![]() |
eXeL@B —› Вопросы новичков —› Unpacking Advanced Registry Tracer |
Посл.ответ | Сообщение |
|
Создано: 31 января 2007 13:42 · Личное сообщение · #1 I'm trying to unpack the advanced registry tracer (http://www.elcomsoft.com/art.html). I've successfully unpacked it and reconstructed the iat, but the problem now is that it checks for presence of the unpacker (in this case asprotect 2.1x as reported by PEiD) pretty much randomly throughout the initialization code by trying to access dynamicly allocated memory (in this case located at 18xxxxx), which of course does not exist in the unpacked executable. Any ideas on how to bypass it? Is there maybe a way to ignore any mov's and calls involving invalid addresses? Some plugin for olly maybe? I allso tried to use lates asprotect unpacker script for olly written by Volx, but it tells me that it cannot recognise version of asprotect used in this file. The script can be found here: www.unpack.cn/viewthread.php?tid=9487&extra=page%3D1 Here is a link to both the original trial and my unpacked version: rapidshare.com/files/14301470/art.rar I hope it's ok to post such links here. I don't mind if you write in russian.. I just don't have a russian keyboard so I write in english... ![]() |
|
Создано: 01 февраля 2007 07:36 · Личное сообщение · #2 |
|
Создано: 01 февраля 2007 13:47 · Личное сообщение · #3 |
|
Создано: 01 февраля 2007 14:18 · Личное сообщение · #4 |
![]() |
eXeL@B —› Вопросы новичков —› Unpacking Advanced Registry Tracer |