E     B8 38473F00      mov eax,3F4738
003F4863     E8 B007FFFF     call 003E5018
003F4868     E8 A3EAFEFF     call 003E3310
003F486D     8D40 00            lea eax,dword ptr ds:[eax]
This is just asprotect virtual .exe extracted by aspr itself into memory, same as secure.dll in armadillo. All protection is in it, so dumping it and analyzing it is a good way to understand how asprotect works.

That's at least my approach on every asprotected target.
Reply With Quote
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 23:31.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )